
Hà Nội
Có làm T7
Hạn chót 09/10/2026
Đăng 14 ngày trước
Ít hơn 20 ứng viên
- Bachelor’s degree in Information Security, IT, Engineering, Law or Audit - 4+ years in cyber security governance, risk and compliance, IT audit or ISMS management - Ownership of an ISMS through at least one full ISO/IEC 27001 certification cycle - Working knowledge of the Law on Cyber Security, Decree 85/2016, 53/2022 and PDPD/PDPL - Experience running a third-party / vendor security risk assessment programme
- Preferred: airport, aviation, banking or critical infrastructure; IEC 62443 exposure
As a Senior GRC Specialist, you are responsible for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT). Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators. Role impact: Your work gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity. Key Accountabilities Governance, Framework & Policy Management (40%) - Own the cyber security policy, standard and procedure framework (ISO 27001, IEC 62443 etc) - Operate the ISMS (ISO 27001) full life cycle: scope, risk methodology, SoA, risk treatment plan, internal audit, management review - Run the exception and waiver process with compensating controls, risk acceptance and expiry dates Risk Management & Third-Party Assurance (30%) - Maintain the enterprise cyber risk register with scoring, treatment plans and named owners - Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems - Determine system security levels under Decree 85/2016 and prepare approval dossiers - Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal - Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms - Track audit, assessment and penetration test findings to closure against severity-based SLAs Compliance, Audit & Reporting (30%) - Coordinate internal audits, external audits, certification assessments and regulator inspections - Report KRIs, KPIs and security posture to the Steering Committee and executive leadership - Govern security awareness and the phishing simulation programme, including remediation tracking • Ngày làm việc: • Giờ làm việc: • Cấp bậc: • Loại công việc:
Nếu bạn đang tìm kiếm vị trí Senior GRC Specialist (Cyber Security) tại Hà Nội, đây là cơ hội làm việc tại Công ty Cổ Phần Hạ Tầng Hàng Không Masterise với mức lương cạnh tranh và môi trường làm việc chuyên nghiệp. Ngoài tin tuyển dụng này, Upzi còn cập nhật nhiều việc làm cùng lĩnh vực và địa điểm mỗi ngày.
Cuối năm