About the role
Security at CloudPeak is an engineering function, not a review gate. We build the guardrails into the landing zones, we write the detections, and when something is wrong we send a pull request rather than a finding with a due date thirty days out.
The team is four engineers supporting a platform that runs workloads for banks, insurers and a hospital network. That means real threat models rather than checklists: cross-tenant isolation, key management across two clouds, supply-chain integrity for the modules customers deploy, and the uncomfortable question of what one compromised CloudPeak engineer could actually do.
This role is open now because we are formalising the customer-facing side of security — the questionnaires, the evidence packs, and the annual assessments where a client's second line of defence spends a day with us. You would split your time roughly seventy-thirty between building and that.
What you'll do
- Threat-model new platform capabilities before they ship, and turn the results into controls that live in code.
- Build and tune detections across cloud audit logs and Kubernetes activity, and reduce the alerts nobody triages.
- Own secrets and key management across AWS and Azure, including rotation that does not break customers at 2am.
- Harden the software supply chain: signed artefacts, dependency policy, and provenance customers can verify.
- Lead incident response for security events alongside the reliability team, and write the postmortem.
- Handle customer security assessments and regulator-driven evidence requests without derailing the engineering roadmap.
What we're looking for
- Five or more years in security engineering, with hands-on cloud security work in AWS or Azure.
- Practical Kubernetes security knowledge: RBAC, admission control, network policy, workload identity.
- You write code — Python or Go — and your controls ship as software.
- Familiarity with the expectations Hong Kong regulated customers bring, including HKMA cloud guidance and PDPO obligations.
- Business Cantonese and English; assessment sessions with local institutions run in both.
Nice to have
- CISSP, OSCP or GIAC certification — we pay for renewals and reward new ones.
- Detection engineering with an open-source stack.
- Experience being on the customer side of a third-party security assessment.
What you get
- Certification bonus plus fully funded exam and training costs
- 13th month salary
- Medical and dental for the family
- 20 days annual leave, rising to 25
- Hybrid — two days a week on site
Skills & keywords
Bryan Sze
Head of Security Engineering · reviews applications personally
Listing ID JOB-TECH-011 · Closes 21 Aug 2026 · HKjobs never asks candidates to pay a fee. Report this listing