Nhân viên bảo mật

Phòng ban:
Phòng An toàn thông tin

Thời gian:
27/07/2026 - 31/08/2026

Địa điểm:
Hồ Chí Minh

Số lượng:
1
Application Security
- Implement and operate application security solutions including WAF, DDoS protection, and PAM (Privileged Access Management).
- Monitor privileged access activities, detect abnormal behavior, and escalate security risks.
- Collaborate with development and infrastructure teams to ensure security-by-design across the application lifecycle (SDLC/DevSecOps).
- Support application vulnerability assessment activities and track remediation progress.
Compliance & Policy Management
- Support the development, maintenance, and updates of information security policies and procedures.
- Ensure compliance with internal security standards and external regulatory requirements (e.g., audit requirements, SSC, Stock Exchange regulations if applicable).
- Prepare documentation and reports for internal and external audits.
Security Monitoring & Reporting
- Monitor application-related security events and access activities.
- Analyze and report security risks, vulnerabilities, and incidents to management.
- Track remediation status of identified security issues and ensure timely resolution.
Security Awareness & Training
- Support the execution of information security awareness programs for employees.
- Assist in developing training materials and communication related to application security best practices.
Project Support & Implementation
- Participate in research, testing, and deployment of new application security solutions.
- Support security-related initiatives in digital transformation and system upgrade projects.
- Contribute to security requirement definition in IT and business projects.
Technical Knowledge
- Strong understanding of web application security and OWASP Top 10.
- Experience with security tools such as WAF, PAM, DDoS protection, SIEM is an advantage.
- Knowledge of SDLC / DevSecOps processes.
- Familiarity with information security standards such as ISO 27001, NIST, CIS and compliance frameworks.
Skills
- Strong analytical and problem-solving skills in security incidents and vulnerabilities.
- Ability to collaborate with cross-functional teams.
- Strong reporting and documentation skills. Detail-oriented with strong logical thinking.
Education & Experience
- Bachelor’s degree in Information Technology, Computer Science, Information Security, or related fields.
- 2–5 years of experience in Application Security, Information Security, or IT Security roles.
Preferred Qualifications (Advantage)
- Certifications in Application Security (CEH, eWPT, eJPT, BSCP or equivalent).
- ISO/IEC 27001 Lead Implementer / Lead Auditor or CISA.
- SC-300 (Identity & Access Management) certification or IAM/PAM experience.
- Experience in banking, securities, fintech, or regulated financial environments.
- Working time: 05 days/week (Monday to Friday).
- Opportunity for promotion and career development.
- Competitive Income.
- Attractive Bonus’s Policy and 13th salary
- Compulsory insurances full salary (Social Insurance, Health Insurance, Unemployment Insurance) based on the Labor Code and PVI Health Insurance based on the Company's regulations (employee and 1 dependent).
- Public holidays based on the Labor Code, 16 Annual leave days based on the Company's regulation, 5-year-employee has 01 more annual leave day.
- 01 birthday leave
- Company Team Building Trip every year.
- Training sponsorship programs: Securities certificates, Soft skills, Technical skills (actual tuition fee), Korean or English language (15ml/year).
- Postgraduate training (30ml/year).
- Professional and dynamic working environment.
- Salary: Negotiation.

