Security Engineer Manager
Job Summary
At Bowtie we arent just selling insurance; were rebuilding it from the ground up. As Hong Kongs first virtual insurer regulated by the HKIA security isnt a checkbox for us its core infrastructure. The successful candidate will own it end to end: application cloud and infrastructure security monitoring access and the regulator and partner relationships that come with the territory.
If youd rather build and operate a security function yourself than write a strategy deck about one we should talk.
Youll be the accountable hands-on owner of Bowties technical security posture setting the standard that our SRE and IT teams execute against and the point of contact when auditors regulators or distribution partners come asking.
Security Monitoring & Detection
Own the selection and rollout of centralised security monitoring (SIEM) across our critical log sources
Be the accountable owner for triaging and acting on alerts
Privileged Access & Identity
Design and provide implementation details to SRE/IT on privileged access management (PAM) for production and super-admin consoles brokered time-bound and logged
Own our identity architecture: IdP SSO SCIM
Application & Cloud Security
Own security integration into our SDLC code review guardrails dependency and supply-chain risk
Own cloud security posture review across our AWS environment (IAM SCP GuardDuty CloudTrail KMS) and our Identity/SaaS/Endpoint Protections
Risk Register & Testing
Define severity definitions and remediation SLOs track them in a single register and report on posture regularly
Run a programme of internal security exercises and an external penetration-test rotation
Governance Response & Partnerships
Lead a joint forum with our SRE and IT teams and put incident runbooks in place
Be the main point of contact for audits regulatory reviews independent security assessments and partner security assessments
Experience & Skills
Application security SDLC integration code review dependency/supply-chain risk; able to run a supply-chain compromise investigation unaided
Cloud security hands-on with AWS IAM SCP GuardDuty CloudTrail KMS
Has deployed a SIEM end to end at least once
Has implemented PAM and designed privileged access workflows
Identity IdP SSO SCIM
Strong written and documentary communication
Exposure to Hong Kong financial services regulatory context (HKIA guidelines cyber risk frameworks data privacy)
A strong plus: framework literacy (NIST CSF 2.0 ISO/IEC 27001 or similar) with experience running gap assessments and implementation
A strong plus: CNAPP (e.g. Orca) EDR and vulnerability management tooling
A strong plus: Cloudflare Zero Trust / Gateway / DLP
A strong plus: Google Workspace admin and MDM/BYOD at scale
Comfortable in Python or TypeScript enough to automate not just ticket-push
Certifications (CISSP CISM AWS Security Specialty OSCP) are welcome but hands-on evidence outranks them
The Person
Genuinely hands-on builds and operates no ego about unglamorous work
Writes clean formal English policy documents and regulator correspondence are a real part of this job
Thinks in risk and cost not just best practice comfortable saying a control isnt worth the money and defending that call
Registers gaps honestly instead of dressing them up
Works across teams without needing a reporting line to get things done
Comfortable pushing back on engineering leads when the risk calls for it
Proposes fixes that can actually be implemented and follows through to verify theyre closed a finding with no remediation path isnt enough here
Sets guardrails rather than approval gates and is comfortable operating without close supervision
Language
Strong written and spoken English required. Cantonese preferred but not required.
Apart from a great career path and an opportunity to do good and do well we also offer:
Competitive package
Flexible work arrangement
Benefits include medical/ dental coverage and wellness programs
Employee discounts
Fun co-operative and flexible startup culture
Weekly sharing sessions and regular social gatherings
Excellent learning opportunities with Professional Development Sponsorship
We are the first licensed virtual insurer (虛擬保險公司) in Hong Kong.
We believe that insurance is fundamentally good and we are here to bring the good back through our passionate innovative and customer-centric team.
By combining our deep domain expertise and our own proprietary modern technology we are building one of the most iconic category-defining health insurance companies in Asia.
We take pride in moving fast all the time and our track record in moving ahead in the game. Our digital insurance platform is also ranked #2 in the world in Sia Partners 2023 report.
As we grow were always looking for highly dynamic hands-on and passionate talent to join our team. If you are looking for a rewarding career where you will grow together with strong talents from different backgrounds and build products and services that bring a positive impact on the lives of millions of people in Hong Kong / Asia apply to our opening today!
Information collected will be treated in strict confidence and used solely for recruitment purposes.
The company will retain all applications no longer than 24 months of which will be destroyed thereafter.
We are an equal-opportunity employer. We do not discriminate on the basis of race sex disability or family status in the employment process.
About Company
Our purpose is simple - we are here to bring back the good of insurance: protecting people and their families. By combiningour deep domain expertise and our modern proprietary technology, we strive to provide better insurance productsand world-class insurance experience to the public. ... View more