Tìm kiếm theo:
Có phải bạn đang tìm
Từ khóa phổ biến
Việc làm nổi bật

Senior IT Security (Techcom Life)

Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank)

Địa điểm làm việc: Hà Nội
Hết hạn: 16/01/2026
Thu nhập: You'll love it
Loại hình: Toàn thời gian
Chức vụ: Nhân viên
Kinh nghiệm: 5 năm

Mô tả công việc

Top 3 Reasons To Join Us
Top-tier banking environment in Vietnam
Challenging opportunities for the "Greater" You
Attractive career path and benefits
The Job

Job Purpose

The job holder is responsible for building, managing, participating in the development of one of the following areas:

a. IS Practice: Evaluate deployment, develop security solutions/Design, test information security/Ensure compliance with security standards (of Vietnam and International)

b. IS Administration: Manage and directly participate in administrative activities on identity and access security/network security/endpoint services and data security

c. IS Engieering: Manage and directly control the implementation of information security policies and standards for applications, infrastructure of company and its partners and suppliers, ensure compliance with the company's information security requirements.

d. IS Red team: Manage and directly perform testing attack activities for technology systems to detect vulnerabilities/weaknesses and provide solution guidance.

e. IS Monitoring: Monitor detecting all attack events/incidents as quickly as possible (realtime) based on events aggregated from security systems as well as other technology components.Then alert relevant departments to investigate and react to that event/incident.

Key Accountabilities (1)

1. Information Security Assurance

- Participate in projects, developing and deploying technology to ensure Information Security for systems to be built, including stages: analysis, building requirements Information security, design Information security, threat modeling, source code review, testing and building controls to ensure Information Security.

- Research and develop necessary information security solutions to prevent attacks and incidents Information security, ensure security and safety for the entire information system of the company.

- Coordinate with the Information Security supervisory department in handling information security incidents.

- Set up and monitor the implementation of company's information security process, regulations, standards, guidelines and policies in accordance with the regulations of the government and international organizations

- Implement and maintain compliance with international standards PCI-DSS, ISO, SWIFT CSP.

- Implement and maintain compliance with company's policies, circulars and regulations by law.

- Regularly perform compliance and integrity checks

of the security policy configuration in the internal system company detects violations or insider attacks.

- Coordinate with Compliance Assessment and Risk Management units to assess the compliance of technology systems according to policies, regulations, standards, processes, checklists.

Key Accountabilities (2)

2. Information Security Red team:

- Implement the strategy to ensure information security:

+ Participate in the implementation of the Information Security strategy by providing input data on attack trends, forms of exploitation and risks arising in each period.

+ Participate in the implementation of the annual information security implementation plan, meet the business and operational needs of the company through the implementation of information security testing programs for the technology activities of the company.

+ Develop penetration testing methods, information security scanning scripts and security checks according to international standards such as OSSTMM, Sans and OWASP.

+ Develop new techniques, exploit scripts and programs for automated penetration testing

- Perform test attack activities:

+ Directly perform vulnerability detection review, vulnerability assessment, and conduct penetration/exploit testing periodically or at the request of the Block leader for all systems/applications ; Penetration testing for system/application after live detection or whenever undergoing a major change. Testing methods must ensure practicality including both technical (technology) and non-technical (people, processes, physical assets). From there, provide CISO as well as other Information Security departments to have programs to deal with the problems of system weaknesses that can be exploited.

+ Perform regular vulnerability scans, information security checks to find vulnerabilities in the system and provide remedial / remedial solutions; supports maintaining compliance with world security standards such as PCI-DSS, ISO27001, SCP (swift).

+ Develop and manage vulnerability management program, threat intelligence database. Collect, track metrics, and analyze trends on cyber defenses, threats, detected attacks, vulnerabilities, and countermeasures/preventions.

+ Actively research / find new vulnerabilities, exploitation techniques and cyber threats; Identify trends in cybersecurity involving tactics, techniques, and processes, targeting for malware development and deployment.

+ Directly participate in the experimental plan of responding to an Information Security incident as an attack unit and in the case of an actual Information Security incident as the response team. Coordinate and provide expert cyber defense engineering skills to resolve cyber attack incidents

Key Accountabilities (3)

3. Information Security Administration

- Building/adjusting and implementing authoritization matrix of systems.

