Vietnamworks's top banner
VietnamWorks - Nền tảng tuyển dụng, việc làm, tra cứu lương & tư vấn nghề nghiệp hàng đầu Việt NamVietnamWorks - Nền tảng tuyển dụng, việc làm, tra cứu lương & tư vấn nghề nghiệp hàng đầu Việt Nam
Tất cả địa điểm
VietnamWorks inTECH - việc làm IT trên VietnamWorks.comVietnamWorks inTECH - việc làm IT trên VietnamWorks.com
Tất cả danh mục
Nhà tuyển dụng
Để xem nhiều việc làm cho Intern, Fresher và người dưới 3 năm kinh nghiệm

Senior IT Security (Techcom Life)

Thương lượng

Hết hạn trong 19 ngày
194 lượt xem
Hà Nội
Trang Văn hóa công ty

Mô tả công việc

Job Purpose

The job holder is responsible for building, managing, participating in the development of one of the following areas:

a. IS Practice: Evaluate deployment, develop security solutions/Design, test information security/Ensure compliance with security standards (of Vietnam and International)

b. IS Administration: Manage and directly participate in administrative activities on identity and access security/network security/endpoint services and data security

c. IS Engieering: Manage and directly control the implementation of information security policies and standards for applications, infrastructure of Techcombank and its partners and suppliers, ensure compliance with the Business's information security requirements.

d. IS Red team: Manage and directly perform testing attack activities for technology systems to detect vulnerabilities/weaknesses and provide solution guidance.

e. IS Monitoring: Monitor detecting all attack events/incidents as quickly as possible (realtime) based on events aggregated from security systems as well as other technology components. Then alert relevant departments to investigate and react to that event/incident.

Key Accountabilities (1)

1. Information Security Assurance

- Participate in projects, developing and deploying technology to ensure Information Security for systems to be built, including stages: analysis, building requirements Information security, design Information security, threat modeling, source code review, testing and building controls to ensure Information Security.

- Research and develop necessary information security solutions to prevent attacks and incidents Information security, ensure security and safety for the entire information system of the Business.

- Coordinate with the Information Security supervisory department in handling information security incidents.

- Set up and monitor the implementation of TCB's information security process, regulations, standards, guidelines and policies in accordance with the regulations of the government and international organizations

- Implement and maintain compliance with international standards PCI-DSS, ISO, SWIFT CSP.

- Implement and maintain compliance with TCB's policies, circulars and regulations of the State Bank.

- Regularly perform compliance and integrity checks of the security policy configuration in the internal system TCB detects violations or insider attacks.

- Coordinate with Compliance Assessment and Risk Management units to assess the compliance of technology systems according to policies, regulations, standards, processes, checklists.

Key Accountabilities (2)

2. Information Security Red team:

- Implement the strategy to ensure information security:

+ Participate in the implementation of the Information Security strategy by providing input data on attack trends, forms of exploitation and risks arising in each period.

+ Participate in the implementation of the annual information security implementation plan, meet the business and operational needs of the bank through the implementation of information security testing programs for the technology activities of the Business.

+ Develop penetration testing methods, information security scanning scripts and security checks according to international standards such as OSSTMM, Sans and OWASP.

+ Develop new techniques, exploit scripts and programs for automated penetration testing

- Perform test attack activities:

+ Directly perform vulnerability detection review, vulnerability assessment, and conduct penetration/exploit testing periodically or at the request of the Block leader for all systems/applications; Penetration testing for system/application after live detection or whenever undergoing a major change. Testing methods must ensure practicality including both technical (technology) and non-technical (people, processes, physical assets). From there, provide CISO as well as other Information Security departments to have programs to deal with the problems of system weaknesses that can be exploited.

+ Perform regular vulnerability scans, information security checks to find vulnerabilities in the system and provide remedial / remedial solutions; supports maintaining compliance with world security standards such as PCI-DSS, ISO27001, SCP (swift).

+ Develop and manage vulnerability management program, threat intelligence database. Collect, track metrics, and analyze trends on cyber defenses, threats, detected attacks, vulnerabilities, and countermeasures/preventions.

