IT Security Expert (Appsec/Infrasec)
Hạn nộp hồ sơ: 20/09/2026 (Còn 26 ngày)
Ứng tuyển sớm để được ưu tiên
Kết nối với Nhà tuyển dụng để tìm hiểu thông tin và gia tăng cơ hội trúng tuyển
Nhà tuyển dụng đang online
Mô tả công việc
OBJECTIVES:
• Work with product team to build technical solution for new features; directly work on those implementations; Do code review, participate in operation to ensure the system works effectively
COMMUNICATION:
• Motivate, monitor and control the compliance of IT Security in processes, implementation and operations
• Ensure that development and operation processes are compliant with policy/circulars/guidance/regulations
• Mitigate risks and protect users & systems by motivations, guidance, monitoring and controls
AppSecEngineering:
• Vulnerability assessment and penetration testing program and responsible for the design and performance of application security robustness tests : Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired and wireless networks, and mobile applications/devices
• Develop and maintain security testing plans
• Automate penetration and other security testing on networks, systems and applications
• Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk
• Produce actionable, threat-based, reports on security testing results
• Act as a source of direction, training, and guidance for less experienced staff
• Mentor and coach other IT security staff to provide guidance and expertise in their growth
• Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation
• Communicate security issues to a wide variety of internal and external "customers" to include technical teams, executives, risk groups, vendors and regulators
• Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests
• Foster and maintain relationships with key stakeholders and business partners
InfraSecEngineering:
• Cybersecurity risk and compliance framework and management: Identify, highlight and remediate information security risk in the Bank
Policy, Standards and Processes:
• Comply with the Bank's Information Security Policy, Regulations, Standards, and Process
• Provide feedback to enhance the current policies, regulations, standards and processes where necessary
• Communicate and ensure all staff understands and comply with the Information Security Policy, Regulations, Standards and Processses
Operations, Reporting and Administration
• Ensure that the Information Security Strategy and Plans are implemented as planned.
• Ensure that Information Security process are followed diligently. This may include Risks Management, Operating Security Services/Tools to support the Information Security Program of the Bank.
• Control approve the request/changes related to security, control activities of IT security: implementing, operating, vulnerabilities management
• Contribute to the IT Security Dash Board for Management
• Work with both internal/external audit during audit programs
• Training IT security awareness
• Collect, analyze and produce report for IT Security every month
• Work with product team to build technical solution for new features; directly work on those implementations; Do code review, participate in operation to ensure the system works effectively
COMMUNICATION:
• Motivate, monitor and control the compliance of IT Security in processes, implementation and operations
• Ensure that development and operation processes are compliant with policy/circulars/guidance/regulations
• Mitigate risks and protect users & systems by motivations, guidance, monitoring and controls
AppSecEngineering:
• Vulnerability assessment and penetration testing program and responsible for the design and performance of application security robustness tests : Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired and wireless networks, and mobile applications/devices
• Develop and maintain security testing plans
• Automate penetration and other security testing on networks, systems and applications
• Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk
• Produce actionable, threat-based, reports on security testing results
• Act as a source of direction, training, and guidance for less experienced staff
• Mentor and coach other IT security staff to provide guidance and expertise in their growth
• Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation
• Communicate security issues to a wide variety of internal and external "customers" to include technical teams, executives, risk groups, vendors and regulators
• Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests
• Foster and maintain relationships with key stakeholders and business partners
InfraSecEngineering:
• Cybersecurity risk and compliance framework and management: Identify, highlight and remediate information security risk in the Bank
Policy, Standards and Processes:
• Comply with the Bank's Information Security Policy, Regulations, Standards, and Process
• Provide feedback to enhance the current policies, regulations, standards and processes where necessary
• Communicate and ensure all staff understands and comply with the Information Security Policy, Regulations, Standards and Processses
Operations, Reporting and Administration
• Ensure that the Information Security Strategy and Plans are implemented as planned.
• Ensure that Information Security process are followed diligently. This may include Risks Management, Operating Security Services/Tools to support the Information Security Program of the Bank.
• Control approve the request/changes related to security, control activities of IT security: implementing, operating, vulnerabilities management
• Contribute to the IT Security Dash Board for Management
• Work with both internal/external audit during audit programs
• Training IT security awareness
• Collect, analyze and produce report for IT Security every month
Yêu cầu
Education:
• Bachelor's or Technical Degree Required (IT, Cryptography, computer science, information systems, business administration or other industry-related curriculum)
Experience:
• 5 years or more of working experience in IT security banking, good knowledge international IT security standards (ISO 270001, PCI-DSS,...), ITIL
• Have good knowledge about: network security, system security, application security and virus/malwares, secure coding
• Expert with architect, security technology, integration
• Have good knowledge with pen test with OWSAP Standard and ability discovery & exploit vulnerabilities, cyber attack
• Good using some tools for hacking: VA, APPScan, Metaexploit, kalilinux
• Experienced in implementing ISO27000/PCI-DSS is preferred Have good knowledge with secure coding with some languages: Python, Shell, PHP and have good knowledge with encryption, cryptography techniques
• Stakeholder expectation management
• People Management
• Risk Management
• Budget Management
Skills:
• Have ability to read and understand the professional documents in English.
