Senior Security Engineer
- Reference
- 11-ISO-0541
- Job type
- Kĩ sư hệ thống
- Location
- HCMC
- Salary
- negotiate
- Job description
- This role is responsible for ensuring the confidentiality, integrity and availability of VNG information resources thru active participation or management of the VNG Vulnerability Management program, participation in security incident investigations, product and project security analysis, and security governance (which includes project managing and security documentation development/maintenance).
Job Description:- Manage ISMS project with:
- Development, implementation of information classification and a Risk Assessment model at VNG
- Development and implementation of security controls
- Development, implement and maintain annual Risk Assessment reviews of VNG information systems.
- Conduct periodic reviews of VNG's information resources security policies, procedures, and compliance. Prepare reports of findings for review by firm management.
- Assist various business units throughout the firm to implement and maintain information resources security.
- Conduct periodic audits of VNG's various applications and systems to ensure information security processes and procedures are effective. Develop and distribute reports that include findings and recommended remediation steps.
- Member of Incident Response Team. Assist with the investigation, documentation, and response to suspected information security events.
- Manage ISMS project with:
- Requirement
- Must have (3-5 years) of experience in the following:
- Experience with the development of policies, procedures, technical configuration standards, and guidelines.
- Experience developing and implementing compliance monitoring processes and procedures.
- Experience with formal project planning/managing and risk assessment methodologies.
- Ability to build strong working relationships at all levels, internal and/or external to the organization.
- Strong written and oral (Vietnamese and English) communication skills.
- Experience conducting risk assessments and system/application reviews.
- Experience preparing management reports, remediation plans, and related planning documents.
- Ability to perform project tasks with little or no supervision.
- A positive attitude with strong and strategic powers of persuasion and negotiation.
- At least 2 years of technology project management or equivalent experience.
Preferable:- ISO 27001 Lead Implementer and/or Lead Auditor certification is a significant plus.
- Other technical or professional certifications, such as CISSP, GIAC or CISA a plus.
