Position: Principal Officer/Senior Officer/Officer in Information Security Policy, Risk Management, and Audit
Number of Vacancies: 8
Job description
Policy Implementation and Security Standards:
- Implement information security policies and apply security standards to enhance the security of information systems.
- Execute security standard projects such as ISO27001, PCI DSS, and NIST.
- Develop security standards and tools for application within VietinBank's systems.
- Design and implement policies for cloud network connectivity and DevSecOps.
- Conduct training to raise information security awareness.
Risk Management:
- Identify, assess, propose, and monitor controls to mitigate information security risks.
- Manage IT assets at VietinBank.
- Develop and implement methods, models, and tools for managing information security risks, from identification and assessment to monitoring and proposing improvements to controls.
- Conduct risk identification and assessment of information systems.
Audit and Compliance:
- Audit the implementation of security standards across systems to ensure compliance with VietinBank's information security policies and international security standards.
- Develop checklists and tools to perform audits in compliance with security standards across information systems.
- Implement tools and systems to monitor, control, and secure VietinBank's documents and data.
- Manage and operate security systems to monitor and protect documents and data
Requirements:
Education: Bachelor's degree from a full-time program.
- Major: Information Technology, Cybersecurity, Computer Networks, Cybersecurity, Electronics and Telecommunications, Computational Mathematics.
Technical Skills:
- Knowledge and experience with international security standards such as ISO27001, PCI DSS, NIST, CIS Benchmarks.
- Holding one of the following security certifications is an advantage: CISSP, OSCP, CEH, CISA, CRISC, CISM, ISO27001 Lead Auditor
Experience:
- Officer: 1 - 2 years of experience in information security, particularly in risk policy, audit, and security system design.
- Senior Officer: 2 - 4 years of experience in information security, particularly in risk policy, audit, and security system design.
- Principal Officer: 4 - 7 years of experience in information security, particularly in risk policy, audit, and security system design
Soft Skills:
- Strong logical thinking and problem-solving skills.
- Good discipline and adherence to regulations.
- Careful, honest, and objective in work.
- Friendly, sociable, and able to work well within a team.
- Able to work under high pressure.
- Strong sense of responsibility, teamwork ability, and effective communication skills.
- Ability to research and learn to work effectively.
English Proficiency:
- Good in listening, speaking, reading, and writing.
- For Principal Officer: Able to work directly with foreign partners in English.