
Hồ Chí Minh
Nghỉ trọn T7, CN
Hạn chót 16/10/2026
Đăng 6 ngày trước
Ít hơn 5 ứng viên
- University degree, preferably in Information Security, Information Technology, or a related technical field. - Relevant certifications strongly preferred: ISO 27001 Lead Auditor, ITIL 4, Personal Data Protection Expert (VnDPO), or equivalent. - Minimum 5 years of experience in IT Governance, IT Risk & Compliance, or Information Security Management — preferably in banking, financial services, or consumer finance. - Proven hands-on experience in developing and maintaining Information Security policies aligned with SBV regulations and international standards. - Demonstrated experience conducting internal security & compliance audits, IT risk assessments, and supporting external/independent audits. - Practical knowledge of Access Control management (user reviews, role matrix, IAM, privileged access management). - Experience with third-party/vendor risk management and security compliance assessments. - Familiarity with industry frameworks and standards: ISMS (ISO 27001), ITSM (ITIL), PCI-DSS. - Experience in process design and documentation. - Working knowledge of project methodologies and tools; familiarity with change management processes (e.g., Change Advisory Board participation) is a plus. - Strong analytical and problem-solving skills; ability to translate complex regulatory requirements into practical controls. - Excellent communication, negotiation, and stakeholder management skills. - Strong written communication in both English and Vietnamese is essential (policy drafting, audit reporting). - Planning, organizing, and time management skills; ability to work independently and drive initiatives. - Adaptability and a continuous learning mindset.
Working knowledge of project methodologies and tools; familiarity with change management processes
Objectives - Implement and maintain governance, policy, and risk management functions across teams within the IT Division — ensuring appropriate policies and controls are in place for effective service delivery and regulatory compliance, while continuously monitoring, coordinating, and executing required enhancements to improve performance, reduce issues, and mitigate IT-wide risks. Key Responsibilities - Policy & Regulatory Compliance - Develop, review, and update Information Security policies, regulations, and procedures in compliance with State Bank of Vietnam (SBV) requirements, Vietnamese laws (including Decree 13 on Personal Data Protection), and international standards (ISO 27001, PCI-DSS). - Prepare and maintain regulatory documentation such as Personal Data Processing Impact Assessment (DPIA) dossiers, and liaise with responsible authorities on personal data protection matters. - Advise and guide colleagues across the IT Division on issued policies, procedures, and standards, ensuring they are implemented correctly and consistently. - Governance Frameworks & Assessments - Execute IT governance frameworks and internal/international standards, monitoring closely to ensure effective implementation across IT functions. - Conduct Information Security and IT compliance assessments against legal and regulatory requirements. - Perform technology risk assessments based on the company's operational risk management framework; propose appropriate controls to mitigate identified risks. - Audit and evaluate the effectiveness of personal data protection measures and security controls. - Risk Monitoring & Reporting - Collaborate with relevant stakeholders to periodically report Key Risk Indicators (KRIs) and IT risk posture to management. - Act as focal point for monitoring and supervising the remediation of findings from internal audits, independent audits, and other inspections. - Periodically report on high-risk IT incidents and compliance status. - Awareness & Capability Building - Develop and deliver Information Security awareness training materials and programs for all staff. - Communicate governance activities and policy changes within the IT Division, ensuring teams understand how these affect IT services and deliverables. - Continuous Improvement - Analyze and improve existing IT policies, procedures, and practices; recommend changes to align with evolving standards and best practices. - Stay updated on new regulations and industry best practices to recommend proactive improvements. - Work closely with cross-functional IT departments to develop and coordinate a compliance schedule tailored to applicable regulations and standards. • Ngày làm việc: • Giờ làm việc: • Cấp bậc: • Loại công việc:
Nếu bạn đang tìm kiếm vị trí IT Security Governance Expert tại Hồ Chí Minh, đây là cơ hội làm việc tại FE CREDIT với mức lương cạnh tranh và môi trường làm việc chuyên nghiệp. Ngoài tin tuyển dụng này, Upzi còn cập nhật nhiều việc làm cùng lĩnh vực và địa điểm mỗi ngày.
Probation with full salary. Lunch allowance. 13th month salary + KPIs bonus. Performance rewards and awards
Healthcare Insurance
Wedding support. Family funeral support