Principal Security Engineer

JOB DESCRIPTION

Partner with Product & Engineering teams to identify cyber attack risks in the system and define tactical and strategic mitigation plans
Conduct complete security lifecycle architecture and technical assessments, including but not limited to design requirements assessment, threat modelling, and risk assessment
Build and champion a standardized set of security requirements and design patterns for internal systems and product offerings.
Maintain SLA's by watching for new vulnerabilities, monitoring existing vulnerabilities, working on false-positives and detection logic changes
Actively participate in company's Software Development Lifecycle (SDLC)
Monitor current and proposed laws, regulations, industry standards and ethical requirements related to privacy and information security.
Influence security strategy and roadmap by leveraging the collective strength of the security team and articulating the capabilities needed to effectively manage the cyber-attack risk
Drive Security QBR in partnership with Product & Engineering   
Represent the company within the security community and with customers on topics related to the security of the company's products and services. 

JOB REQUIREMENT

3+ years in a senior security leadership role  
6+ years’ experience working in a security focused role in the technology or other technology heavy industry (e.g. Financial Services) 
Superb communication and interpersonal skills.
Consistent track record designing and integrating security controls in cloud-based architectures
Significant experience conducting threat modelling and risk assessments of cloud services, demonstrating clear ability to identify unique vulnerabilities
Expert level knowledge at all layers of the information security stack with hands-on security engineering experience on AWS, GCP, TFE, Azure, Kubernetes, etc.
Prior experience working with engineering teams on design and implementation of best-practices for security as code
Have the mindset of "First-Time-Right" and "Secure-By-Default"
Working knowledge of the MITRE ATT&CK, NIST CSF, and CIS Critical Control frameworks
Certified Information System Security Professional (CISSP) or Certified in Risk and Information Systems Control (CRISC) certifications preferred
BS or MS in Computer Science, Information Systems, Engineering or a related field

WHAT'S ON OFFER

Flexible working time and the ability to work remotely from wherever you are, it is a significant advantage for bank candidates.
Attractive income (base salary & performance bonus) in Viet Nam fintech markets
Full-salary paid for social insurance & Premium healthcare package
20 days of annual leave, 10 days of sick leave and public holidays.
Devices provided (Macbook, mouse, monitor…)
Frequent team bonding and company activities/ events.
Work in newly innovated office and open working space.
Improve English skills, learn more about thinking and working style. Fully adopt Agile way of working, lean team structure.
Working with many talented people with good manners from 13 various cultural backgrounds: US, UK, India, China, Spain, etc,…
Empowered to listen creative ideas, and there is no distance between bosses and employees. 

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Digital Bank, Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Job ID:

J01123

Status:

Close

Related Job:

Software Engineer (Node.js) - Database

Ho Chi Minh - Viet Nam


Product

  • NodeJS

Design system architectures, establish coding standards, and construct cohesive, cloud-native solutions. Develop high-quality Node.js code, optimize system performance, and tackle complex software integration challenges. Oversee the testing, deployment, and comprehensive documentation of integrated systems. Mentor less-experienced engineers, engage in cross-functional teamwork, and ensure solutions meet business requirements and international standards. Participate actively in all Agile software development phases, including creating user stories and executing sprint planning Engage with multinational companies, demonstrating flexibility to occasionally adapt to US and EU time zones.

Negotiation

View details

Software Engineer (Node.js) - Platform Security

Ho Chi Minh - Viet Nam


Product

  • NodeJS

Design system architectures, establish coding standards, and construct cohesive, cloud-native solutions. Develop high-quality Node.js code, strengthen system security and reliability, and tackle complex software integration challenges. Design and implement platform security controls across web applications, APIs, and cloud services, including authentication, authorization, session management, secrets management, encryption, and audit logging. Identify and remediate security risks through threat modeling, secure code reviews, automated security testing, dependency scanning, and investigation of security-related issues. Oversee the testing, deployment, and comprehensive documentation of integrated systems. Mentor less-experienced engineers, engage in cross-functional teamwork, and ensure solutions meet business requirements and international standards. Participate actively in all Agile software development phases, including creating user stories and executing sprint planning Engage with multinational companies, demonstrating flexibility to occasionally adapt to US and EU time zones.

Negotiation

View details

AI Agent Ops Engineer

Ho Chi Minh - Viet Nam


Product

  • AI

#Agent Engineering & operation Design, build, and maintain production-grade AI agent systems, including: context engineering and instruction architecture, prompt hardening and safe execution boundaries, tool integrations and multi-step orchestration, memory strategies and reliability patterns. Own the full agent lifecycle: prototype → evaluate → deploy → monitor → iterate. Build and maintain an evaluation pipeline to measure agent quality, catch regressions, and enforce deployment gates (golden datasets, scenario suites, automated checks). Instrument agents and agent platforms for production observability: structured logging, tracing, and metrics; latency and cost monitoring; tool-call success rates and failure analysis. Define operational readiness standards including: rollback criteria, incident response playbooks, recovery paths for common failure modes.#Team Enablement & Coaching Embed with product engineering teams to identify high-value use cases ready for agent automation. We will be operating in a Central Agent Ops role enabling Ai product builders through AI enablers. Translate business workflows into agent-executable tasks with clear: contact boundaries/interfaces, assumptions and inputs/outputs, failure modes and safe fallbacks. Deliver targeted coaching to engineers on: context engineering best practices, harness design and regression testing patterns, agent skill design and tool-contract discipline. Reduce onboarding time for teams adopting AI capabilities-from first conversation to a production-ready agent. Train product engineers to extend and maintain agent skills independently.#Standards & Knowledge operations Author and maintain org-level standards for agents, including: naming conventions, context file structures and ownership rules, skill interface contracts (inputs/outputs, invariants, error handling), evaluation criteria and release quality bars. Establish and enforce "repo-as-discipline" practices so agent knowledge is: versioned, reviewable, discoverable, reusable; not trapped in prompt snippets or individual heads. Build and grow a shared agent skills library that teams can reuse and extend. Track and aggregate AI tooling/framework updates and external best practices, serving as a central intake so product teams don't each have to follow the entire AI landscape. Run internal knowledge-sharing sessions, showcases, and retrospectives to propagate learnings efficiently.

Negotiation

View details