Cybersecurity Analyst

  • Full Time

Why This Role Matters
This role is critical in protecting and strengthening our cloud‑native and microservices ecosystem as the business scales across our O+O (Offline + Online) model. By embedding security directly into how we build and operate platforms, you empower teams to innovate with confidence—putting a smile on customers’ faces by safeguarding their data, services, and seamless digital experiences.


What You’ll Be Doing

  •  Cloud‑Native Security Ownership: Own and continuously tune our CNAPP platform to deliver runtime threat detection, vulnerability visibility, compliance posture, and CSPM — applying a customer‑focused mindset grounded in measurable, data‑driven outcomes.
  • Runtime Threat Detection & Incident Response: Monitor container runtime behaviour, investigate alerts, and lead cloud‑native incident triage in close collaboration with engineering and operations teams.
  • Kubernetes Security Hardening: Assess and harden Kubernetes clusters against CIS Benchmarks and NSA/CISA guidance, using a scientific and risk‑based approach to reduce attack surface at scale.
  • Container Image & Supply Chain Security: Maintain continuous visibility of image vulnerabilities across registries and production workloads, enabling secure delivery across both online platforms and offline‑integrated services.
  • Vulnerability & CVE Lifecycle Management: Classify, track, and manage CVEs end‑to‑end—partnering with engineers on remediation while supporting informed residual risk decisions.
  • Secure Infrastructure‑as‑Code Enablement: Embed security requirements into Terraform, Helm, and Kustomize workflows, making security a shared capability rather than a bottleneck.
  • Security Knowledge & Playbook Development: Build clear runbooks, playbooks, and baseline standards that help teams operate securely and consistently across environments.


What You’ll Bring

  •  Hands‑on experience securing cloud‑native, containerised, or microservices environments
  • Confidence working with CNAPP tools (e.g. Sysdig, NeuVector, Aqua, Prisma Cloud, Lacework, Wiz) for policy management and alert triage
  • Strong knowledge of container security principles, including image hardening, runtime protection, and supply chain risk
  • Solid exposure to Kubernetes security and cloud infrastructure practices
  • Clear communication in English (written & spoken) and Cantonese (spoken), enabling effective cross‑team collaboration
  • A customer‑focused mindset and ability to apply structured, data‑informed decision making


How You Will Make An Impact

  •  Proactive ownership of security posture in fast‑moving, cloud‑native environments
  • Ability to partner with engineers and DevOps teams to shift security left without slowing delivery
  • Strong judgement in prioritising risk, responding to incidents, and managing vulnerabilities pragmatically
  • Curiosity and continuous learning in cloud security, DevSecOps, and modern threat landscapes
  • Discipline in documentation, measurement, and building defensible security baselines

We are an equal opportunity employer and welcome applications from all qualified candidates. The information provided will be treated in strict confidence and be used only for consideration of your application for relevant/ similar posts within the AS Watson Group.


Where you’ll be working from

Ready to start crafting your career?