Senior/Lead Information Security Engineer

Hồ Chí Minh
Thỏa thuận
5 năm kinh nghiệm
Hạn nộp hồ sơ: 01/10/2026 (Còn 10 ngày)
Ứng tuyển sớm để được ưu tiên
Kết nối với Nhà tuyển dụng để tìm hiểu thông tin và gia tăng cơ hội trúng tuyển
OMess
Nhà tuyển dụng đang online

Mô tả công việc

Tóm tắt công việc
Role Overview
Fundiin is evolving from a BNPL product into a multi-product consumer financial platform - and with that evolution comes increasing regulatory scrutiny, higher expectations from lenders and partners, and a growing attack surface that needs to be managed proactively.
As Information Security & Compliance Lead, you will play a pivotal role in shaping Fundiin's security function - building on existing practices and certifications to establish a comprehensive, proactive framework that scales with the business. You will own the security and compliance posture end-to-end, working closely with engineering, DevOps, and external vendors to ensure Fundiin can scale into regulated financial services with confidence.
Fundiin already holds ISO 27001 and PCI-DSS certifications and has established security practices in place - this role is not about starting from zero, but about bringing structure, ownership, and a proactive mindset to what exists, and building what is still missing.
For the right person, this is a rare opportunity to own and shape an entire security function at a high-growth fintech - with direct visibility to the CTO and meaningful impact on how Fundiin scales into regulated financial markets.
This is a role for someone who is technically grounded, ownership-oriented, and comfortable leading through influence rather than headcount.
What You Will Do
1. Vulnerability & Threat Management
Own the vulnerability management program - define scope, tooling, SLAs, and remediation workflows; coordinate with DevOps and vendors for execution
Monitor CVE feeds and vendor advisories; assess impact on Fundiin's tech stack and drive timely remediation
Define security requirements and acceptance criteria for CI/CD pipeline - coordinate with DevOps to implement scanning and security gates
2. Security Operations & Access Control
Define monitoring requirements and detection rules; coordinate with SOC vendor for 24/7 coverage; lead incident response when escalated
Own the access control framework - enforce least privilege, conduct periodic access reviews, and ensure clean offboarding
Define and enforce policies for developer access to production environments and sensitive data
3. Data Security & Privacy
Own the data security framework - define classification, encryption, masking, and export control policies for customer PII and eKYC data
Drive NĐ 13/2023 compliance - own data mapping, DPIA, and consent management; coordinate with product and engineering for implementation
4. Policy, Governance & Compliance
Define and maintain security policies, rules, and checklists across the organization
Own renewal and maintenance of ISO 27001 and PCI-DSS certifications; drive compliance with local regulatory requirements - coordinate with external auditors and consultants as needed
Define and standardize compliance checklists for lender onboarding; coordinate responses to audit and security questionnaires from partners
Maintain risk register and track remediation status; report regularly to management
5. Awareness & Reporting
Define and drive the security awareness program - coordinate training and secure coding sessions for the engineering team
Deliver regular risk, vulnerability, and remediation status reports to management
Serve as primary point of contact for internal and external audits
At Fundiin, we believe in fostering a dynamic work environment that encourages personal and professional growth.
Empowerment and Growth:
We offer great autonomy, freedom to make decisions, room to take risks and learn from mistakes.
Get involved from the ground up in creating and developing new products, leading teams, working on innovative projects, and gaining visibility within the industry.
Competitive Benefits:
Enjoy a robust benefits package, including meaningful ESOP options.
Access our premium health care program and annual health checkup.
Receive a budget of 2,400,000 VND per year for professional development.
Take advantage of device allowances or financing options covering up to 50% of new device purchases.
Engaging Work Environment:
Participate in our monthly Town Hall meetings and collaborative sharing sessions.
15 days of annual leave to recharge and pursue personal interests, plus an extra day for every 3 years of service.
Join biannual team-building trips for bonding and connections.
Enjoy free daily drinks and weekly TGIF snacks and beverages.

