Security Architecture

Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank)

Thỏa thuận
25/05/2026
Toàn thời gian
Key Accountabilities (1)
Why This Role: Security governance is currently squeezed into regular domain reviews. Security requirements are reactive ("add security to the design") rather than proactive ("here are the security standards, build against them"). Payment Card Industry Data Security Standard (PCI-DSS), Anti-Money Laundering (AML), and banking secrecy regulations require dedicated security governance. This role ensures security standards are published upfront, embedded in reference architectures, and consistently applied across all designs.
Responsibilities:
+ Security Reference Architectures: Develop and maintain reference architectures for each domain that embed security controls (authentication, authorization, encryption, audit, secrets management). SAs use these as starting points, not as afterthought add-ons.
+ Security Standards & Checklists: Publish domain-specific security checklists (e.g., "Building a microservice in Domain 5? Here are the 12 required security controls"). Tier 1 self-approval checklists include security checklist items.
+ Security Review in Tier 2/Tier 3: Participate in Tier 2 reviews (with Domain EA) and Tier 3 reviews (with ARB) to assess architectural security. This is dialogue, not veto - Security Lead and Domain Lead solve design problems together.
+ Threat Modeling: Conduct threat modeling workshops for high-risk designs (Tier 3, or any design involving payment/regulatory data). Use STRIDE or similar framework. Document threats and mitigations in the architecture decision record.
+ Security Policy Development: Work with Compliance, Risk, and IT Security teams to translate regulatory requirements (SBV banking secrecy, PCI-DSS, AML) into architectural policies and standards.
+ Third-Party Security Assessment: Lead security architecture assessments for new vendors, cloud platforms, or technology selections. Provide security evaluation input to PoC process (works with Emerging Tech Lead).
+ ARB Participation: Attend every ARB meeting to present security architecture updates, discuss security review findings, and provide security perspective on high-complexity designs.
+ Incident Root-Cause Liaison: When security incidents occur, work with IR team to identify whether the root cause was an architectural control gap. Feed findings back into reference architecture updates.
Success Metrics (6-month review):Security reference architectures developed for 2-3 high-risk domains (Domain 1, Domain 4, Domain 5)Security checklists published and integrated into Tier 1 self-approval workflow% of Tier 2/Tier 3 designs with documented threat modeling: 100% (for high-risk designs)Spot-check audits find security control compliance: 95%+No post-implementation security architecture gaps discovered in spot-check audits
Success Profile - Qualification and Experiences

Qualifications
- Graduated in Information Technology or Banking
Work Experience
- Understand the bank's IT development strategy and roadmap in the next 5 years
- Able to propose solution architecture for some main business areas of the bank such as Payment, BPM, DW, Risks, Lending...
- Ability to coordinate with other units to carry out the work from ideation, to design and operation.
- Having expertise, deep understanding of analysis, design, selection of technical solutions
- At least 8 years of experience in practical implementation of many key solutions in end-to-end banking from business to application and deployment layer such as card, core, internet banking, data warehouse...
- Strong verbal and written communication, collaboration, and leadership skills with Technical teams and Business teams
- Experience guiding/teaching others in architecture principles, such as roadmaps, technical standards, non-functional requirements, and solution diagramming/documentation
- Demonstrated success working with standard software development lifecycle models, deliverables/artifacts and tools, SOA concepts and design patterns
- Experience designing scalable/reliable/flexible/secure solutions across heterogeneous hardware platforms , operating systems, middlewares, and infrastructure technologies
- Technical experience with architecture, technology stacks, or overall architectural governance
- Experience with cloud computing and/or other virtualization technologies
- Experience establishing and documenting standards, guidelines, and best practices

Language level
English, according to TCB's regulations in each period

Thông tin chung

  • Thu nhập: Thỏa thuận

Việc làm tương tự

Kỹ Sư An Ninh Thông Tin

NetNam Corporation

Từ $ 20tr /tháng
Hà Nội
08/05/2026

Phó Phòng Chính Trị Nhân Sự

Công ty An ninh mạng Viettel- Chi nhánh Tập đoàn Công nghiệp- Viễn thông quân đội

Thoả thuận
Hà Nội
24/05/2026

Chuyên viên Bảo mật Thông tin - [BAC A BANK - Khối Ngân hàng Số]

Ngân Hàng Thương Mại Cổ Phần Bắc Á

thỏa thuận
Hà Nội
15/05/2026

Project Manager - Dự Án Phần Mềm

Công ty An ninh mạng Viettel- Chi nhánh Tập đoàn Công nghiệp- Viễn thông quân đội

Thoả thuận
Hà Nội
20/06/2026

Kỹ sư kiểm thử xâm nhập hệ thống (ATTT)

CÔNG TY CÔNG NGHỆ THÔNG TIN VNPT (VNPT-IT)

Thỏa thuận
Hà Nội, Hồ Chí Minh
23/06/2026

Senior Officer, DevSecOps

Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank)

Thỏa thuận
Hà Nội
25/06/2026

Project Manager - Dự Án Phần Mềm

Công ty An ninh mạng Viettel- Chi nhánh Tập đoàn Công nghiệp- Viễn thông quân đội

Thoả thuận
Hà Nội
20/06/2026

Kỹ sư Nghiên cứu phát triển An toàn thông tin

CÔNG TY CÔNG NGHỆ THÔNG TIN VNPT (VNPT-IT)

Thỏa thuận
Hà Nội
23/06/2026

Kỹ sư An ninh thông tin

CÔNG TY CÔNG NGHỆ THÔNG TIN VNPT (VNPT-IT)

Thỏa thuận
Hà Nội
22/06/2026

Kỹ sư Nghiên cứu phát triển An toàn thông tin

CÔNG TY CÔNG NGHỆ THÔNG TIN VNPT (VNPT-IT)

Thỏa thuận
Hà Nội
23/06/2026
Vị trí Security Architecture do công ty Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank) tuyển dụng tại Hà Nội, Joboko tự động tổng hợp mức lương Thỏa thuận, tìm thêm việc làm về Security Architecture hoặc công ty Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank) ở các link phía trên

Giới thiệu công ty

Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank)

Địa chỉ: Số 6 Phố Quang Trung, Phường Cửa Nam, TP Hà Nội, Việt Nam
Quy mô: Trên 10.000 nhân viên

Việc làm HOT

CÔNG TY CỔ PHẦN VATECH VIỆT
10 - 15 triệu VND + Hoa Hồng
Hà Nội, Hồ Chí Minh, Đà Nẵng
CÔNG TY CỔ PHẦN VATECH VIỆT
Negotiable
Hà Nội, Hồ Chí Minh
Công ty Cổ phần Y Dược Vietlife
Thỏa thuận
Hà Nội
CÔNG TY TNHH APP SYSTEMS SERVICES (VIETNAM)
20 triệu VND (thương lượng) + Phụ Cấp + Hoa Hồng + Thưởng
Hà Nội
CÔNG TY TNHH VĂN HÓA TRUYỀN THÔNG JOY FLAME
13 - 18 triệu VND + 1.5% hoa hồng doanh thu Idol + Thưởng
Hồ Chí Minh