CV WorkCV Work
Lọc
Tỉnh / thành
Ngành nghề
Mức lương

Senior GRC Specialist (Cyber Security)

~38 triệu (dự kiến)📍 Hà NộiỨng tuyển ngay →

Chưa có CV? Tạo CV miễn phí ở đây →

Mô tả công việc

MỤC ĐÍCH CÔNG VIỆC/ JOB PURPOSE

As a Senior GRC Specialist, you are the airport’s authority for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).

Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, NIST CSF, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.

Role impact: Your work protects the airport’s licence to operate, sustains its national critical-infrastructure obligations, gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.


TRÁCH NHIỆM CHÍNH/ KEY ACCOUNTABILITIES

Governance, Framework & Policy Management (40%)

• Own the cyber security policy, standard and procedure framework (ISO 27001, NIST CSF, IEC 62443)

• Operate the ISMS: scope, risk methodology, SoA, risk treatment plan, internal audit, management review

• Maintain one control library mapped to ISO 27001, Decree 85/2016, Decree 53/2022 and PDPD/PDPL

• Run the exception and waiver process with compensating controls, risk acceptance and expiry dates

• Embed security requirements into SDLC, cloud onboarding, change management and procurement

Risk Management & Third-Party Assurance (30%)

• Maintain the enterprise cyber risk register with scoring, treatment plans and named owners

• Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems

• Determine system security levels under Decree 85/2016 and prepare approval dossiers

• Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal

• Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms

• Track audit, assessment and penetration test findings to closure against severity-based SLAs


Compliance, Audit & Reporting (30%)

• Coordinate internal audits, external audits, certification assessments and regulator inspections

• Maintain the regulatory obligations register and horizon-scan Vietnamese cyber and privacy law

• Report KRIs, KPIs and security posture to the Steering Committee and executive leadership

• Govern security awareness and the phishing simulation programme, including remediation tracking

• Coordinate regulatory incident notification with Legal and maintain BCP/DR governance evidence

Yêu cầu công việc

Qualifications and Experience:

• Bachelor’s degree in Information Security, IT, Engineering, Law or Audit

• 6+ years in cyber security governance, risk and compliance, IT audit or ISMS management

• Ownership of an ISMS through at least one full ISO/IEC 27001 certification cycle

• Working knowledge of the Law on Cyber Security, Decree 85/2016, 53/2022 and PDPD/PDPL

• Experience running a third-party / vendor security risk assessment programme

• Preferred: airport, aviation, banking or critical infrastructure; IEC 62443 exposure

Quyền lợi

  • Thưởng: Cuối năm

Nhà tuyển dụng

Công Ty Cổ Phần Hạ Tầng Hàng Không Masterise · 📍 Hà Nội

Việc khác tại Công Ty Cổ Phần Hạ Tầng Hàng Không Masterise

Senior GRC Specialist (Cyber Security)~38 triệu (dự kiến) · 📍 Hà Nội
Ứng tuyển ngay →