Regional ISO Engineer

JOB DESCRIPTION

Job Purpose/Role
This role will be a combination of ISO role and PCI role.
The Information Security Officer (ISO) is assigned to Security Assurance Manager. The ISO has overall responsibility for the effective implementation and maintenance of the Information Security Management System (ISMS) within Company. Furthermore, the ISO oversees the fulfilment of Information Security requirements in all services provided by Company as shared service provider to its customers. The scope of ISO covers several Business Units (usually the entire or part of Europe, Americas or APAC regions).
The PCI Compliance Officer is assigned to Security Assurance Manager. The PCI Compliance Officer provides advice on compliance matters related to Payment Cards Industries standards / frameworks. He / she represents Company to industry bodies, monitors and evaluates relevant PCI compliance risks that can affect the business. The scope of PCI Compliance Officer is global for Company Partners related demand.
Key responsibilities/What you do
ISO
Each Information Security Function shall be responsible for oversight of the related ISMS activities, risk identification and assessment, prevention and advice with respect to the Information Security Risk areas: of the local Company and of the services provided by the local Company to its customers.
The function is responsible for the effective implementation of Comapny’s Information Security principles. This includes to promptly report to the IS Function matters which potentially have impact on the Company’s reputation.
In case of conflict of interests, the ISO shall refer a matter to the Security Assurance Manager and ultimately to the Company CISO.
PCI
Define and help manage PCI DSS program
Evaluate compliance against IT security policies, functional rules, controls and Payment Cards Industry standards
Drive a distributed annual subsidiary assessment exercise
Manage vendors that support PCI engagements (scoping, assessments, consultations, etc.)
Manage non-planned PCI-related inquiries and provide/coordinate unified guidance to subsidiary and Amazon service teams
Provide consultancy on PCI requirements, deliver recommendations and risk interpretations in a clear, concise and audiencespecific format. 

JOB REQUIREMENT

Bachelor's degree in Computer or higher in related fields.
Recognized Information Security Certifications e.g. CISSP, CISM. CRISC or ISO27001 Lead Auditor preferred
Experience with internal controls, risk assessments, business processes and internal IT control testing or operational auditing
Information Security experience related to risk management controls assurance & compliance programs
Previous experience creating and/or performing review and gap analysis of information security policies and standards against cybersecurity frameworks
Related security control and compliance experience in various frameworks including PCI DSS, PCI PA-DSS, PCI PTS, GLBA, NYDFS, ISO, NIST, etc.
Excellent communication skills, interpersonal, oral, and written in English

WHAT'S ON OFFER

We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroad
We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location)
From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered
Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Outsource

Technical Skills:

Security

Location:

Others - Thailand

Working Policy:

Job ID:

J01245

Status:

Close

Related Job:

Senior AI DevSecOps Engineer

Ho Chi Minh - Viet Nam


Product

  • Devops
  • AWS
  • Azure
  • Security

Management of CI/CD Pipeline: Ensure automation, security, and scalability across all stages of the development lifecycle. Infrastructure & Security: Design and implement secure multi-cloud infrastructure solutions leveraging cloud services, containerization, and orchestration tools. Policy as Code: Define and enforce security and compliance policies across Kubernetes clusters using OPA or Kyverno, ensuring guardrails are automated and auditable. AI & Platform Automation: Drive the adoption of AI-powered tools and workflows to automate infrastructure operations, optimize CI/CD pipelines, accelerate root cause analysis, improve security posture, and enhance engineering productivity. Observability & Alerting: Build and maintain a comprehensive observability stack with proactive alerting, dashboards, and runbooks for critical business flows and security events. Secret & Credential Management: Design and enforce secrets management practices across all environments ensuring zero hardcoded credentials in codebases and pipelines. Incident Response & On-Call: Own and continuously improve incident response processes, define runbooks, lead post-mortems, track MTTR, and participate in on-call rotation to maintain platform reliability and SLO adherence. Threat Modelling & Penetration Testing: Conduct regular threat modelling sessions with engineering teams and coordinate or perform penetration testing activities to proactively identify attack surfaces before they reach production. Code Security: Conduct regular code reviews and static/dynamic analysis to identify and remediate security vulnerabilities. Compliance and Best Practices: Ensure compliance with industry standards and best practices. Collaboration: Collaborate with development, operations, and security teams to foster a culture of automation and security-first thinking. Mentorship: Mentor junior engineers and other team members on security best practices. Documentation: Maintain thorough and up-to-date documentation of security policies, procedures, and incident reports. Trend Scouting: Stay updated with the latest trends in technology and AI to integrate innovative solutions into our processes.

Negotiation

View details

Senior Data Engineer (C++, Python, AI/LLM)

Ho Chi Minh - Viet Nam


Outsource

  • Data Engineering
  • C/C++
  • Python

Refine a wide array of structured and unstructured data to produce high-quality datasets for quantitative analysis and financial engineering. Improve data integrity and quality by creating validation tools and frameworks to assess the effectiveness of data enrichment pipelines. Gain expertise in machine learning, deep learning, and emerging AI/LLM applications, and analyze the underlying dynamics and behaviors in the data. Derive insights from large-scale datasets and collaborate with research teams to pinpoint opportunities for tradable signals. Create utility tools to automate software development, testing, deployment, and monitoring workflows. Offer technical support to global researchers, including diagnosing technical issues, troubleshooting Python and C++ code, and suggesting scalable fixes and improvements. Troubleshoot and resolve issues in C++ applications and data pipelines with a strong focus on performance, stability, correctness, and maintainability. Investigate and implement AI/LLM-based solutions to enhance data processing, workflow efficiency, troubleshooting, documentation, and research support processes.

Negotiation

View details

Senior Backend Engineer

Ho Chi Minh, Ha Noi - Viet Nam


Product

  • Golang
  • Ruby

Develop, construct, and operate backend services for a leading B2B SaaS platform serving the construction industry. Establish an organized, maintainable, and scalable software architecture. Identify and address performance bottlenecks such as query optimization, caching, and asynchronous processing. Uphold software quality with automated testing, code reviews, observability, and CI/CD practices. Validate AI-generated code to ensure security, accuracy, and maintainability. Provide guidance and support to engineers to enhance the team's engineering standards. Backend: Ruby (on Rails), Golang, Amazon Aurora (MySQL), DynamoDB FrontEnd: Nuxt.js, Vue.js, Next.js, ReactJS Mobile App: Kotlin, Swift, Flutter Deploy/ Build: AWS Amplify, CodePipeline, CodeBuild, CircleCI, GitHub Actions Others: Swagger, Docker, Figma, Confluence, JIRA, esa, gRPC Infrastructure: Helm, Terraform Automation test: Autify, Magicpod

Negotiation

View details