- Develop requirements and measures to control access and protect the company's data.

- Develop, maintain and optimize information security policy/rule/configuration for solutions to ensure information security such as: Information security solutions on access identity management (PAM, IAM...); Network information security solutions (Firewall, NAC, APT, NetIPS, DDOS...); Information Security solutions on endpoints (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security...); Information security solutions on data (DLP, FAM...).

- Assess, evaluate, review:

+ Decentralization enforcement ensures compliance with the decentralized matrix.

+ The issue and withdrawal of privileged accounts and digital certificates on technology systems.

+ Exception requirements related to identity, access rights on technology systems

+ Change requirements on information security assurance solutions.

- Risk management and compliance

+ Identify risks of the department in the process of operation, ensuring compliance with the processes and regulations of the company. Coordinate with relevant units to handle risks.

+ Perform risk treatment activities according to reports of internal/external audit departments.


Your Skills and Experience

- Graduated in IT, Computer Science or Telecommunications

- Strong knowledge of application, network, and system security.

- Hands-on experience in penetration testing and vulnerability assessment.

- Preferred certifications: OSCP, CEH, or equivalent.

- Foreign language: English: Level 1 - TOEIC under 550

- Having ISC2 SSCP security certificates is an advantage

Experience:

- Experience in performing security testing in financial / service / telecommunications organizations from 5 years. The experience includes the following aspects:

+ Research, design, implement and evaluate Information security for systems and applications

+ Implement PCI-DSS, ISO, Swift CSP... Participate in the development and control of compliance with security standards for IT systems

- Experience in performing security testing in financial / service / telecommunications organizations. The experience includes the following aspects:

+ Experience in researching security holes, developing attack techniques/tools, performing attack testing of technology systems by technical and non-technical measures)

- Having experience in implementing, managing, and operating in-depth in terms of policies, set of rules, configuration of information security at least one of the following areas at financial/service/telecommunications organizations (5 years):

- Security solutions for access identity management (PAM, IAM...);

- Network security solutions (Firewall, NAC, APT, NetIPS, DDOS...);

- Security solutions for terminals (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security...);

- Data security solutions (DLP, FAM...).

- Experience in information security assessment according to Agile method


Why You'll Love Working Here

WHY BECOME IT/DATA EXPERTS AT TECHCOMBANK?

  • Investing over 500 million USD to develop large-scale IT projects, Techcombank is one of the leading bank in Technology trends in Vietnam
  • You will grow with Techcombank by having the opportunity to learn from top experts from across the world
  • Techcombank provides a rewarding remuneration structure that commensurate with your achievement and contribution
  • Techcombank is the Top 2 Best place to work in the banking industry where you can experience various exciting activities throughout the year: Company anniversary, Team building, Active Saturday , Year End Party, etc.

Yêu cầu

Information Security, Firewall, Security , Pentest, Cybersecurity

Quyền lợi

WHY BECOME IT/DATA EXPERTS AT TECHCOMBANK?

  • Investing over 500 million USD to develop large-scale IT projects, Techcombank is one of the leading bank in Technology trends in Vietnam
  • You will grow with Techcombank by having the opportunity to learn from top experts from across the world
  • Techcombank provides a rewarding remuneration structure that commensurate with your achievement and contribution
  • Techcombank is the Top 2 Best place to work in the banking industry where you can experience various exciting activities throughout the year: Company anniversary, Team building, Active Saturday , Year End Party, etc.

Thông tin chung

  • Thu nhập: You'll love it

Cách thức ứng tuyển

Ứng viên nộp hồ sơ trực tuyến bằng cách bấm nút Ứng tuyển bên dưới:
Hạn nộp: 16/01/2026
Giới thiệu công ty Xem trang công ty
Ngân hàng thương mại cổ phần Kỹ Thương Việt Nam (hay còn được gọi là Techcombank; mã giao dịch: TCB) là một ngân hàng thương mại cổ phần của Việt Nam, được thành lập năm 1993 với số vốn ban đầu 20 tỷ đồng.
Quy mô công ty
Từ 5000 - 10000 nhân viên

Các thông tin được cung cấp chỉ nhằm mục đích cho người dùng tham khảo, JobOKO không đại diện và không có sự liên quan tới doanh nghiệp ngân hàng thương mại cổ phần kỹ thương việt nam (techcombank) trong các hoạt động tuyển dụng. Các thông tin bản quyền, nhãn hiệu hoặc bất kỳ quyền sở hữu trí tuệ nào liên quan đến nội dung, thương hiệu hay hình ảnh doanh nghiệp này không thuộc sở hữu của JobOKO.

