Networking & Security Engineer
Capula · Hong Kong, Hong Kong, Hong Kong · 2026-04-17
About this role
We are seeking a hands-on Network & Security Engineer with deep expertise in Cisco networking, firewall management, and SD-WAN, combined with a strong security-first mindset. Networking and security are the core priorities of this role. The successful candidate will take a leading part in designing, maintaining, and strengthening the firm's network and security infrastructure in response to an increasingly sophisticated threat landscape, including emerging risks associated with AI.
This is a technically demanding role that combines hands-on network engineering with proactive security ownership. The successful candidate will act as a security-first thinker across everything they touch (from day-to-day network operations through to strategic infrastructure design) and will be expected to drive meaningful improvements to the firm's network architecture and defensive capabilities.
This role is office-based and requires five days per week on-site presence.
Key Responsibilities
• Design, implement, and maintain the firm's network infrastructure, including Cisco routers, switches, firewalls, VPNs, and wireless systems, ensuring high availability, performance, and security at every layer.
• Own and manage the firm's SD-WAN architecture, including deployment, configuration, optimisation, and ongoing management of SD-WAN fabric across all sites.
• Manage and continuously improve firewall infrastructure, including rule-base management, policy design, segmentation, and regular firewall audits to ensure a tightly controlled network perimeter.
• Lead the firm's security operations function, owning threat detection, incident response, and vulnerability management end-to-end, with network traffic analysis as a core input.
• Monitor, triage, and respond to security events across the network and wider environment, including log analysis, anomaly detection, and threat hunting, with strong awareness of modern and AI-enabled attack vectors.
• Own and drive security hardening across network devices, servers, endpoints, and cloud-adjacent systems, ensuring consistent application of best practices and compliance with security policies.
• Design secure network architecture, embedding segmentation, access control, and security requirements from the outset rather than retrofitting them.
• Conduct regular network and vulnerability assessments and penetration testing exercises, prioritising and remediating findings in a timely manner.
• Manage and continuously improve security tooling, including SIEM, EDR, IDS/IPS, and endpoint protection platforms, with particular focus on integration with network infrastructure.
• Act as the escalation point for network and security-related incidents across 2nd and 3rd line, providing expert guidance and driving resolution.
• Operate across Windows and Linux (Red Hat/CentOS) environments, ensuring both are maintained to a consistent security baseline and integrate cleanly with network infrastructure.
• Collaborate with infrastructure and technology teams to embed secure network design into project delivery and BAU processes.
• Develop and maintain network and security documentation, including network diagrams, firewall rule documentation, incident response playbooks, SOPs, and runbooks.
• Stay current with evolving networking technologies and the threat landscape, bringing proactive recommendations to improve the firm's network architecture and security posture over time.
• Participate in an on-call rotation to support critical network and security systems and respond to incidents outside business hours.
Requirements
• Minimum 7+ years’ experience in infrastructure, networking, and security roles
• Strong hands-on experience with Windows Server and Linux (Red Hat/CentOS)
• Solid networking knowledge, including TCP/IP, VLANs, VPNs, DNS, DHCP, with practical experience in Cisco environments
• Demonstrated experience implementing and supporting security controls, including:
• Patch management and system hardening
• Endpoint protection and monitoring
• Identity and access management
• Good understanding of cyber security principles, including modern threat landscapes and evolving risks (e.g. automation and AI-driven attack vectors)
• Experience with virtualisation (VMware) and enterprise storage (SAN/NAS)
• Scripting or automation experience (e.g. PowerShell, Bash) is advantageous
• Experience in financial services or regulated environments is preferred
• Strong troubleshooting skills with a structured and analytical approach
• Able to balance BAU responsibilities with project delivery effectively
• A thoughtful and forward-looking mindset, with the ability to identify risks and propose improvements
• Clear and confident communicator, able to engage with both technical and non-technical stakeholders
• Self-motivated, accountable, and willing to take ownership of issues end-to-end
• Collaborative and adaptable, with a practical and solutions-focused approach
Skills asked for
- penetration testing
- linux
- bash
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.