Mô tả công việc
MỤC ĐÍCH CÔNG VIỆC/ JOB PURPOSE (tối đa 2000 từ/ max 2000 words)
As a Senior GRC Specialist, you are the airport's authority for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).
Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, NIST CSF, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.
Role impact: Your work protects the airport's licence to operate, sustains its national critical-infrastructure obligations, gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.
TRÁCH NHIỆM CHÍNH/ KEY ACCOUNTABILITIES
Governance, Framework & Policy Management (40%)
• Own the cyber security policy, standard and procedure framework (ISO 27001, NIST CSF, IEC 62443)
• Operate the ISMS: scope, risk methodology, SoA, risk treatment plan, internal audit, management review
• Maintain one control library mapped to ISO 27001, Decree 85/2016, Decree 53/2022 and PDPD/PDPL
• Run the exception and waiver process with compensating controls, risk acceptance and expiry dates
• Embed security requirements into SDLC, cloud onboarding, change management and procurement
Risk Management & Third-Party Assurance (30%)
• Maintain the enterprise cyber risk register with scoring, treatment plans and named owners
• Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems
• Determine system security levels under Decree 85/2016 and prepare approval dossiers
• Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal
• Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms
• Track audit, assessment and penetration test findings to closure against severity-based SLAs
Compliance, Audit & Reporting (30%)
• Coordinate internal audits, external audits, certification assessments and regulator inspections
• Maintain the regulatory obligations register and horizon-scan Vietnamese cyber and privacy law
• Report KRIs, KPIs and security posture to the Steering Committee and executive leadership
• Govern security awareness and the phishing simulation programme, including remediation tracking
• Coordinate regulatory incident notification with Legal and maintain BCP/DR governance evidence
Yêu cầu
Qualifications and Experience:
• Bachelor's degree in Information Security, IT, Engineering, Law or Audit
• 6+ years in cyber security governance, risk and compliance, IT audit or ISMS management
• Ownership of an ISMS through at least one full ISO/IEC 27001 certification cycle
• Working knowledge of the Law on Cyber Security, Decree 85/2016, 53/2022 and PDPD/PDPL
• Experience running a third-party / vendor security risk assessment programme
• Preferred: airport, aviation, banking or critical infrastructure; IEC 62443 exposure
Certifications: Preferred
• CISA / CRISC / CISM
• ISO/IEC 27001 Lead Auditor or Lead Implementer
• CISSP / CDPSE / CIPM
Quyền lợi
Thưởng
Cuối năm
Thông tin khác
NGÀY ĐĂNG
31/07/2026
CẤP BẬC
Nhân viên
NGÀNH NGHỀ
Ngân Hàng & Dịch Vụ Tài Chính > Tuân Thủ & Kiểm Soát Rủi Ro
KỸ NĂNG
Cyber Security Governance, Risk Management, Compliance Auditing, Isms Management
LĨNH VỰC
Khác
NGÔN NGỮ TRÌNH BÀY HỒ SƠ
Tiếng Anh
SỐ NĂM KINH NGHIỆM TỐI THIỂU
6
QUỐC TỊCH
Người Việt Nam
Xem thêm
Thông tin chung
Nơi làm việc