+ Actively research / find new vulnerabilities, exploitation techniques and cyber threats; Identify trends in cybersecurity involving tactics, techniques, and processes, targeting for malware development and deployment.

+ Directly participate in the experimental plan of responding to an Information Security incident as an attack unit and in the case of an actual Information Security incident as the response team. Coordinate and provide expert cyber defense engineering skills to resolve cyber attack incidents

Key Accountabilities (3)

3. Information Security Administration

- Building/adjusting and implementing MTPQ of systems.

- Develop requirements and measures to control access and protect the Business's data.

- Develop, maintain and optimize information security policy/rule/configuration for solutions to ensure information security such as: Information security solutions on access identity management (PAM, IAM…); Network information security solutions (Firewall, NAC, APT, NetIPS, DDOS...); Information Security solutions on endpoints (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security…); Information security solutions on data (DLP, FAM...).

- Assess, evaluate, review:

+ Decentralization enforcement ensures compliance with the decentralized matrix.

+ The issue and withdrawal of privileged accounts and digital certificates on technology systems.

+ Exception requirements related to identity, access rights on technology systems

+ Change requirements on information security assurance solutions.

- Risk management and compliance

+ Identify risks of the department in the process of operation, ensuring compliance with the processes and regulations of the Business. Coordinate with relevant units to handle risks.

+ Perform risk treatment activities according to reports of internal/external audit departments.

Yêu cầu công việc

Qualification:

• Graduated in IT, Computer Science or Telecommunications

• Foreign language: English: Level 1 – TOEIC under 550

• Certificates in information security such as OSCP, PCI DSS assessment implementation certificate, ISO

• Having ISC2 SSCP security certificates is an advantage

• Having certificates of companies providing security solutions such as Microsoft/Cisco/PaloAlto/Checkpoint/Cyberark/Sailpoint…

• Having certificates in information security such as - SANS SEC660, SEC760, SANS SEC642, SANS SEC575, OSCE, OSCP

Experience:

• Experience in performing security testing in financial / service / telecommunications organizations from 5 years. The experience includes the following aspects:

+ Research, design, implement and evaluate Information security for systems and applications

+ Implement PCI-DSS, ISO, Swift CSP... Participate in the development and control of compliance with security standards for IT systems

• Experience in performing security testing in financial / service / telecommunications organizations. The experience includes the following aspects:

+ Experience in researching security holes, developing attack techniques/tools, performing attack testing of technology systems by technical and non-technical measures)

• Having experience in implementing, managing, and operating in-depth in terms of policies, set of rules, configuration of information security at least one of the following areas at financial/service/telecommunications organizations (5 years):

- Security solutions for access identity management (PAM, IAM...);

- Network security solutions (Firewall, NAC, APT, NetIPS, DDOS...);

- Security solutions for terminals (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security...);

- Data security solutions (DLP, FAM...).

• Experience in information security assessment according to Agile method

Phân tích mức độ cạnh tranh

VietnamWorks AI

  • Bạn phù hợp bao nhiêu % cho vị trí này?

  • Bạn xếp hạng Top bao nhiêu so với những hồ sơ ứng tuyển?

  • Thị trường đang trả mức lương bao nhiêu cho vị trí tương tự?

  • Nhu cầu tuyển dụng cho vị trí này trên thị trường cao hay thấp?

Giá

29.000đ / lượt

Các phúc lợi dành cho bạn

Khác

Company's Policy

Thông tin việc làm

04/11/2025

Nhân viên

Công Nghệ Thông Tin/Viễn Thông > Bảo Mật Công Nghệ Thông Tin

English, Information Security, Network Security, Penetration Testing, Vulnerability Scanning

Dịch vụ Y tế/Chăm sóc sức khỏe

Bất kỳ

5

Không giới hạn

Địa điểm làm việc

Hà Nội, Hanoi, Vietnam

Từ khoá:
Trang chủViệc làmDịch vụ Y tế/Chăm sóc sức khỏeTechcombankSenior IT Security (Techcom Life)
Techcombank
Techcombank
Techcombank

Số 6 Quang Trung, phường Trần Hưng Đạo, Quận Hoàn Kiếm, Thành Phố Hà Nội

(Xem bản đồ)
HR DEPT
Trang Văn hóa công ty

Nhận diện một số hình thức lừa đảo

Lừa đảo thu phí

Đưa ra lời mời làm việc dễ dàng bất thường, đãi ngộ cao, kèm theo yêu cầu nộp các loại phí.

