Partner with software engineering and infrastructure teams to embed security throughout the software development lifecycle. Implement and operate security controls across cloud services, core infrastructure, and business applications on Windows and Linux platforms. Requires 3-5 years of product security experience, proficiency in Python/C++/Rust/Go/Kotlin/Java, and strong understanding of secure coding practices and DevSecOps.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
Our client is a leading global quantitative investment firm renowned for leveraging advanced technology, cloud infrastructure, and quantitative research to power its global trading platforms. As part of its continued investment in secure software engineering and cloud-native technology, the firm is expanding its Product Security team to strengthen security across business applications, cloud platforms, and core infrastructure in a fast-paced, engineering-driven environment.
We are seeking a Product Security / Security Architect to partner closely with software engineering and infrastructure teams to embed security throughout the software development lifecycle. This is an exciting opportunity for a security professional who is passionate about secure-by-design principles, application security, cloud security, and DevSecOps, while working alongside highly skilled engineers building mission-critical trading systems.
This role is based in Hong Kong. To ensure a smooth transition for the right candidate, comprehensive relocation support and benefits will be provided.
This role is based in Hong Kong. To ensure a smooth transition for the right candidate, comprehensive relocation support and benefits will be provided.
Key Responsibilities:
- Product Security Engineering: Support the implementation and operation of security controls across cloud services, core infrastructure, and business applications running on Windows and Linux platforms.
- Secure Software Development: Partner with software engineering teams to integrate security into application design and development, promoting secure coding practices across technologies such as Python, C++, Rust, Go, and Kotlin/Java.
- Application Security & Threat Assessment: Perform threat modelling, vulnerability assessments, security code reviews, and identify security risks while working with engineering teams to develop practical remediation strategies.
- DevSecOps & Security Automation: Assist with integrating and managing security tools—including SAST, DAST, dependency scanning, and other security testing solutions—within CI/CD pipelines and runtime environments.
- Risk & Vendor Security: Conduct vendor security assessments to evaluate third- party security practices, ensuring alignment with internal security standards and risk management requirements.
- Security Advisory & Collaboration: Work closely with engineering, infrastructure, and platform teams to provide security guidance, share best practices, and continuously improve the organization's product security capabilities.
Looking to advance your Cyber Security career with relocation support? Explore Cyber Security Jobs with Relocation Packages that include comprehensive packages to help you move and settle in your new role.
Qualifications & Experience:
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or a related discipline.
- 3–5 years of experience in Product Security, Application Security, Software Engineering, Security Engineering, or a related technical role.
- Hands-on experience with secure software development and proficiency in at least one programming language such as Python, C++, Rust, Go, or Kotlin/Java.
- Strong understanding of secure coding practices, application security principles, and common software and cloud vulnerabilities.
- Experience securing Windows and/or Linux environments.
- Practical experience with AWS and/or Microsoft Azure, ideally within hybrid cloud
- environments.
- Working knowledge of threat modelling, vulnerability management, risk
- assessment, and secure development methodologies.
- Experience integrating security testing tools such as SAST, DAST, dependency
- scanning, or similar solutions into CI/CD pipelines.
- Exposure to low-latency or performance-sensitive systems, financial services, or
- other highly regulated environments is advantageous.
- Strong analytical, problem-solving, and communication skills, with a collaborative
- mindset and a passion for continuous learning and security automation.
Discover our full range of relocation jobs with comprehensive support packages to help you relocate and settle in your new location.
To Apply:
Please apply directly to this posting or email us your Resume/CV to [email protected]. Due to the high volume of applications, only shortlisted candidates will be contacted.
About PFCC
We partner with the world’s most sophisticated financial institutions to unlock sustainable value. By merging operational excellence with the power of AI and digital transformation, we ensure our clients are equipped to lead, not just keep pace.
Bridging the Gap between Vision and Technical Mastery, we believe that even the most advanced strategy is only as powerful as the people executing it. That is why we specialize in identifying and placing high-calibre technical talent within the world’s premier financial ecosystems. Whether it’s securing mission-critical infrastructure or driving global digital shifts, we connect elite IT professionals with opportunities at global financial leaders.
Similar Jobs
Explore other opportunities that match your interests