Vietnam Job Openings
Techcombank
Senior Officer, Information Security (40001098)
August 26, 2024
Senior Officer, Information Security (40001098)
Job Purpose
a. IS Practice: Evaluate deployment, develop security solutions/Design, test information security/Ensure compliance with security standards (of Vietnam and International)
b. IS Administration: Manage and directly participate in administrative activities on identity and access security/network security/endpoint services and data security
c. IS Engieering: Manage and directly control the implementation of information security policies and standards for applications, infrastructure of Techcombank and its partners and suppliers, ensure compliance with the Bank's information security requirements.
d. IS Red team: Manage and directly perform testing attack activities for technology systems to detect vulnerabilities/weaknesses and provide solution guidance.
e. IS Monitoring: Monitor detecting all attack events/incidents as quickly as possible (realtime) based on events aggregated from security systems as well as other technology components.Then alert relevant departments to investigate and react to that event/incident.
Key Accountabilities (1)
- Participate in projects, developing and deploying technology to ensure Information Security for systems to be built, including stages: analysis, building requirements Information security, design Information security, threat modeling, source code review, testing and building controls to ensure Information Security.
- Research and develop necessary information security solutions to prevent attacks and incidents Information security, ensure security and safety for the entire information system of the bank.
- Coordinate with the Information Security supervisory department in handling information security incidents.
- Set up and monitor the implementation of TCB's information security process, regulations, standards, guidelines and policies in accordance with the regulations of the government and international organizations
- Implement and maintain compliance with international standards PCI-DSS, ISO, SWIFT CSP.
- Implement and maintain compliance with TCB's policies, circulars and regulations of the State Bank.
- Regularly perform compliance and integrity checks
- Coordinate with Compliance Assessment and Risk Management units to assess the compliance of technology systems according to policies, regulations, standards, processes, checklists.
Key Accountabilities (2)
- Implement the strategy to ensure information security:
+ Participate in the implementation of the annual information security implementation plan, meet the business and operational needs of the bank through the implementation of information security testing programs for the technology activities of the bank. Bank.
+ Develop penetration testing methods, information security scanning scripts and security checks according to international standards such as OSSTMM, Sans and OWASP.
+ Develop new techniques, exploit scripts and programs for automated penetration testing
- Perform test attack activities:
+ Perform regular vulnerability scans, information security checks to find vulnerabilities in the system and provide remedial / remedial solutions; supports maintaining compliance with world security standards such as PCI-DSS, ISO27001, SCP (swift).
+ Develop and manage vulnerability management program, threat intelligence database. Collect, track metrics, and analyze trends on cyber defenses, threats, detected attacks, vulnerabilities, and countermeasures/preventions.
+ Actively research / find new vulnerabilities, exploitation techniques and cyber threats; Identify trends in cybersecurity involving tactics, techniques, and processes, targeting for malware development and deployment.
+ Directly participate in the experimental plan of responding to an Information Security incident as an attack unit and in the case of an actual Information Security incident as the response team. Coordinate and provide expert cyber defense engineering skills to resolve cyber attack incidents
Key Accountabilities (3)
- Building/adjusting and implementing MTPQ of systems.
- Develop requirements and measures to control access and protect the bank's data.
- Develop, maintain and optimize information security policy/rule/configuration for solutions to ensure information security such as: Information security solutions on access identity management (PAM, IAM…); Network information security solutions (Firewall, NAC, APT, Net IPS, DDOS...); Information Security solutions on endpoints (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security…); Information security solutions on data (DLP, FAM...).
- Assess, evaluate, review:
+ The issue and withdrawal of privileged accounts and digital certificates on technology systems.
+ Exception requirements related to identity, access rights on technology systems
+ Change requirements on information security assurance solutions.
- Risk management and compliance
+ Perform risk treatment activities according to reports of internal/external audit departments.
Key Relationships - Direct Manager
Key Relationships - Direct Reports
Key Relationships - Internal Stakeholders
Key Relationships - External Stakeholders
Success Profile - Qualification and Experiences
- Graduated in IT, Computer Science or Telecommunications
- Foreign language: English: Level 1 – TOEIC under 550
- Certificates in information security such as OSCP, PCI DSS assessment implementation certificate, ISO
- Having ISC2 SSCP security certificates is an advantage
- Having certificates of companies providing security solutions such as Microsoft/Cisco/Palo Alto/Checkpoint/Cyberark/Sailpoint…”
Experience:
- Experience in performing security testing in financial / service / telecommunications organizations from 5 years. The experience includes the following aspects:
+ Implement PCI-DSS, ISO, Swift CSP... Participate in the development and control of compliance with security standards for IT systems
- Experience in performing security testing in financial / service / telecommunications organizations. The experience includes the following aspects:
- Having experience in implementing, managing, and operating in-depth in terms of policies, set of rules, configuration of information security at least one of the following areas at financial/service/telecommunications organizations (5 years):
- Security solutions for access identity management (PAM, IAM...);
- Network security solutions (Firewall, NAC, APT, Net IPS, DDOS...);
- Security solutions for terminals (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security...);
- Data security solutions (DLP, FAM...).
- Experience in information security assessment according to Agile method"
New Job Alerts
KMS Technology
Principal Automation Test Engineer, KMS Solutions
FULL TIME
November 18, 2024
View Job DescriptionLittleBig Connection
Experienced Java Backend Developer [F/M/X]
November 18, 2024
View Job DescriptionNVG Technology
Mid/Senior Android Engineer - 100% (w/m/d)
FULL TIME
November 18, 2024
View Job DescriptionOUJI (VIETNAM) COMPANY LIMITED
Kế toán tổng hợp- General Accountant - Nhận việc ngay
FULL TIME
November 18, 2024
View Job DescriptionLooking for similar job?
Bảo Hiểm Nhân Thọ Tương Hỗ Dai-Ichi Life
PHỤ TRÁCH CAO CẤP PHÁT TRIỂN KINH DOANH (BUSINESS DEVELOPMENT SENIOR OFFICER)
FULL TIME
August 31, 2024
View Job DescriptionSee What’s New: Techcombank Job Opportunities
Techcombank
Expert, Market and Liquidity Risk Analysis (40000794)
October 16, 2024
View Job DescriptionNew Job Alerts
KMS Technology
Principal Automation Test Engineer, KMS Solutions
FULL TIME
November 18, 2024
View Job DescriptionLittleBig Connection
Experienced Java Backend Developer [F/M/X]
November 18, 2024
View Job DescriptionNVG Technology
Mid/Senior Android Engineer - 100% (w/m/d)
FULL TIME
November 18, 2024
View Job DescriptionOUJI (VIETNAM) COMPANY LIMITED
Kế toán tổng hợp- General Accountant - Nhận việc ngay
FULL TIME
November 18, 2024
View Job Description