• Strong interpersonal and communication skill
• Be able to catch up and manage works quickly and effectively
• Be able to work independently with high pressure, good in teamwork
• Careful, responsible, and secure in protecting information/data belong to Bank
• Good knowledge of risk management principles, methodology and practice
• Bachelor's or Technical Degree Required (IT, Cryptography, computer science, information systems, business administration or other industry-related curriculum)
Experience:
• 5 years or more of working experience in IT security banking, good knowledge international IT security standards (ISO 270001, PCI-DSS,...), ITIL
• Have good knowledge about: network security, system security, application security and virus/malwares, secure coding
• Expert with architect, security technology, integration
• Have good knowledge with pen test with OWSAP Standard and ability discovery & exploit vulnerabilities, cyber attack
• Good using some tools for hacking: VA, APPScan, Metaexploit, kalilinux
• Experienced in implementing ISO27000/PCI-DSS is preferred Have good knowledge with secure coding with some languages: Python, Shell, PHP and have good knowledge with encryption, cryptography techniques
• Stakeholder expectation management
• People Management
• Risk Management
• Budget Management
Skills:
• Have ability to read and understand the professional documents in English.
• Strong interpersonal and communication skill
• Be able to catch up and manage works quickly and effectively
• Be able to work independently with high pressure, good in teamwork
• Careful, responsible, and secure in protecting information/data belong to Bank
• Good knowledge of risk management principles, methodology and practice
Quyền lợi
Thưởng
Financial support:
Probation with full salary
Lunch allowance
Wedding support
Family funeral support
13th month salary + KPIs bonus
Performance rewards and awards
Healthcare Insurance
Financial support:
Probation with full salary
Lunch allowance
Wedding support
Family funeral support
13th month salary + KPIs bonus
Performance rewards and awards
Healthcare Insurance
Thông tin khác
Xem thêm
Thông tin chung
- Thu nhập: $ 1,000-2,000 /tháng
Nơi làm việc
- Ho Chi Minh City, Vietnam
Việc làm tương tự khác
CÔNG TY CỔ PHẦN XÂY DỰNG VÀ CÔNG NGHIỆP NSN
Hồ Chí Minh
Thương lượng
Công ty Cổ phần Chứng khoán KIS Việt Nam (KIS Việt Nam)
Hồ Chí Minh
Thương lượng
CÔNG TY TNHH TƯ VẤN KỸ THUẬT APEX SOUTHERN CROSS
Hồ Chí Minh
Negotiable (15 - 40M)
Công ty Cổ phần Chứng khoán VNDIRECT
Hồ Chí Minh
Thương lượng
Công ty TNHH transcosmos Việt Nam
Hồ Chí Minh
7 - 7.1 triệu
Trường Tiểu Học, Trung Học Cơ Sở Và Trung Học Phổ Thông Anh Quốc
Hồ Chí Minh
Thương lượng
EL4 - Software Studio
Hồ Chí Minh, Đà Nẵng
range Up to VND 78,000,000
Công ty Tài chính TNHH Ngân hàng Việt Nam Thịnh Vượng SMBC FE CREDIT
Xem trang công ty- Địa chỉ công ty: Tầng 2, Tòa nhà REE Tower, Số 9 Đoàn Văn Bơ - Phường 12 - Quận 4 - TP. Hồ Chí Minh
- Quy mô: Trên 10.000 nhân viên
- Lĩnh vực: Ngân hàng/ Tài Chính
Thông tin công việc
Vị trí:
Nhân viên
Hình thức làm việc:
Toàn thời gian
Việc làm tương tự
Cảnh báo dấu hiệu lừa đảo tuyển dụng
Đội ngũ hỗ trợ của JobOKO sẵn sàng đồng hành, tư vấn và giới thiệu những cơ hội việc làm phù hợp, giúp Ứng viên tự tin phát triển sự nghiệp và chinh phục mục tiêu nghề nghiệp bền vững.
Hotline CSKH
1900.63.63.84
Công ty Cổ phần JobOKO Toàn cầu
Đội ngũ hỗ trợ của JobOKO luôn chủ động tư vấn các giải pháp tuyển dụng tối ưu, cam kết đồng hành và hỗ trợ Quý Nhà tuyển dụng đạt được hiệu quả tuyển dụng bền vững.
Hotline CSKH
0962.107.888
Công ty Cổ phần JobOKO Toàn cầu