Information Security Manager
Chưa có CV? Tạo CV miễn phí ở đây →
Mô tả công việc
1. Develop Information Security Policies, Standards, and Regulations
• Participate in the development, review, and update of the information security (IS) and personal data protection strategies, policies, procedures, standards, and guidelines.
• Monitor and analyze domestic and international regulations, standards, and best practices relating to information security, cybersecurity, and personal data protection, and recommend appropriate adoption across the NCI.
• Translate regulatory (e.g., Law on Cybersecurity 2025, Decree 85/2016/NĐ-CP, Circular 12/2022/TT-BTTTT, Circular 09/2020/TT-NHNN), governance, and technical requirements into internal policies, control requirements, implementation guidelines, and operational standards.
2. Monitor Information Security Compliance
• Plan and participate in information security compliance reviews, audits, and assessments, such as information security assessments and information security risk assessments, personal data protection compliance assessments.
• Track and follow up on the remediation of identified non-conformities, security vulnerabilities, compliance gaps, and information security risks.
• Prepare compliance reports, risk alerts, and recommendations to strengthen information security governance.
• Coordinate the implementation of, and ensure the protection of, data subjects' rights.
• Coordinate the preparation and updating of Personal Data Processing Impact Assessment (DPIA) dossiers and Cross-Border Personal Data Transfer Impact Assessment (CDTIA) dossiers.
3. Information Security Risk Management
• Participate in identifying, assessing, classifying, and monitoring information security risks affecting critical information systems, data assets, business services, and technology platforms.
• Recommend appropriate risk treatment and mitigation measures based on risk impact and likelihood.
• Develop and monitor the implementation of risk mitigation plans.
4. Information Security Review for IT Systems, Projects, and Solutions
• Review information security requirements incorporated into the design, architecture, and technical solutions of IT systems and projects.
• Participate in security assessments of IT solutions, products, services, and information systems before and during implementation.
• Recommend security control requirements based on system criticality, data sensitivity, and implementation scope.
5. Monitor Information Security Incidents and Corrective Actions
• Organize the implementation of technical measures for personal data security, personal data protection standards and technical standards, and incident response plans for personal data protection incidents.
• Monitor the Security Information and Event Management (SIEM) system to enable the early detection of cybersecurity threats.
• Monitor, consolidate, and analyze information security incidents, policy violations, and security weaknesses identified during system operations.
• Participate in information security incident response, coordinate with technical teams and system owners to identify root causes, contain the incident, assess business impact, and implement corrective actions.
• Recommend preventive measures at the policy, process, technology, and organizational levels to prevent recurrence.
• Receive reports of, report to the competent authorities on, and coordinate the handling of personal data protection violations or personal data breaches/leakage incidents.
6. Implement Information Security Programs
• Participate in organizing information security assessments, security exercises, awareness campaigns, training programs, personal data protection training and capacity-building programs, and communication initiatives.
• Support the development of a strong information security culture and promote security compliance throughout the organization.
7. Participate in the Company's data protection activities.
• Bachelor’s degree in Computer Sc
Yêu cầu công việc
• Bachelor’s degree in Computer Science, Information Technology, Engineering, or a related field, or equivalent work experience.
• Professional certifications for training in information security and/or Data Protection Officer (DPO) are preferred.
• At least 5 years of IT experience in the financial industry as a Technical Architect (TA) on system development projects
• At least 3 years of experience in building and operating open-source, cloud, and virtualization systems
• Excellent problem-solving skills in addressing integration issues between infrastructure and services
• Experience in database and server operation/management
• Strong communication experience required to align IT infrastructure with business requirements
• Ability to collaborate effectively with cross-functional teams, work independently, manage deadlines, and solve problems in a structured and systematic manner.
Salary & Benefit
• Competitive salary package based on candidate’s knowledge and skills (open to
negotiation).
• Health Insurance
• Allowance or rewards for birthday, giving birth, wedding, sickness, new years, autumn festival, 1st June, etc.
• Summer Leave: 1-3 days based on seniority
Quyền lợi
- Chăm sóc sức khoẻ: Health Insurance
- Nghỉ phép có lương: Summer Leave: 1-3 days based on seniority
- Khác: Competitive salary package based on candidate’s knowledge and skills (open to negotiation). Allowance or rewards for birthday, giving birth, wedding, sickness, new years, autumn festival, 1st June, etc.
Nhà tuyển dụng
NICE Credit Information Co., Ltd · 📍 Hà Nội
Việc khác tại NICE Credit Information Co., Ltd
- N
Business Development Manager6 ngày trước · Còn 17 ngày