Security Manager

JOB DESCRIPTION

Secure enterprise information by designing, implementing, and enforcing security controls, safeguards, policies, and procedures; managing staff. The job holder will provides guidance and assurance for SDLC and IT Ops, manages external relationships with relevant authorities and CERTs, relevant regulatory bodies. Also design and provide IT risk awareness trainings to staff.
Achieve system security operational objectives by contributing information and recommendations to strategic plan and review; preparing and completing action plans; implementing production, productivity, quality, and customer- service standards; resolving problems; completing audits; identifying trends; determining system improvements; implementing change.
Meet system security financial objectives by forecasting requirements; preparing an annual budget; scheduling expenditures; analyzing variances; initiating corrective actions.
Protect computer assets by developing security strategies; directing system control development and access management, monitoring, control, and evaluation.
Establish system safeguards by directing disaster preparedness development; conducting preparedness tests.
Develop security awareness by directing development of orientation and training programs; counseling clients.
Advise senior management by identifying critical security issues; recommending risk-reduction solutions.
Update job knowledge by participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations; coordinating hardware and software evaluations with vendors.
Accomplish system security and organization mission by completing related results as needed. 
Accomplish system security human resource objectives by recruiting, selecting, orienting, training, assigning, scheduling, coaching, counseling, and disciplining employees; communicating job expectations; planning, monitoring, appraising, and reviewing job contributions; planning and reviewing compensation actions; enforcing policies and procedures.
Any other task assigned by the line manager.

JOB REQUIREMENT

BA in Computer Science or comparable practice/experience
Excellent in Information Security Policies, Network Security, Quality Management, Technical Management, Tracking Budget Expenses, Strategic Planning, Problem Solving, Information Analyzing.
Ability to convey information to all levels of the company.
Minimum 5 years of relevant experience in IT Security function/IT risk management and/or relevant positions with consulting/audit companies operating in the local market.

WHAT'S ON OFFER

Attractive packages and commissions
Young and active environment in one of the top Fintech Company in Vietnam
All Ideas are appreciated – No barriers– No limitation
Performance-based bonus.
Insurance package for high-level employees.
Chance to work with many strong people with oversea experienced. We take career path development seriously.

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security, Network, IT inhouse

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Job ID:

J00546

Status:

Close

Related Job:

Senior AI DevSecOps Engineer

Ho Chi Minh - Viet Nam


Product

  • Devops
  • AWS
  • Azure
  • Security

Management of CI/CD Pipeline: Ensure automation, security, and scalability across all stages of the development lifecycle. Infrastructure & Security: Design and implement secure multi-cloud infrastructure solutions leveraging cloud services, containerization, and orchestration tools. Policy as Code: Define and enforce security and compliance policies across Kubernetes clusters using OPA or Kyverno, ensuring guardrails are automated and auditable. AI & Platform Automation: Drive the adoption of AI-powered tools and workflows to automate infrastructure operations, optimize CI/CD pipelines, accelerate root cause analysis, improve security posture, and enhance engineering productivity. Observability & Alerting: Build and maintain a comprehensive observability stack with proactive alerting, dashboards, and runbooks for critical business flows and security events. Secret & Credential Management: Design and enforce secrets management practices across all environments ensuring zero hardcoded credentials in codebases and pipelines. Incident Response & On-Call: Own and continuously improve incident response processes, define runbooks, lead post-mortems, track MTTR, and participate in on-call rotation to maintain platform reliability and SLO adherence. Threat Modelling & Penetration Testing: Conduct regular threat modelling sessions with engineering teams and coordinate or perform penetration testing activities to proactively identify attack surfaces before they reach production. Code Security: Conduct regular code reviews and static/dynamic analysis to identify and remediate security vulnerabilities. Compliance and Best Practices: Ensure compliance with industry standards and best practices. Collaboration: Collaborate with development, operations, and security teams to foster a culture of automation and security-first thinking. Mentorship: Mentor junior engineers and other team members on security best practices. Documentation: Maintain thorough and up-to-date documentation of security policies, procedures, and incident reports. Trend Scouting: Stay updated with the latest trends in technology and AI to integrate innovative solutions into our processes.

Negotiation

View details

Lead Penetration Tester

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments. Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues. Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices. Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks. Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments. Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved. Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation. Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices. Lead the planning, scoping, and execution of penetration testing activities across assigned projects. Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements. Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions. Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value. Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams. Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders. Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities. Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices. Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

Negotiation

View details

Delivery Manager

Ho Chi Minh - Viet Nam


Outsource

  • Project Management

Oversee the leadership, mentoring and development of two engineering teams, namely AI BI and AI-Powered Service Desk. This includes managing recruitment, evaluating performance, and facilitating career growth. Take accountability for the delivery of both teams, comprising planning, prioritization, sprint execution, and ensuring high-quality releases. Work in conjunction with Product, Data Science/ML, and Design to establish roadmaps and convert business requirements into technical implementation. Offer technical direction and architectural oversight across BI dashboards, analytics pipelines, and AI-powered service/support tooling. Advocate for engineering best practices such as code quality, testing, CI/CD, observability, and documentation. Manage competing priorities across both teams, resolve obstacles for engineers, and oversee inter-team dependencies. Collaborate with backend, frontend, and ML engineers to ensure unified architecture across the teams. Provide regular reports on team performance, progress in delivery, and potential risks to senior leadership. Cultivate an environment focused on accountability, collaboration, and continual enhancement. Remain involved in hands-on tasks as required, including code reviews, architecture discussions, and making technical decisions.

Negotiation

View details