Analyst – Technology Risk Management
- MTR Corporation Limited 香港鐵路有限公司
- Hong Kong, Hong Kong
- HKD 480,000 – HKD 720,000
Responsibilities
- Ensure security monitoring tools and processes, e.g. IDS/ IPS, SIEM, cover critical IT/ OT environments. Regularly fine-tune monitoring rules, review logs, and ensure log retention and analysis comply with corporate and regulatory requirements.
- Maintain organizational readiness for cybersecurity incidents affecting critical systems. Ensure proper incident classification, activate response teams promptly, and coordinate communications among Security Operations Center (SOC), IT/ OT teams, and information security leaders.
- Ensure timely and accurate statutory incident notifications and reporting, including regulatory submissions within prescribed timelines and detailed incident reports as required.
- Lead post-incident reviews, root cause analysis, and continuous improvement initiatives. Drive implementation of lessons learned and conduct regular cyber incident drills to strengthen response capabilities.
- Act as a technology risk delegate for security incidents, providing real-time updates and incident metrics to the information security leaders throughout the incident.
- Collaborate closely with the managed SOC and cybersecurity leads in business units and functions to incident response aligns with the incident response plan, the information policies, standards and guidelines.
Requirements
- Bachelor in Computer Science, Information Security or a related discipline
- A minimum of 3 years' experience in security operations, incident response, or SOC roles, and implementing monitoring solutions in complex environments. Experience in a critical infrastructure or ICS/ OT security context is preferred
- Possession of professional certifications such as CISSP, CISM, CISA, CISP or similar are highly preferred
- Possession of specialized incident response or SOC-related certifications, e.g., GIAC, GCIH, GCFA, is an advantage
- Strong knowledge of security monitoring, threat detection, and incident response. Familiarity with cyber incident management frameworks, e.g. NIST, SANS, and regulatory incident reporting requirements. Excellent crisis management and problem-solving skills, with the ability to remain calm and decisive under pressure
- Strong communication skills, enabling clear coordination with both technical teams and senior management during incidents
- Possession of a proactive mindset for continuous improvement, ensuring lessons learned from incidents lead to tangible security enhancements
Applications
You are invited to apply online via http://www.mtr.com.hk/mtr\_job\_en or send in your CV stating the position (with reference number) you are applying for by mail to Human Resource Management Department, MTR Corporation, G.P.O. Box 9916, Hong Kong on or before 24 September 2026.
For other job openings, please visit MTR Corporation's website for more details.
All information provided by applicants will be treated in strict confidence and used for recruitment purpose only. All personal data of unsuccessful applicants will be retained for 12 months for future recruitment purpose and will then be destroyed.
Primary Location
Hong Kong
Schedule
Full-time
Job Posting
10/Sep/26, 9:56:12 AM
Closing Date
24/Sep/26, 3:59:00 PM
Job Number:
260000SP
Skills
- SIEM
- Intrusion Detection/Prevention Systems (IDS/IPS)
- Incident Response
- Log Analysis
- Security Monitoring
- Root Cause Analysis
- Regulatory Compliance







