About Viettel Cyber Security
With a proven track record of preventing over 25,000 cyberattacks annually, managing more than 1,000 websites and 16,000 applications, and serving over 100 enterprise clients-including government agencies, major corporations, and industry leaders across the banking, finance, insurance, and securities sectors-Viettel Cyber Security (VCS) is a leading provider of cybersecurity services in Vietnam.
Project Overview - Autonomous SOC
Viettel Cyber Security is developing Autonomous SOC, an Agentic AI platform for Security Operations, with the goal of enabling end-to-end automation across the Detection → Reasoning → Response lifecycle.
Rather than using AI solely as an assistant for Security Analysts, the project focuses on building a system where AI Agents can analyze, reason, coordinate, and execute Security tasks through defined workflows, while remaining governed by Human-in-the-loop mechanisms, Guardrails, and Access Controls.
As the Security Domain Expert, you will be responsible for translating your Security Operations knowledge and hands-on experience into workflows, frameworks, and operational principles for the Autonomous SOC.
A deep AI background is not required; knowledge or experience in AI/LLM/Agentic AI is an advantage.
Location: Hanoi, Vietnam
Job Description:
Standardize Security Operations: Analyze Detection, Triage, Investigation, and Incident Response activities to design operational workflows and structured decision frameworks.
Establish Security Frameworks & Methodologies: Standardize security tasks, competencies, decision criteria, and escalation paths based on industry standards (NIST/NICE Frameworks) and global best practices.
Design Governance & Control Mechanisms: Define authorization rules, risk tiers, Human-in-the-Loop triggers, and safety guardrails required for safe security automation.
Develop Security Benchmarks & Testing Scenarios: Create evaluation criteria and benchmark scenarios to measure the accuracy, performance, and reliability of automated security processes.
Cross-Functional Engineering Collaboration: Translate security domain knowledge into clear technical specifications for AI and
Software Engineering teams implementing the Autonomous SOC platform.
Continuous Optimization: Analyze operational metrics and real-world incident cases to continuously refine security workflows, decision frameworks, and control mechanisms.
Requirements & Skills:
Professional Qualifications
At least 3+ years of hands-on experience in Security Operations (SOC), Incident Response, Threat Detection, Threat Hunting, or Security Engineering.
Deep expertise in SOC operational workflows with a proven ability to formalize operational knowledge into standardized workflows and decision frameworks.
Strong analytical, systematic thinking, and risk-assessment capabilities with an evidence-based approach to decision-making.
Demonstrated ability to operate within structured frameworks and methodologies rather than relying purely on ad-hoc personal experience.
Strong technical communication skills to translate security requirements into actionable technical solutions for engineering teams.
Security Knowledge & Frameworks
Good understanding of the NIST Cybersecurity Framework, NIST NICE Framework, or equivalent cybersecurity frameworks/standards.
Experience developing or standardizing Security Processes, Security Workflows, Security Playbooks/Runbooks.
Understanding of Risk Assessment, Incident Response, Security Controls, Access Control, and Least Privilege.
Knowledge of AI/LLM/Agentic AI or experience participating in Security Automation projects is a strong advantage.
Key Skills
Strong ability to analyze and systematize complex Security problems.
Ability to make evidence-based and risk-based decisions.
Strong technical/business writing skills, with the ability to produce clear business requirements and technical specifications.
Strong communication and collaboration skills, with the ability to work effectively across Security, AI, Software Engineering, and Product/Service Owner teams.
Proactive mindset with a strong interest in researching emerging technologies and continuously improving Security processes and capabilities.
Why Join Autonomous SOC?
1/ Pioneer Next-Gen AI Security: Work at the forefront of Agentic AI x Cybersecurity. Direct how AI Agents analyze, reason, and autonomously execute security workflows alongside top-tier AI and Engineering talent.
2/ Impact at Enterprise Scale: Build production-grade solutions deployed across VCS's massive customer ecosystem- protecting critical infrastructure across Banking, Government, and Enterprise sectors.
3/ Collaborate with World-Class Experts: Work alongside elite cybersecurity researchers (Pwn2Own champions and top vulnerability researchers) in an environment that heavily promotes research, technical sharing, and continuous professional development.