Senior GRC Specialist (Cyber Security)
Chưa có CV? Tạo CV miễn phí ở đây →
Mô tả công việc
MỤC ĐÍCH CÔNG VIỆC/ JOB PURPOSE
As a Senior GRC Specialist, you are the airport’s authority for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).
Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, NIST CSF, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.
Role impact: Your work protects the airport’s licence to operate, sustains its national critical-infrastructure obligations, gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.
TRÁCH NHIỆM CHÍNH/ KEY ACCOUNTABILITIES
Governance, Framework & Policy Management (40%)
• Own the cyber security policy, standard and procedure framework (ISO 27001, NIST CSF, IEC 62443)
• Operate the ISMS: scope, risk methodology, SoA, risk treatment plan, internal audit, management review
• Maintain one control library mapped to ISO 27001, Decree 85/2016, Decree 53/2022 and PDPD/PDPL
• Run the exception and waiver process with compensating controls, risk acceptance and expiry dates
• Embed security requirements into SDLC, cloud onboarding, change management and procurement
Risk Management & Third-Party Assurance (30%)
• Maintain the enterprise cyber risk register with scoring, treatment plans and named owners
• Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems
• Determine system security levels under Decree 85/2016 and prepare approval dossiers
• Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal
• Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms
• Track audit, assessment and penetration test findings to closure against severity-based SLAs
Compliance, Audit & Reporting (30%)
• Coordinate internal audits, external audits, certification assessments and regulator inspections
• Maintain the regulatory obligations register and horizon-scan Vietnamese cyber and privacy law
• Report KRIs, KPIs and security posture to the Steering Committee and executive leadership
• Govern security awareness and the phishing simulation programme, including remediation tracking
• Coordinate regulatory incident notification with Legal and maintain BCP/DR governance evidence
Yêu cầu công việc
Qualifications and Experience:
• Bachelor’s degree in Information Security, IT, Engineering, Law or Audit
• 6+ years in cyber security governance, risk and compliance, IT audit or ISMS management
• Ownership of an ISMS through at least one full ISO/IEC 27001 certification cycle
• Working knowledge of the Law on Cyber Security, Decree 85/2016, 53/2022 and PDPD/PDPL
• Experience running a third-party / vendor security risk assessment programme
• Preferred: airport, aviation, banking or critical infrastructure; IEC 62443 exposure
Quyền lợi
- Thưởng: Cuối năm
Nhà tuyển dụng
Công Ty Cổ Phần Hạ Tầng Hàng Không Masterise · 📍 Hà Nội
Việc khác tại Công Ty Cổ Phần Hạ Tầng Hàng Không Masterise
- C
Chuyên Gia Đấu Thầu Xây Dựng Hạ Tầng (Dự Án BT)17 ngày trước · Còn 12 ngày - C
Senior Business Analyst (eCommerce)6 ngày trước · Còn 19 ngày - C
Director/ Senior Manager - Construction Managementhôm qua · Còn 29 ngày - C
Senior Expert, Customer Experience6 ngày trước · Còn 24 ngày - C
Senior Expert, Interface Engineer (ICT infrastructure)6 ngày trước · Còn 21 ngày - C
Expert/ Senior Specialist, Construction Supervisorhôm qua · Còn 29 ngày