Mô tả công việc
Security Monitoring & Operations
Continuously monitor systems through IDS/IPS, SIEM, and other security tools.
Detect and respond to security incidents: malware, brute force attacks, DDoS, phishing, web attacks, and transaction anomalies.
Manage, configure, and upgrade security and network devices, including NGFW firewalls, VPN, switches, and anti-DDoS systems.
Monitor security for trading systems (OMS/Trading Core), partner API connections, online trading platforms, and mobile applications.
Risk Assessment & Control
Conduct security risk assessments for new systems and IT projects.
Coordinate with external vendors to perform penetration testing and vulnerability assessments.
Track, analyze, and remediate vulnerabilities (CVE, Zero-day).
Review and assess cloud infrastructure security.
Regulatory Compliance & Audit
Ensure compliance with regulations, including Circular 13/2022/TT-BTC and requirements from SSC, Stock Exchanges, and VSD.
Maintain alignment with standards such as ISO 27001 and SOC 2.
Develop and update Information Security (IS) procedures: access management, risk management, incident response, backup, and disaster recovery.
Access & Privilege Management
Manage system access rights across the domain, CRM, email, databases, and trading systems.
Perform periodic access reviews and user attestation.
Implement and manage MFA and privileged account management (PAM).
Incident Response
Execute incident response procedures and conduct root cause analysis (RCA).
Report incidents to SSC/HOSE/VSD when trading activities are affected.
Security Awareness
Conduct internal security awareness training on anti-phishing, email safety, and risk identification.
Yêu cầu
Strong knowledge of Cybersecurity, IT Risk Management, and Internal Controls.
Proficient with core security tools: Firewall, IDS/IPS, WAF, SIEM, DLP/DDP, VPN.
Good understanding of Web/App Security (OWASP Top 10) and API Security.
Experience with Linux/Windows servers, database security (Oracle/MS SQL/PostgreSQL), and networking (TCP/IP, routing, VLAN...).
Understanding of securities system architecture (OMS, trading core, clearing & settlement).
Penetration testing experience is an advantage.
Preferred Certifications: CEH/OSCP/Security+/CySA+.
Languages: Good at English.
Soft skills: Analytical thinking, fast incident response, good documentation skills, and effective communication.
Quyền lợi
Competitive salary based on capabilities.
Salary review 1-2 times per year.
Lunch allowance, parking allowance, phone allowance, and other types of allowances, depending on job position.
Annual health check-ups, 24/24 accident insurance (health insurance), and social insurance with 100% of the salary package. Private health insurance is provided by PJICO.
Opportunities to participate in professional and career skill training programs organized by the company.
Financial support for attending external training programs.
Participation in sports, entertainment, and travel activities such as team connection events, birthday celebrations, team-building, holiday gifts, etc., to promote health and strengthen employee engagement.
KPI bonus based on work results.
Leave policy:
12 days/year for staff-level positions.
15 days/year for managerial positions.
Bảo hiểm xã hội, Bảo hiểm sức khỏe, Bảo hiểm sức khỏe ngưởi thân, Bảo hiểm full lương, Khám sức khỏe định kỳ, Team building, Du lịch hàng năm, Thưởng hiệu quả làm việc
Thông tin khác
Thời gian làm việc
Thứ 2 - Thứ 6 (từ 08:00 đến 17:00)
Thông tin chung
Nơi làm việc
- - Hồ Chí Minh: Phu My Hung Tower , 8 Hoàng Văn Thái, Phường Tân Mỹ
Cách thức ứng tuyển
Ứng viên nộp hồ sơ trực tuyến bằng cách bấm nút Ứng tuyển bên dưới:
Hạn nộp: 10/01/2026