Principal Security Engineer

JOB DESCRIPTION

Partner with Product & Engineering teams to identify cyber attack risks in the system and define tactical and strategic mitigation plans
Conduct complete security lifecycle architecture and technical assessments, including but not limited to design requirements assessment, threat modelling, and risk assessment
Build and champion a standardized set of security requirements and design patterns for internal systems and product offerings.
Maintain SLA's by watching for new vulnerabilities, monitoring existing vulnerabilities, working on false-positives and detection logic changes
Actively participate in company's Software Development Lifecycle (SDLC)
Monitor current and proposed laws, regulations, industry standards and ethical requirements related to privacy and information security.
Influence security strategy and roadmap by leveraging the collective strength of the security team and articulating the capabilities needed to effectively manage the cyber-attack risk
Drive Security QBR in partnership with Product & Engineering   
Represent the company within the security community and with customers on topics related to the security of the company's products and services. 

JOB REQUIREMENT

3+ years in a senior security leadership role  
6+ years’ experience working in a security focused role in the technology or other technology heavy industry (e.g. Financial Services) 
Superb communication and interpersonal skills.
Consistent track record designing and integrating security controls in cloud-based architectures
Significant experience conducting threat modelling and risk assessments of cloud services, demonstrating clear ability to identify unique vulnerabilities
Expert level knowledge at all layers of the information security stack with hands-on security engineering experience on AWS, GCP, TFE, Azure, Kubernetes, etc.
Prior experience working with engineering teams on design and implementation of best-practices for security as code
Have the mindset of "First-Time-Right" and "Secure-By-Default"
Working knowledge of the MITRE ATT&CK, NIST CSF, and CIS Critical Control frameworks
Certified Information System Security Professional (CISSP) or Certified in Risk and Information Systems Control (CRISC) certifications preferred
BS or MS in Computer Science, Information Systems, Engineering or a related field

WHAT'S ON OFFER

Flexible working time and the ability to work remotely from wherever you are, it is a significant advantage for bank candidates.
Attractive income (base salary & performance bonus) in Viet Nam fintech markets
Full-salary paid for social insurance & Premium healthcare package
20 days of annual leave, 10 days of sick leave and public holidays.
Devices provided (Macbook, mouse, monitor…)
Frequent team bonding and company activities/ events.
Work in newly innovated office and open working space.
Improve English skills, learn more about thinking and working style. Fully adopt Agile way of working, lean team structure.
Working with many talented people with good manners from 13 various cultural backgrounds: US, UK, India, China, Spain, etc,…
Empowered to listen creative ideas, and there is no distance between bosses and employees. 

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Digital Bank, Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Salary:

Negotiation

Job ID:

J01123

Status:

Close

Related Job:

Pentest Manager

Ha Noi - Viet Nam


Product

  • Pentest

Tham gia triển khai dịch vụ pentest cho khách hàng: tiếp nhận, xác định các yêu cầu, phạm vi, điều kiện đảm bảo của các dự án pentest được giao Bóc tách công việc theo quy trình pentest, phân chia cho các thành viên tham gia thực hiện dự án Hướng dẫn các pentester thực hiện kiểm tra đánh giá ATTT cho ứng dụng Kiểm soát chất lượng dịch vụ, tuân thủ quy trình, nguồn lực và thời gian triển khai cho các dự án được giao Là đầu mối kỹ thuật, làm việc với các bộ phận nội bộ VCS (AM, CSKH, PM) & Khách hàng để phối hợp giải quyết các vấn đề trong phạm vi cung cấp dịch vụ Nghiên cứu cải tiến quy trình, checklist, các kỹ thuật mới nhằm nâng cao chất lượng dịch vụ, năng suất lao động, giảm tỉ lệ sót lỗi Đảm bảo SLA theo hợp đồng đã ký với Khách hàng

Negotiation

View details

SOC Manager

Ho Chi Minh, Ha Noi - Viet Nam


Product

  • Security
  • System
  • Network

Quản lý, kiểm soát chất lượng các dịch vụ cung cấp cho Nhóm các khách hàng của công ty: dịch vụ Giám sát ATTT 24/7, Xử lý sự cố, Threat hunting, Threat intelligence… Quản lý mức độ trưởng thành ATTT: Đánh giá, tư vấn nâng cao mức độ trưởng thành ATTT Quản lý Rủi ro ATTT & Quản lý tiếp xúc mối đe dọa liên tục đối với hệ thống của KH Nhận diện và quản lý vấn đề ATTT của khách hàng trong quá trình vận hành giám sát và xử lý sự cố Đại diện TTGS làm việc với các bộ phận nội bộ VCS (Triển khai, phát triển giải pháp, PM, sale, pre-sale, AM, CSKH, …) & Khách hàng để phối hợp giải quyết các vấn đề trong phạm vi cung cấp dịch vụ Đảm bảo SLA theo hợp đồng đã ký với Khách hàng

Negotiation

View details

Senior Staff Engineer

Ho Chi Minh - Viet Nam


Product

  • NestJS
  • Angular
  • Typescript

Revamp and streamline key components throughout the Angular 20 + NestJS codebase. Recognize and integrate architectural enhancements such as modularization, domain distinction, and shared service boundaries. Work closely with the CTO to refine product architecture without disrupting release schedule. Guarantee system efficiency, data integrity, and sustainability through improved design. Analyze crucial code pathways and mentor others in cutting-edge Angular and TypeScript methodologies. Introduce practices that elevate testability, deployment security, and developer productivity. Engage in product design conversations to synchronize engineering endeavors with actual user requirements.

Negotiation

View details