Senior GRC Specialist (Cyber Security)

Công ty Cổ Phần Hạ Tầng Hàng Không Masterise

Thương lượng
31/08/2026
Toàn thời gian

Mô tả công việc

MỤC ĐÍCH CÔNG VIỆC/ JOB PURPOSE (tối đa 2000 từ/ max 2000 words)
As a Senior GRC Specialist, you are the airport's authority for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).
Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, NIST CSF, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.
Role impact: Your work protects the airport's licence to operate, sustains its national critical-infrastructure obligations, gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.
TRÁCH NHIỆM CHÍNH/ KEY ACCOUNTABILITIES
Governance, Framework & Policy Management (40%)
• Own the cyber security policy, standard and procedure framework (ISO 27001, NIST CSF, IEC 62443)
• Operate the ISMS: scope, risk methodology, SoA, risk treatment plan, internal audit, management review
• Maintain one control library mapped to ISO 27001, Decree 85/2016, Decree 53/2022 and PDPD/PDPL
• Run the exception and waiver process with compensating controls, risk acceptance and expiry dates
• Embed security requirements into SDLC, cloud onboarding, change management and procurement
Risk Management & Third-Party Assurance (30%)
• Maintain the enterprise cyber risk register with scoring, treatment plans and named owners
• Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems
• Determine system security levels under Decree 85/2016 and prepare approval dossiers
• Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal
• Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms
• Track audit, assessment and penetration test findings to closure against severity-based SLAs
Compliance, Audit & Reporting (30%)
• Coordinate internal audits, external audits, certification assessments and regulator inspections
• Maintain the regulatory obligations register and horizon-scan Vietnamese cyber and privacy law
• Report KRIs, KPIs and security posture to the Steering Committee and executive leadership
• Govern security awareness and the phishing simulation programme, including remediation tracking
• Coordinate regulatory incident notification with Legal and maintain BCP/DR governance evidence

Yêu cầu

Qualifications and Experience:
• Bachelor's degree in Information Security, IT, Engineering, Law or Audit
• 6+ years in cyber security governance, risk and compliance, IT audit or ISMS management
• Ownership of an ISMS through at least one full ISO/IEC 27001 certification cycle
• Working knowledge of the Law on Cyber Security, Decree 85/2016, 53/2022 and PDPD/PDPL
• Experience running a third-party / vendor security risk assessment programme
• Preferred: airport, aviation, banking or critical infrastructure; IEC 62443 exposure
Certifications: Preferred
• CISA / CRISC / CISM
• ISO/IEC 27001 Lead Auditor or Lead Implementer
• CISSP / CDPSE / CIPM

Quyền lợi

Thưởng
Cuối năm

Thông tin khác

NGÀY ĐĂNG
31/07/2026
CẤP BẬC
Nhân viên
NGÀNH NGHỀ
Ngân Hàng & Dịch Vụ Tài Chính > Tuân Thủ & Kiểm Soát Rủi Ro
KỸ NĂNG
Cyber Security Governance, Risk Management, Compliance Auditing, Isms Management
LĨNH VỰC
Khác
NGÔN NGỮ TRÌNH BÀY HỒ SƠ
Tiếng Anh
SỐ NĂM KINH NGHIỆM TỐI THIỂU
6
QUỐC TỊCH
Người Việt Nam
Xem thêm

Thông tin chung

  • Thu nhập: Thương lượng

Nơi làm việc

  • Hanoi, Hanoi, Vietnam

Việc làm tương tự

Nhân viên Dự án Công nghệ thông tin

CÔNG TY CỔ PHẦN TƯ VẤN, XÂY LẮP VIỆT NAM

18 - 25 triệu VNĐ
Hà Nội
29/08/2026

Chuyên Viên Bảo Mật Thông Tin

NGÂN HÀNG TMCP BẮC Á - BAC A BANK

Cạnh tranh
Hà Nội
29/08/2026

Chuyên Gia Kiến Trúc và Giải Pháp An Toàn Thông Tin - K.CNTT

NGÂN HÀNG TMCP ĐẠI CHÚNG VIỆT NAM - PVcomBank

Thương lượng
Hà Nội
13/08/2026

OT Cybersecurity Specialist (Ha Noi & Hai Phong)

Praxis Automation Vietnam Representative Office

Thương lượng
Hà Nội, Hải Phòng
22/08/2026

Chuyên Viên Cao Cấp An Ninh Thông Tin - Tntech - 2V068

Công Ty TNHH Rox

Thương lượng
Hà Nội
09/08/2026

Mid/Senior DevSecOps/ Cloud Security Engineer

CÔNG TY TNHH DR.JOY VIỆT NAM

Up to 60M
Hà Nội
25/08/2026

[PHENIKAA GROUP] CHUYÊN VIÊN AN TOÀN THÔNG TIN (IT RISK)

Chi nhánh Công Ty Cổ phần Y Học Vĩnh Thiện - Bệnh viện Đại học Phenikaa

25 Tr - 40 Tr VND
Hà Nội
27/08/2026

TECHNICAL ENGINEER (INTEGRATION SYSTEM)

Công ty Cổ phần Dịch vụ viễn thông COMIT - COMIT Corporation

Thỏa thuận
Hà Nội
10/08/2026

Chuyên viên cao cấp An ninh thông tin - TNTech - 2V057

CÔNG TY CỔ PHẦN TNTECH

thỏa thuận
Hà Nội
10/08/2026

Cyber Security Specialist

Scandinavian Software Park

You'll love it
Hà Nội
04/09/2026
Vị trí Senior GRC Specialist (Cyber Security) do công ty Công ty Cổ Phần Hạ Tầng Hàng Không Masterise tuyển dụng tại Hà Nội, Joboko tự động tổng hợp mức lương Thương lượng, tìm thêm việc làm về Senior GRC Specialist (Cyber Security) hoặc công ty Công ty Cổ Phần Hạ Tầng Hàng Không Masterise ở các link phía trên

Việc làm HOT

CÔNG TY CỔ PHẦN X-MEDIA
12.000.000 - 16.000.000đ/tháng
Hà Nội
Công ty Cổ Phần Đầu Tư và Xây dựng số 18.3 (LICOGI 18.3)
13 - 18 triệu VND
Hà Nội, Hải Dương, Hưng Yên, Thanh Hóa
CÔNG TY CỔ PHẦN LAI PHÚ
15 - 18 triệu VND
Hồ Chí Minh
Công ty Cổ phần Rau quả Thực phẩm An Giang ANTESCO
Thỏa Thuận
Hồ Chí Minh
Công ty TNHH Suntex
20 - 25 triệu VND
Hưng Yên