Senior Manager Application Security

JOB DESCRIPTION

PURPOSE
To deliver highly technical Information Security Reviews in support of stakeholders from both Business and IT teams across all Group's Business Units, to identify and mitigate of material business risks representing significant threats to the success of the Group's activities.
To contribute to the continuous enhancement of the Information Security Review process by making iterative enhancements to the overall approach, workflow, scope and implementation in alignment with the needs of Group Information Security's customers and according to the changing technical, regulatory and business environment.
The impact for failing to undertake the Information Security Reviews effectively, could include a significant failure in the Group's security posture leading to highly damaging reputation damage, loss of public confidence, regulatory penalties and legal proceedings against the company and its executives.
KEY ACCOUNTABILITIES
The role sits within the Group Information Security - Application Security team and have the accountabilityfor Information Security Review for all the 10 Businessunits in Asia Pacific.
Be the tandem partner with the senior manager leading the Information Security Reviews.
Perform and coordinate Information Security Reviews throughout the lifecycle of a project.
Drive awareness and support to Group IT Security, Group IT and Business Units IT, to understand the I TSecurity Architecture process, as well as their implications across the organizations.
Deliver a consultative service to all stakeholders involved with the Information Security Reviews and, in doing so, provide a measurable benefit to the Group's IT projects in terms of their successful, timely and secure delivery.
The timely identification of key risks leading to their successful remediation without un due delay to the delivery of business objectives.
Act as a Subject Matter Expert for all information security aspects of all projects and, in doing so, facilitate the efficient and secure delivery of those projects.
Identify technical risks as result of the security reviews, ensure these risks are reported to the appropriate risk team (s) to track remediation within the agreed timeframes.
Initiate and evaluate projects, to build and enhance new capabilities in the Company, that related to Identify, Protect, Detect, Respond and Recover to technical risks.
Align security reviews to the Company Group Information Security and overall IT Strategy needs.
Manage allocated resources to deliver the security reviews (either internal staff or vendors).
Collaborate with other Cyber Incident Response and Threat Intel teams on evaluation of weaknesses or new risks that require Group Information Security continuous improvement.
Provide expertise to Business Units when needed, in building local IT Security solutions.
KEY PERFORMANCE INDICATORS
Delivery of security assessments in accordance with the SLAs for this service line.
Deliver a consultative service to all stakeholders involved with the Information Security Reviews and, in doing so, provide a measurable benefit to the Group's IT projects in terms of their successful, timely and secure delivery.
The timely identification of key risks leading to their successful remediation without undue delay to the delivery of business objectives.
Act as a Subject Matter Expert for all information security aspects of all projects and, in doing so, facilitate the efficient and secure delivery of those projects.
EXTERNAL & INTERNAL CONTACTS
Group Head of Application Security
Group CISO
Business Units IT Security Teams
Group and Business Units Chief of Technology and Operations
Group and Business Units IT & Operations
Group and Business Units Internal Audit
External Auditors
Vendors and/or Service Providers

JOB REQUIREMENT

QUALIFICATIONS / EXPERIENCE
University degree from Information Technology or equivalent discipline.
Minimum 8 years working experience in IT Security Management role, preferably in Financial Services.
Regional experience in IT Security Technical or Engineering roles.
Technical experience in Identify, Protect, Detect, Response or Recover areas.
Sufficient experience and Subject Matter Expert level of knowledge in fields of Information Security & solid understanding of project teams' needs. For instance, secure architecture design, risk assessment and remediation & general IT technologies.
Sound consulting capability including, clear and concise written and verbal communications, ability to manage senior stakeholders, and work on high profile projects with tight timelines, always present logical thinking and problemsolving capabilities even under pressures.
KNOWLEDGE & TECHNICAL SKILLS
Certifications or official training on Cloud IAAS, CASB, SIEM solutions, WAF solutions, End Point Protection solutions, Firewall & IPS solutions, NGAV and ED Rsolutions, Orchestration and Automation, Web, Email and DNS Protection, etc.
Excellent interpersonal and influential skills.
Good communication and presentation skills.
Collaborative, consultative and customer service focussed approach to delivery.
Leadership skills, problem solving anddecision making skills; as the incumbenth as to deal with a cross section of stakeholders across 10 countries.

