Head of IT Security

JOB DESCRIPTION

Objective
Develops, implements, and maintains an effective information security program to ensure the protection of the our Client's information and computing resources.
Key responsibilities/duties:
lEnsures confidentiality, integrity, and availability of Home credit information and computing systems by managing the planning, implementation, and enhancement of the Bank's Information Security assurance program.
lServes as a project manager or provides project oversight for Information Security related projects.
lManages technically skilled individuals by performing normal management functions of staffing, planning, controlling, and directing; reviewing and evaluating performance; reviewing employment candidates; recommending salary increases and promotions for the Information Security group; and preparing budget for area of supervision.
lAccommodates the Home credit automation objectives and development of Home credit policies on information security by developing strategic, tactical and operational information security plans.
lDevelops and administers internal information security assurance, standards and procedures.
lProvides oversight for all Information Security related incidents and investigations.
lProvides Security Consulting Services Bank Management and Business functions as needed in a manner that is consistent with the risk framework identified by the Home credit System Information Security policy.
lContributes to and participates Home credit Operational Risk Management.
lServes as a central point of contact with staff and Internal Audit department, and external audit functions for consultation on information security issues, controls and compliance .
lOversees the implementation of information security awareness programs for Home credit's staff.
lEnsures that safety rules and regulations are adhered to by personnel in area, and performs job duties and responsibilities in conformance with sound safety practices.

JOB REQUIREMENT

Fluent English and Vietnamese – spoken & written
Bachelor's degree or equivalent experience.
Minimum of five years work experience directly in the information security field.
Minimum of three years management or similar leadership experience.
Excellent risk management, enterprise defense, consulting and external "threat awareness" competencies.
Strong knowledge of various automated security control systems, encryption, message authentication, vulnerability assessment, intrusion detection, penetration testing, incident response, and manual control procedures. 
Working knowledge of security systems associated with computing platforms, networking, operating systems and applications. 
Strong knowledge, experience or understanding of security policy or control frameworks and risk assessment tools.
Possesses conflict resolution and values of openness, honesty and respect.
Very strong analytical, planning, problem solving, organizational, project management skills and the ability to multi-task well.
Very strong interpersonal, oral and written communication skills, including the ability to communicate with all levels of organization and European HQ.
Ability to understand and manage complex technical and security problems that require attention to detail, timely resolution and a high degree of discretion.
Nice to have:
Experience with regulation of financial industry in Vietnam preferred.
CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager) or similar Information Security certifications preferred.

WHAT'S ON OFFER

Monthly allowance (600k)
13th-month Salary and performance- based KPI Bonus (1-3 months)
15+ Annual Leaves
Flexible time, Work-from-home policies 
Full Social Insurance, 24/7 Accidental Insurance, Annual Medical Check- up,Premium PTI 24/7 
Team Building and CSR activities: Year- end Party, New-year Party, Company trip, Charity activities, Blood donation
Learning workshops: Free Udemy E-learning, English courses, Senior management development training programs

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Job ID:

J01048

Status:

Close

Related Job:

Head of Insights and Analytics

Ho Chi Minh - Viet Nam


Product

#Strategic Performance Advisory As a strategic partner to Executive Leadership, this role drives the measurement, interpretation, and optimization of Service Centre performance. Serve as a trusted advisor to the Executive Leadership Team, shaping how business performance is measured, monitored, and improved across the Service Centre. Lead and develop a central Insights & Analytics team of approximately 4-5 analysts and data engineers responsible for enterprise performance reporting and decision support. Design, maintain, and continuously enhance a robust performance management framework, including KPIs, scorecards, dashboards, executive reporting, and insight generation. Transform complex operational, technology, workforce, customer, and delivery data into clear, actionable insights that enable strategic decision-making and investment prioritization. Provide executive-level analysis and recommendations on productivity, capacity, service performance, operational risk, and business outcomes. Develop compelling performance narratives that support senior stakeholder discussions and inform enterprise-wide planning and decision-making. Promote a culture of evidence-based decision-making and performance accountability across the Service Centre.#Analytics Delivery Oversight & Capability LeadershipAs the functional leader for analytics capability, this role provides strategic oversight, governance, and leadership across multiple analytics teams delivering services to the broader bank. Provide senior leadership and oversight of analytics teams delivering business-critical data and analytics solutions through business-aligned delivery backlogs. Ensure analytics delivery is effectively governed, strategically aligned, outcomefocused, and consistent with enterprise data and analytics standards. Establish and embed best practices, operating models, and governance frameworks to drive delivery excellence and consistency across teams. Build organizational capability through coaching, mentoring, succession planning, and talent development, creating a strong pipeline of analytics leaders and specialists. Drive the maturity of analytics practices, tools, and methodologies to enhance efficiency, quality, and business impact. Foster a high-performance culture that encourages innovation, collaboration, continuous improvement, and data-driven problem solving

Negotiation

View details

Head of Engineering - Marketing Technology

Ho Chi Minh - Viet Nam


Product

  • Management

Develop an integrated roadmap for strategic execution based on the organization's strategic aspirations and lead the implementation process from planning to delivery. Manage multiple engineering teams throughout the organization to achieve desired outcomes, hence having knowledge of the organization's specific areas of operation is an advantage. Collaborate closely with business teams and product owners to verify requirements before and after delivery through showcases and post-production monitoring. Take responsibility for both the development and operation of applications in production, providing active operational support and establishing a clear support model with a focus on site reliability engineering. Direct and oversee the implementation of cybersecurity updates, including keeping software versions current and patching infrastructure regularly. Oversee investment allocation across the organization to maintain alignment, ensure effective spending, and offer insights on the effectiveness and prioritization of investments. Integrate engineering excellence with domain expertise in marketing while pursuing strategic technology objectives.

Negotiation

View details

Lead Penetration Tester

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments. Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues. Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices. Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks. Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments. Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved. Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation. Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices. Lead the planning, scoping, and execution of penetration testing activities across assigned projects. Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements. Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions. Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value. Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams. Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders. Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities. Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices. Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

Negotiation

View details