Yêu cầu

Must Have
3-5+ years of experience in information security with hands-on technical depth - vulnerability management, access control, log monitoring, and incident response
Strong understanding of common attack vectors and security controls - OWASP Top 10, CVE management, secure architecture principles
Experience in fintech, banking, or a regulated financial environment
Familiarity with at least one compliance framework - ISO 27001, PCI-DSS, or equivalent - sufficient to maintain and operate, not just document
Able to drive programs forward without a dedicated team - comfortable coordinating across engineering, product, and external vendors to get things done
Strong ownership mindset - identifies gaps proactively, drives resolution, does not wait to be told what to do
Nice To Have
Security teams within fintech or financial technology companies: In-house security teams at reputable banks , Reputable security service providers, Fintech security teams in Fintech companies
Candidates with strong hands-on technical depth in incident response, and combined with exposure to security and compliance frameworks.
Familiarity with AI-powered security tools - vulnerability scanning (Snyk or equivalent), threat detection, or security operations - and comfortable using LLMs to accelerate security workflows such as threat analysis, policy drafting, and reporting
Familiarity with GCP security tools - Cloud Audit Logs, Security Command Center, Cloud DLP
Experience with CI/CD security integration - SAST, DAST, dependency scanning
Knowledge of NĐ 13/2023 and Vietnamese regulatory requirements for financial services
Security certifications - CISSP, CISM, ISO 27001 Lead Implementer, or equivalent

Thông tin khác

Information Security
OWASP
ISO
Architecture
CISSP
GCP
Fintech
CISM
PCI
Snyk
CVE
CI/CD
DLP
LLM
DAST
SAST

Thông tin chung

  • Thu nhập: Thỏa Thuận

Nơi làm việc

  • Tầng 7, tòa Lottery Tower, 77 Trần Nhân Tôn, An Dong, Ho Chi Minh

Công Ty Cổ Phần Fundiin

Xem trang công ty
Địa chỉ công ty: 17 Bà Huyện Thanh Quan, P.6, Q.3, TPHCM
Quy mô: Từ 10 - 25 nhân viên
Lĩnh vực: IT phần mềm, Kinh doanh
Thông tin công việc
Vị trí:
Nhân viên
Hình thức làm việc:
Toàn thời gian
Việc làm tương tự
Application Security Engineer
CÔNG TY CỔ PHẦN CON CƯNG
Hồ Chí Minh
CÔNG TY CỔ PHẦN CON CƯNG
Cạnh tranh
Infrastructure Cyber Security Engineer DevSecOps
CÔNG TY TNHH NHÓM MÂY
Hồ Chí Minh, Long An
CÔNG TY TNHH NHÓM MÂY
You'll love it
Medior Enterprise Security Architect
De Heus Asia
Hồ Chí Minh
De Heus Asia
You'll love it
[2026_TTVHCNTT]_CV Kiểm soát An ninh thông tin - Giám sát An toàn thông tin - SOC Chi tiết công việc | Vietcombank
Ngân hàng TMCP Ngoại thương Việt Nam - Vietcombank
Hà Nội, Hồ Chí Minh, Nước Ngoài
Ngân hàng TMCP Ngoại thương Việt Nam - Vietcombank
Thỏa thuận
DevSecOps Engineer
CÔNG TY CỔ PHẦN CON CƯNG
Hồ Chí Minh
CÔNG TY CỔ PHẦN CON CƯNG
Thỏa Thuận
Cảnh báo dấu hiệu lừa đảo tuyển dụng
Thu phí và cung cấp thông tin
  • Phí hồ sơ, đồng phục, đặt cọc.
  • Yêu cầu nộp bản gốc giấy tờ.
  • Cung cấp mã OTP.
Hứa hẹn trúng tuyển 100%
  • Không yêu cầu trình độ.
  • Không cần thử việc.
Phỏng vấn bất thường
  • Địa điểm xa văn phòng công ty.
  • Phỏng vấn qua Telegram.
Yêu cầu làm nhiệm vụ
  • Tải app, nạp tiền.
  • Làm nhiệm vụ nhận thưởng.
Tin tuyển dụng sơ sài
  • Mô tả công việc chung chung
  • Nhiệm vụ đơn giản, thu nhập khủng
  • Lỗi chính tả, đánh máy.
Đội ngũ hỗ trợ của JobOKO sẵn sàng đồng hành, tư vấn và giới thiệu những cơ hội việc làm phù hợp, giúp Ứng viên tự tin phát triển sự nghiệp và chinh phục mục tiêu nghề nghiệp bền vững.
Đội ngũ hỗ trợ của JobOKO luôn chủ động tư vấn các giải pháp tuyển dụng tối ưu, cam kết đồng hành và hỗ trợ Quý Nhà tuyển dụng đạt được hiệu quả tuyển dụng bền vững.