
Hồ Chí Minh
Nghỉ trọn T7, CN
Hạn chót 24/09/2026
Đăng 1 tháng trước
Ít hơn 20 ứng viên
- Bachelor's or Technical Degree Required (IT, Cryptography, computer science, information systems, business administration or other industry-related curriculum) - 5 years or more of working experience in IT security banking, good knowledge international IT security standards (ISO 270001, PCI-DSS,…), ITIL - Good knowledge about: network security, system security, application security and virus/malwares, secure coding - Expert with architect, security technology, integration - Good knowledge with pen test with OWSAP Standard and ability discovery & exploit vulnerabilities, cyber attack - Good using some tools for hacking: VA, APPScan, Metaexploit, kalilinux - Experienced in implementing ISO27000/PCI-DSS is preferred - Good knowledge with secure coding with some languages: Python, Shell, PHP and have good knowledge with encryption, cryptography techniques - Stakeholder expectation management - People Management - Risk Management - Budget Management - Ability to read and understand the professional documents in English. - Strong interpersonal and communication skill - Ability to catch up and manage works quickly and effectively - Ability to work independently with high pressure, good in teamwork - Careful, responsible, and secure in protecting information/data belong to Bank - Good knowledge of risk management principles, methodology and practice
Experienced in implementing ISO27000/PCI-DSS
OBJECTIVES: • Work with product team to build technical solution for new features; directly work on those implementations; Do code review, participate in operation to ensure the system works effectively COMMUNICATION: • Motivate, monitor and control the compliance of IT Security in processes, implementation and operations • Ensure that development and operation processes are compliant with policy/circulars/guidance/regulations • Mitigate risks and protect users & systems by motivations, guidance, monitoring and controls AppSecEngineering: • Vulnerability assessment and penetration testing program and responsible for the design and performance of application security robustness tests : Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired and wireless networks, and mobile applications/devices • Develop and maintain security testing plans • Automate penetration and other security testing on networks, systems and applications • Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk • Produce actionable, threat-based, reports on security testing results • Act as a source of direction, training, and guidance for less experienced staff • Mentor and coach other IT security staff to provide guidance and expertise in their growth • Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation • Communicate security issues to a wide variety of internal and external “customers” to include technical teams, executives, risk groups, vendors and regulators • Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests • Foster and maintain relationships with key stakeholders and business partners InfraSecEngineering: • Cybersecurity risk and compliance framework and management: Identify, highlight and remediate information security risk in the Bank Policy, Standards and Processes: • Comply with the Bank’s Information Security Policy, Regulations, Standards, and Process • Provide feedback to enhance the current policies, regulations, standards and processes where necessary • Communicate and ensure all staff understands and comply with the Information Security Policy, Regulations, Standards and Processes Operations, Reporting and Administration • Ensure that the Information Security Strategy and Plans are implemented as planned. • Ensure that Information Security process are followed diligently. This may include Risks Management, Operating Security Services/Tools to support the Information Security Program of the Bank. • Control approve the request/changes related to security, control activities of IT security: implementing, operating, vulnerabilities management • Contribute to the IT Security Dash Board for Management • Work with both internal/external audit during audit programs • Training IT security awareness • Collect, analyze and produce report for IT Security every month • Ngày làm việc: • Giờ làm việc: • Cấp bậc: • Loại công việc:
Nếu bạn đang tìm kiếm vị trí IT Security Expert (Appsec/Infrasec) tại Hồ Chí Minh, đây là cơ hội làm việc tại FE CREDIT với mức lương cạnh tranh và môi trường làm việc chuyên nghiệp. Ngoài tin tuyển dụng này, Upzi còn cập nhật nhiều việc làm cùng lĩnh vực và địa điểm mỗi ngày.
Probation with full salary. Lunch allowance. 13th month salary + KPIs bonus. Performance rewards and awards
Healthcare Insurance
Wedding support. Family funeral support
1,000 - 2,200 USD/tháng
Hồ Chí Minh
Nghỉ trọn T7, CN