Xem chi tiết
Trang chủViệc làmDịch vụ Y tế/Chăm sóc sức khỏeTechcombankSenior IT Security (Techcom Life)
tìm việc làmtuyển dụngthần số họccv xin việcmẫu cvviệc làm bắc giangviệc làm hưng yênviệc làm bà rịa vũng tàuviệc làm quảng ngãiviệc làm nam địnhviệc làm huếviệc làm thái bìnhviệc làm ninh bìnhviệc làm hà tĩnhviệc làm tphcmviệc làm đà nẵngviệc làm hải phòngviệc làm cần thơviệc làm bình dươngtìm việc làm tại hà nộiviệc làm nhân viên kinh doanhtuyển dụng kế toán trưởngviệc làm salestuyển dụng marketingtuyển dụng content marketingtuyển dụng nhân sựtuyển dụng kế toán tổng hợptuyển dụng kiểm toántuyển dụng truyền thôngviệc làm qa qctuyển dụng brand marketingtuyển dụng hr managerviệc làm ngành maytuyển dụng marketing managerviệc làm giáo dụcviệc làm partimetuyển dụng nhân viên thiết kếtuyển dụng tài chínhviệc làm tự động hóaviệc làm báo chítuyển dụng kiểm toán ngân hàngviệc làm in ấndata analystCông ty CP Navigos Group Việt Nam. Địa chỉ: Tầng 20, tòa nhà e.town Central, 11 Đoàn Văn Bơ, Phường 13, Quận 4, TP. HCM. Giấy CNĐKDN số 0304836029 do Sở Kế Hoạch và Đầu Tư Thành phố Hồ Chí Minh cấp lần đầu ngày 11/12/2006
  • Tìm việc làm
  • Tìm theo khu vực
  • VietnamWorks
  • Về VietnamWorks
  • Về VietnamWorks inTECH
  • Liên Hệ
  • Hỏi Đáp
  • Thỏa Thuận Sử Dụng
  • Quy Định Bảo Mật
  • Quy Chế Hoạt Động Sàn Giao Dịch Thương Mại Điện Tử VietnamWorks
  • Sơ Đồ Trang Web
  • Dành cho Nhà tuyển dụng
  • Đăng tuyển dụng
  • Tìm kiếm hồ sơ
  • Sản phẩm Dịch vụ khác
  • Liên hệ
  • Việc làm theo khu vực
  • Hồ Chí Minh
  • Hà Nội
  • Hải Phòng
  • Đà Nẵng
  • Cần Thơ
Xem tất cả khu vực
  • Việc làm theo ngành nghề
  • Kế toán
  • Ngân hàng
  • Phần mềm máy tính
  • IT Support / Help Desk
  • Xây dựng
Tìm việc làm
  • Ứng dụng di động
  • Ứng dụng di độngỨng dụng di độngỨng dụng di độngỨng dụng di động
  • Chứng nhận bởi
  • Chứng nhận bởi
  • Theo dõi Vietnamworks trên
  • VietnamWorks's FacebookVietnamWorks's LinkedinVietnamWorks's TiktokVietnamWorks's YoutubeVietnamWorks's Spotify
Powered by
Kết Nối Với VietnamWorks
VietnamWorks's FacebookVietnamWorks's LinkedinVietnamWorks's TiktokVietnamWorks's YoutubeVietnamWorks's Spotify
Copyright © Công Ty Cổ Phần Navigos Group Việt Nam
Tầng 20, tòa nhà E.Town Central, 11 Đoàn Văn Bơ, Phường 13, Quận 4, TP.HCM, Việt Nam

VietnamWorks Logo© VietnamWorks
VietnamWorks inTECH Logo
Powered by