Người dùng cần tự xác minh thông tin trước khi ứng tuyển, giao dịch hoặc đưa ra bất kỳ quyết định nào dựa trên các nội dung này.

Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank)
Địa chỉ công ty: Số 6 Phố Quang Trung, Phường Cửa Nam, TP Hà Nội, Việt Nam

Phúc lợi dành cho bạn

  • Thưởng
HOT

Job hot

Công ty cổ phần JobOKO Toàn cầu
Thỏa thuận
Hà Nội
CÔNG TY CỔ PHẦN X-MEDIA
9.000.000đ - 12.000.000đ/tháng
Hà Nội
Ngân hàng TMCP Đông Nam Á - SeABank
10 - 20 triệu VND
Hà Nội, Hồ Chí Minh
CÔNG TY CỔ PHẦN MINH PHÚC TRANSFORMATION
7 - 10 triệu VND
Hà Nội
CÔNG TY CỔ PHẦN X-MEDIA
Thỏa thuận
Hà Nội

Job liên quan

Công ty Cổ phần công nghệ KiotViet
20 - 40 triệu
Hà Nội
Công Ty TNHH Bảo Hiểm Nhân Thọ MB Ageas Life
Cạnh tranh
Hà Nội
Tổng Công ty Sản xuất thiết bị Viettel - Tập đoàn Công nghiệp - Viễn thông Quân đội (VIETTEL)
Cạnh tranh
Hà Nội
CÔNG TY CÔNG NGHỆ THÔNG TIN ĐIỆN LỰC MIỀN BẮC - CHI NHÁNH TỔNG CÔNG TY ĐIỆN LỰC MIỀN BẮC
Thoả thuận
Hà Nội

Việc làm tương tự

MB Life
Thỏa Thuận
20/12/2025
Hà Nội
CÔNG TY CỔ PHẦN TẬP ĐOÀN VÀNG BẠC ĐÁ QUÝ DOJI
25 triệu - 30 triệu
21/12/2025
Hà Nội
Ngân hàng Thương mại Cổ phần Kỹ Thương Việt Nam (Techcombank)
Thỏa thuận
24/01/2026
Hà Nội
CÔNG TY CỔ PHẨN TẬP ĐOÀN MK
$ 1,000-1,600 /tháng
20/12/2025
Hà Nội
CÔNG TY CỔ PHẦN CÔNG NGHỆ THÔNG TIN ĐÔNG NAM Á (SEATECH)
Thương lượng
08/01/2026
Hà Nội
CÔNG TY CỔ PHẦN CÔNG NGHỆ TÀI CHÍNH VNFITE
Thỏa thuận
20/12/2025
Hà Nội
Công ty TNHH Chứng khoán Ngân hàng TMCP Ngoại thương Việt Nam (Vietcombank Securities VCBS)
500 - 2000
26/12/2025
Hà Nội
TỔNG CÔNG TY TRUYỀN THÔNG (VNPT - MEDIA)
Thỏa thuận
20/12/2025
Hà Nội
Công ty TNHH MTV Thông tin M3
Thỏa Thuận
17/12/2025
Hà Nội
CÔNG TY TNHH XUẤT NHẬP KHẨU THƯƠNG MẠI YÊN PHÁT
18 - 25 triệu
31/12/2025
Hà Nội

Giải thưởng
của chúng tôi

Giải đồng

Chương trình Make in Viet-Nam 2023

Top 3

Nền tảng số tiêu biểu của Bộ TT&TT 2022

Top 10

Doanh nghiệp khởi nghiệp sáng tạo Việt Nam - Hội đồng tư vấn kinh doanh ASEAN bình chọn

Top 10

Dự án xuất sắc nhất Viet-Solutions 2020 - Chương trình Chuyển đổi số  Quốc gia của Bộ TT&TT