Security Engineer / Manager
Role Summary
At Bowtie, we aren't just selling insurance; we're rebuilding it from the ground up. As Hong Kong's first virtual insurer, regulated by the HKIA, security isn't a checkbox for us — it's core infrastructure. The successful candidate will own it end to end: application, cloud, and infrastructure security, monitoring, access, and the regulator and partner relationships that come with the territory.
If you'd rather build and operate a security function yourself than write a strategy deck about one, we should talk.
About the Role
You'll be the accountable, hands-on owner of Bowtie's technical security posture — setting the standard that our SRE and IT teams execute against, and the point of contact when auditors, regulators, or distribution partners come asking.
Your Key Responsibilities Include:
Security Monitoring & Detection
Own the selection and rollout of centralised security monitoring (SIEM) across our critical log sources
Be the accountable owner for triaging and acting on alerts
Privileged Access & Identity
Design and provide implementation details to SRE/IT on privileged access management (PAM) for production and super-admin consoles — brokered, time-bound, and logged
Own our identity architecture: IdP, SSO, SCIM
Application & Cloud Security
Own security integration into our SDLC — code review guardrails, dependency and supply-chain risk
Own cloud security posture review across our AWS environment (IAM, SCP, GuardDuty, CloudTrail, KMS) and our Identity/SaaS/Endpoint Protections
Risk Register & Testing
Define severity definitions and remediation SLOs, track them in a single register, and report on posture regularly
Run a programme of internal security exercises and an external penetration-test rotation
Governance, Response & Partnerships
Lead a joint forum with our SRE and IT teams, and put incident runbooks in place
Be the main point of contact for audits, regulatory reviews, independent security assessments and partner security assessments
About you
Experience & Skills
Application security — SDLC integration, code review, dependency/supply-chain risk; able to run a supply-chain compromise investigation unaided
Cloud security — hands-on with AWS IAM, SCP, GuardDuty, CloudTrail, KMS
Has deployed a SIEM end to end at least once
Has implemented PAM and designed privileged access workflows
Identity — IdP, SSO, SCIM
Strong written and documentary communication
Exposure to Hong Kong financial services regulatory context (HKIA guidelines, cyber risk frameworks, data privacy)
A strong plus: framework literacy (NIST CSF 2.0, ISO/IEC 27001 or similar) with experience running gap assessments and implementation
A strong plus: CNAPP (e.g. Orca), EDR, and vulnerability management tooling
A strong plus: Cloudflare Zero Trust / Gateway / DLP
A strong plus: Google Workspace admin and MDM/BYOD at scale
Comfortable in Python or TypeScript — enough to automate, not just ticket-push
Certifications (CISSP, CISM, AWS Security Specialty, OSCP) are welcome, but hands-on evidence outranks them
The Person
Genuinely hands-on — builds and operates, no ego about unglamorous work
Writes clean, formal English — policy documents and regulator correspondence are a real part of this job
Thinks in risk and cost, not just best practice — comfortable saying a control isn't worth the money, and defending that call
Registers gaps honestly instead of dressing them up
Works across teams without needing a reporting line to get things done
Comfortable pushing back on engineering leads when the risk calls for it
Proposes fixes that can actually be implemented, and follows through to verify they're closed — a finding with no remediation path isn't enough here
Sets guardrails rather than approval gates, and is comfortable operating without close supervision
Language
Strong written and spoken English required. Cantonese preferred, but not required.
We Offer
Apart from a great career path and an opportunity to do good and do well, we also offer:
Competitive package
Flexible work arrangement
Benefits include medical/ dental coverage and wellness programs
Employee discounts
Fun, co-operative, and flexible startup culture
Weekly sharing sessions and regular social gatherings
Excellent learning opportunities with Professional Development Sponsorship
About Bowtie
We are the first licensed virtual insurer (虛擬保險公司) in Hong Kong.
We believe that insurance is fundamentally good, and we are here to bring the good back through our passionate, innovative, and customer-centric team.
By combining our deep domain expertise and our own proprietary modern technology, we are building one of the most iconic, category-defining health insurance companies in Asia.
We take pride in moving fast all the time and our track record in moving ahead in the game. Our digital insurance platform is also ranked #2 in the world in Sia Partners' 2023 report.
As we grow, we're always looking for highly dynamic, hands-on, and passionate talent to join our team. If you are looking for a rewarding career where you will grow together with strong talents from different backgrounds and build products and services that bring a positive impact on the lives of millions of people in Hong Kong / Asia, apply to our opening today!
Information collected will be treated in strict confidence and used solely for recruitment purposes.
The company will retain all applications no longer than 24 months of which will be destroyed thereafter.
We are an equal-opportunity employer. We do not discriminate on the basis of race, sex, disability, or family status in the employment process.
- Locations
- Hong Kong
- Remote status
- Hybrid
About Bowtie Life Insurance Company Limited
Our purpose is simple - we are here to bring back the good of insurance: protecting people and their families.
By combining our deep domain expertise and our modern proprietary technology, we strive to provide better insurance products and world-class insurance experience to the public.
In the past 4+ years, we have been providing a wide range of medical coverage to the Hong Kong public. Our sum assured has exceeded US$5 Billion.
Let's continue to deliver a better insurance experience for all.
Let's Make Insurance Good Again.