WHAT'S ON OFFER

13th salary
Bonus paid in April next year if joining before Oct 2024
Paid leave up to 22 days per year (prorated for partially joining)
Work remote 1 day per week
Health insurance for employees and direct dependents

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Salary:

Negotiation

Job ID:

J01575

Status:

Close

Related Job:

Senior/Middle QA Engineer

Ho Chi Minh - Viet Nam


Product

  • Automation Test
  • Playwright
  • Typescript
  • Selenium
  • Java

#The Opportunity Implement, maintain the automations test scripts using such as tools: Playwright with Typescript, Selenium with Java. Implement API service testing with Rest API using Playwright. Implement Api performance testing scenarios using JMeter. Work with SQL, MongoDB, Atlast MongoBD, CI/CD Jenkins, Docker, AzureDevOps, AWS, TestOps … Record and maintain source code in GitHub for automation scripts Participate in standup meeting, grooming meeting, product backlog to review of product requirements to understand test objectives, to provide input on testability of requirements and estimation for the testing activities. Provide the testing approach, develop the automation test scripts, reduce the manual testing by increasing automations testing coverage. Design the test case, writing the automation scripts, performance test scripts by JMeter. Participate and understand the testing process, testing strategy to apply into the daily testing activity. Collaborative with project team, PO, QA Manager/Lead to understand project objectives, releasing cycle, gather automation requirements, design automated tests, and troubleshoot issues. Maintain and fixing the automation test scripts, submit the issue to defect management system. Participate in project meetings to discuss and agree on automation testing approach. Do manual testing.#Key Responsibilities Participate in standup meeting, grooming meeting, product backlog to review of product requirements to understand test objectives, to provide input on testability of requirements and estimation for the testing activities. Provide the testing approach, develop the automation test scripts, reduce the manual testing by increasing automations testing coverage. Design the manual test case, writing the automation scripts, performance test scripts by JMeter. Participate and understand the testing process, testing strategy to apply into the daily testing activity. Collaborative with project team, PO, QA Manager/Lead to understand project objectives, releasing cycle, gather automation requirements, design automated tests, and troubleshoot issues. Maintain and fixing the automation test scripts, submit the issue to defect management system. Report the defects/bug into discover into Defect tracking management tool like Jira. Collaborate with the Agile team to provide the testing result for User Stories and approve for the US to move next environment.

Negotiation

View details

Senior Fullstack Engineer

Ho Chi Minh - Viet Nam


Product

  • Java
  • Angular
  • Microservices
  • AWS
  • Azure

#The Opportunity You will reach your full capabilities by developing innovative products with trending and cutting-edge cloud and microservices technologies with a full lifecycle - you propose it, you build it, you own it. You are the foundation of one potential and game-changer startup in Insurance Doma.#Key ResponsibilitiesYour key responsibilities as Senior Full-stack Engineers will include: Develop and understand the enterprise data landscape and map data stores and -flows between the operational systems for our micro-service approach Implementing the feature with high performance, scalable and testable components for our architecture and execute its development. Developing and deploying modern architectural patterns/techniques (microservices, DDD, TDD) including developing using modern frameworks, e.g. Spring Boot, Spring Cloud Developing and deploying modern frontend microservices, enrich DM Storybook using the latest Angular version. Develop RESTful APIs and microservices-based solution leveraging containers (AKS, Kubernetes, Docker) technologies. Using AI coding tools to speed up the development. Understand AI-Powered insurance solutions such as AI claim processing, recommendation engine... Hold yourself accountable to high engineering standards, pay special attention to performance and scalability Collaboration with architects, engineers and project teams to ensure engineering principles are met and built and act as a change agent Write structured, well-documented, maintainable, and clean code Demonstrate strong English communication skills (both verbal & written) Utilize rapid prototyping techniques to accelerate time-to-market for our customers Trend scouting around new technology

Negotiation

View details

Senior Signal Processing Engineer

Others - Viet Nam


Outsource

  • Python

Design and improve rPPG/TOI pipelines using RGB/IR video with motion/illumination compensation. Implement multi-stage preprocessing, denoising, and quality scoring. Examples: adaptive filtering, ICA/PCA variants, color-space transforms, skin ROI stabilization, signal confidence metrics. o Build cross-device normalization strategies and error-bounded estimators. Define biomarker-level acceptance criteria and failure modes for consumer-grade capture. Partner with iOS and ML teams to integrate algorithms into on-device or hybrid pipelines. Produce technical documentation suitable for regulatory-risk positioning and Apple review support. Benchmark report across device models, skin tones, lighting, and motion conditions. Biomarker feature specification sheet with recommended thresholds and confidence bands. A/B results showing improvements in stability, missingness, and downstream inference performance.

Negotiation

View details