Security Engineer / Manager
Bowtie Life Insurance Company Limited Wan Chai, Hong Kong Island, Hong Kong S.A.R.
Insurance · 51-200 employees
About the role
The candidate will own the end-to-end technical security posture, including application, cloud, and infrastructure security. They will also manage security monitoring, privileged access, and serve as the primary point of contact for regulators and auditors.
What they look for
Requirements
The role requires hands-on experience with AWS security, SIEM deployment, and identity management systems. Candidates should have strong communication skills and experience navigating financial services regulatory frameworks.
Benefits
Full description
Role Summary
At Bowtie, we aren't just selling insurance; we're rebuilding it from the ground up. As Hong Kong's first virtual insurer, regulated by the HKIA, security isn't a checkbox for us — it's core infrastructure. The successful candidate will own it end to end: application, cloud, and infrastructure security, monitoring, access, and the regulator and partner relationships that come with the territory.
If you'd rather build and operate a security function yourself than write a strategy deck about one, we should talk.
About the Role
You'll be the accountable, hands-on owner of Bowtie's technical security posture — setting the standard that our SRE and IT teams execute against, and the point of contact when auditors, regulators, or distribution partners come asking.
Your Key Responsibilities Include:
- Security Monitoring & Detection
- Own the selection and rollout of centralised security monitoring (SIEM) across our critical log sources
- Be the accountable owner for triaging and acting on alerts
- Privileged Access & Identity
- Design and provide implementation details to SRE/IT on privileged access management (PAM) for production and super-admin consoles — brokered, time-bound, and logged
- Own our identity architecture: IdP, SSO, SCIM
- Application & Cloud Security
- Own security integration into our SDLC — code review guardrails, dependency and supply-chain risk
- Own cloud security posture review across our AWS environment (IAM, SCP, GuardDuty, CloudTrail, KMS) and our Identity/SaaS/Endpoint Protections
- Risk Register & Testing
- Define severity definitions and remediation SLOs, track them in a single register, and report on posture regularly
- Run a programme of internal security exercises and an external penetration-test rotation
- Governance, Response & Partnerships
- Lead a joint forum with our SRE and IT teams, and put incident runbooks in place
- Be the main point of contact for audits, regulatory reviews, independent security assessments and partner security assessments
About you
Experience & Skills
- Application security — SDLC integration, code review, dependency/supply-chain risk; able to run a supply-chain compromise investigation unaided
- Cloud security — hands-on with AWS IAM, SCP, GuardDuty, CloudTrail, KMS
- Has deployed a SIEM end to end at least once
- Has implemented PAM and designed privileged access workflows
- Identity — IdP, SSO, SCIM
- Strong written and documentary communication
- Exposure to Hong Kong financial services regulatory context (HKIA guidelines, cyber risk frameworks, data privacy)
- A strong plus: framework literacy (NIST CSF 2.0, ISO/IEC 27001 or similar) with experience running gap assessments and implementation
- A strong plus: CNAPP (e.g. Orca), EDR, and vulnerability management tooling
- A strong plus: Cloudflare Zero Trust / Gateway / DLP
- A strong plus: Google Workspace admin and MDM/BYOD at scale
- Comfortable in Python or TypeScript — enough to automate, not just ticket-push
- Certifications (CISSP, CISM, AWS Security Specialty, OSCP) are welcome, but hands-on evidence outranks them
The Person
- Genuinely hands-on — builds and operates, no ego about unglamorous work
- Writes clean, formal English — policy documents and regulator correspondence are a real part of this job
- Thinks in risk and cost, not just best practice — comfortable saying a control isn't worth the money, and defending that call
- Registers gaps honestly instead of dressing them up
- Works across teams without needing a reporting line to get things done
- Comfortable pushing back on engineering leads when the risk calls for it
- Proposes fixes that can actually be implemented, and follows through to verify they're closed — a finding with no remediation path isn't enough here
- Sets guardrails rather than approval gates, and is comfortable operating without close supervision
Language
Strong written and spoken English required. Cantonese preferred, but not required.
We Offer
Apart from a great career path and an opportunity to do good and do well, we also offer:
- Competitive package
- Flexible work arrangement
- Benefits include medical/ dental coverage and wellness programs
- Employee discounts
- Fun, co-operative, and flexible startup culture
- Weekly sharing sessions and regular social gatherings
- Excellent learning opportunities with Professional Development Sponsorship
About Bowtie
We are the first licensed virtual insurer (虛擬保險公司) in Hong Kong.
We believe that insurance is fundamentally good, and we are here to bring the good back through our passionate, innovative, and customer-centric team.
By combining our deep domain expertise and our own proprietary modern technology, we are building one of the most iconic, category-defining health insurance companies in Asia.
We take pride in moving fast all the time and our track record in moving ahead in the game. Our digital insurance platform is also ranked #2 in the world in Sia Partners' 2023 report.
As we grow, we're always looking for highly dynamic, hands-on, and passionate talent to join our team. If you are looking for a rewarding career where you will grow together with strong talents from different backgrounds and build products and services that bring a positive impact on the lives of millions of people in Hong Kong / Asia, apply to our opening today!
Information collected will be treated in strict confidence and used solely for recruitment purposes.
The company will retain all applications no longer than 24 months of which will be destroyed thereafter.
We are an equal-opportunity employer. We do not discriminate on the basis of race, sex, disability, or family status in the employment process.
Similar roles
-
Manager, Cybersecurity Governance & Risk
Anglo-Eastern Ship Management Hong Kong, Hong Kong Island, Hong Kong S.A.R.
-
Information Security Engineer - Cloud Security
Ryanair Group Holdings Wrocław, Lower Silesian Voivodeship, Poland
- Nederlands Sprekende Klantadviseur Cybersecurity - Work Remote In Greece
-
Cybersecurity Expert
Inetum Lisbon, Portugal
-
Marketing Manager - Telecoms and Cybersecurity
Enea Dublin, Leinster, Ireland · €45K–€60K/yr
-
Sales Specialist Cybersecurity - H/F
Devoteam Levallois-Perret, Ile-de-France, France