Mô tả công việc
1. Develop Information Security Policies, Standards, and Regulations
• Participate in the development, review, and update of the information security (IS) and personal data protection strategies, policies, procedures, standards, and guidelines.
• Monitor and analyze domestic and international regulations, standards, and best practices relating to information security, cybersecurity, and personal data protection, and recommend appropriate adoption across the NCI.
• Translate regulatory (e.g., Law on Cybersecurity 2025, Decree 85/2016/NĐ-CP, Circular 12/2022/TT-BTTTT, Circular 09/2020/TT-NHNN), governance, and technical requirements into internal policies, control requirements, implementation guidelines, and operational standards.
2. Monitor Information Security Compliance
• Plan and participate in information security compliance reviews, audits, and assessments, such as information security assessments and information security risk assessments, personal data protection compliance assessments.
• Track and follow up on the remediation of identified non-conformities, security vulnerabilities, compliance gaps, and information security risks.
• Prepare compliance reports, risk alerts, and recommendations to strengthen information security governance.
• Coordinate the implementation of, and ensure the protection of, data subjects' rights.
• Coordinate the preparation and updating of Personal Data Processing Impact Assessment (DPIA) dossiers and Cross-Border Personal Data Transfer Impact Assessment (CDTIA) dossiers.
3. Information Security Risk Management
• Participate in identifying, assessing, classifying, and monitoring information security risks affecting critical information systems, data assets, business services, and technology platforms.
• Recommend appropriate risk treatment and mitigation measures based on risk impact and likelihood.
• Develop and monitor the implementation of risk mitigation plans.
4. Information Security Review for IT Systems, Projects, and Solutions
• Review information security requirements incorporated into the design, architecture, and technical solutions of IT systems and projects.
• Participate in security assessments of IT solutions, products, services, and information systems before and during implementation.
• Recommend security control requirements based on system criticality, data sensitivity, and implementation scope.
5. Monitor Information Security Incidents and Corrective Actions
• Organize the implementation of technical measures for personal data security, personal data protection standards and technical standards, and incident response plans for personal data protection incidents.
• Monitor the Security Information and Event Management (SIEM) system to enable the early detection of cybersecurity threats.
• Monitor, consolidate, and analyze information security incidents, policy violations, and security weaknesses identified during system operations.
• Participate in information security incident response, coordinate with technical teams and system owners to identify root causes, contain the incident, assess business impact, and implement corrective actions.
• Recommend preventive measures at the policy, process, technology, and organizational levels to prevent recurrence.
• Receive reports of, report to the competent authorities on, and coordinate the handling of personal data protection violations or personal data breaches/leakage incidents.
6. Implement Information Security Programs
• Participate in organizing information security assessments, security exercises, awareness campaigns, training programs, personal data protection training and capacity-building programs, and communication initiatives.
• Support the development of a strong information security culture and promote security compliance throughout the organization.
7. Participate in the Company's data protection activities.
Yêu cầu
• Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or equivalent work experience.
• Professional certifications for training in information security and/or Data Protection Officer (DPO) are preferred.
• At least 5 years of IT experience in the financial industry as a Technical Architect (TA) on system development projects
• At least 3 years of experience in building and operating open-source, cloud, and virtualization systems
• Excellent problem-solving skills in addressing integration issues between infrastructure and services
• Experience in database and server operation/management
• Strong communication experience required to align IT infrastructure with business requirements
• Ability to collaborate effectively with cross-functional teams, work independently, manage deadlines, and solve problems in a structured and systematic manner.
Salary & Benefit
• Competitive salary package based on candidate's knowledge and skills (open to
negotiation).
• Health Insurance
• Allowance or rewards for birthday, giving birth, wedding, sickness, new years, autumn festival, 1st June, etc.
• Summer Leave: 1-3 days based on seniority
Quyền lợi
Chăm sóc sức khoẻ
Health Insurance
Nghỉ phép có lương
Summer Leave: 1-3 days based on seniority
Khác
Competitive salary package based on candidate's knowledge and skills (open to negotiation).
Allowance or rewards for birthday, giving birth, wedding, sickness, new years, autumn festival, 1st June, etc.
Thông tin khác
NGÀY ĐĂNG
30/07/2026
CẤP BẬC
Trưởng phòng
NGÀNH NGHỀ
Công Nghệ Thông Tin/Viễn Thông > Bảo Mật Công Nghệ Thông Tin
KỸ NĂNG
Information Security Policies, Risk Management, Technical Architecture, Compliance Audits, Database Management
LĨNH VỰC
Tài Chính
NGÔN NGỮ TRÌNH BÀY HỒ SƠ
Bất kỳ
SỐ NĂM KINH NGHIỆM TỐI THIỂU
5
QUỐC TỊCH
Không hiển thị
Xem thêm
Thông tin chung
Nơi làm việc
- Phòng 8008, tầng 8, toà Tây, Lotte Center Hanoi, số 54 đường Liễu Giai, phường Giảng Võ, Hà Nội