Senior Manager IT Security Engineer

JOB DESCRIPTION

PURPOSE
Drive the Company's IT Security Engineering function as a SME for the Company and all Business Units (10 Business Units) in Asia Pacific.
Define and partner with stakeholders in a multi-disciplined team structure, designing and implementing cloud security solutions to provide coverage across a variety of projects
Lead stakeholders' and vendors engagements and providing subject matter expertise to Business Units and engagement teams
Develop deep working relationships with senior executives across engagement teams.
Responsible and execute large-scale project deliveries
Manage teams and mentor junior resources
Oversee infrastructure and microservices security architecture (inclusive of: container security architecture, data security architecture, network security architecture and operational security architecture).
Review the infrastructure and microservices design against different security regulatory, industry and internal standards such as PCI DSSand CSA Containers' security guidelines and identifying the necessary security architecture requirements for the same.
Review the infrastructure and microservices network and data architecture and identifying the necessary security architecture requirements for the same.
Ensure that final design addresses identified threats and countermeasures during threat modelling.
Build knowledge capital through research and development and leveraging industry insights to deliver best of breed expertise to stakeholders.
Lead the growth of cloud security practice across business units, project team and other stakeholders.
Drive IT Security Engineering Initiatives and Projects definition and implementation, selection of solutions and architecture, as well as define operations framework and its continuous improvement.
KEY ACCOUNTABILITIES
Support the Head of IT Security Engineering in define and maintainthe IT Security Engineering framework for the Company.
Drive awareness and support to Group IT Security, Group IT and Business Units IT, to understand the IT Security Solutions and Processes, as well as their implications across the organization.
Drive IT Security Engineering Initiatives and Projects definition and implementation, selection of solutions and architecture, as well as define operations framework and its continuous improvement.
Partner with the Head of IT Security Engineering and Group CISO, through tracking and reporting function, to ensure regular updates to management on the IT Security Engineering Program and risks.
KEY PERFORMANCE INDICATORS
On Time on Budget delivery ofkey IT Security Engineering Program uplifts or deployments, aligned with Group IT Security roadmap.
Support the Head of IT Security Engineering in continuous uplift of the IT Security Engineering program.
Ensure IT Security Engineering Program across Business Units is carried out in alignment with the Company's business objectives and defined IT Security Plan timelines.
Group IT Security Engineering Security Framework implementation and controls are delivered in a cost-effective way using processes and resources (including people andtechnologies) aligned with the Company's business goals.
Group IT Security Engineering support and governance are provided for all Business Units.
IT Security Engineering Program awareness is conducted when necessary.
Doing things right, creating synergies for the overall the Company's goals and objectives, along with a people first approach.
EXTERNAL & INTERNALCONTACTS
Head of IT Security Engineering
Group CISO
Business Units IT SecurityTeams
Group and Business Units Chief of Technology and Operations
Group and Business Units IT & Operations
Group and Business UnitsInternal Audit
External Auditors
Vendors and/or Service Providers

JOB REQUIREMENT

QUALIFICATIONS / EXPERIENCE
Minimum 8 years working experience in IT Security Management role, preferably in Financial Services.
Regional experience in IT Security Technical or Engineering roles.
Degree from Information Technology or equivalent discipline.
Technical experience in Identify, Protect, Detect, Response or Recover areas.
KNOWLEDGE & TECHNICALSKILLS
Cloud security-related certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud SecurityProfessional (CCSP), or any cloud provider-specific security certifications.
A robust grasp of cloud security best practices, principles, and patterns. This should include knowledge of the Shared Responsibility Model and an understanding of how it impacts security posture.
In-depth knowledge of at least one major cloud service provider (e.g., AWS, Azure, GCP) with a comprehensive understanding of their service offerings, architecture, and security controls.
Experience with scripting and automation tools to streamline security operations.
Knowledge of vulnerability scanning tools and techniques, as well as experience with there mediation of identified vulnerabilities.
Knowledge of cloud networking constructs, security groups, network ACLs, and other network security methodologies.
Excellent interpersonal and influential skills to enable the implementation and enforcement of the IT Security Engineering program.
Good communication and presentation skills.

WHAT'S ON OFFER

13th salary
Bonus paid in April next year if joining before Oct 2024
Paid leave up to 22 days per year (prorated for partially joining)
Work remote 1 day per week
Health insurance for employees and direct dependents

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

insurance, Hongkong company

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Salary:

Negotiation

Job ID:

J01572

Status:

Close

Related Job:

Penetration Tester

Ha Noi - Viet Nam


Product

  • Pentest

Tham gia triển khai dịch vụ pentest cho khách hàng: tiếp nhận yêu cầu, xác định phạm vi và điều kiện đảm bảo của các dự án pentest được giao. Phân chia công việc theo quy trình pentest và giao cho các thành viên thực hiện dự án. Hướng dẫn các pentester thực hiện kiểm tra đánh giá ATTT cho ứng dụng. Kiểm soát chất lượng dịch vụ, tuân thủ quy trình, nguồn lực và thời gian triển khai cho các dự án được giao. Là đầu mối kỹ thuật, làm việc với các bộ phận nội bộ và Khách hàng để phối hợp giải quyết các vấn đề trong phạm vi cung cấp dịch vụ. Nghiên cứu cải tiến quy trình, checklist và các kỹ thuật mới nhằm nâng cao chất lượng dịch vụ và năng suất lao động, giảm tỉ lệ sót lỗi. Đảm bảo SLA theo hợp đồng đã ký với Khách hàng.

Negotiation

View details

SOC Management Specialist

Ho Chi Minh, Ha Noi - Viet Nam


Product

  • Security
  • System
  • Network

Quản lý và kiểm soát chất lượng dịch vụ: Đảm bảo chất lượng các dịch vụ an toàn thông tin (ATTT) cung cấp cho nhóm khách hàng của công ty, bao gồm: Giám sát ATTT 24/7, Xử lý sự cố, Threat Hunting, Threat Intelligence, ... Quản lý mức độ trưởng thành ATTT: Thực hiện đánh giá, tư vấn và đề xuất giải pháp nhằm nâng cao mức độ trưởng thành về ATTT cho khách hàng. Quản lý rủi ro và mối đe dọa ATTT: Theo dõi, phân tích và quản lý rủi ro ATTT cũng như tiếp xúc liên tục với các mối đe dọa đối với hệ thống của khách hàng. Nhận diện và xử lý vấn đề ATTT: Phát hiện và quản lý các vấn đề phát sinh liên quan đến ATTT trong quá trình giám sát vận hành và xử lý sự cố. Phối hợp liên phòng ban: Đại diện Trung tâm Giám sát (TTGS) làm việc với các bộ phận nội bộ VCS như Triển khai, Phát triển giải pháp, Quản lý dự án (PM), Kinh doanh, Pre-sale, Account Manager (AM), Chăm sóc khách hàng (CSKH), ... và khách hàng để phối hợp xử lý các vấn đề trong phạm vi dịch vụ cung cấp. Đảm bảo cam kết dịch vụ (SLA): Theo dõi và đảm bảo các chỉ số SLA được thực hiện đúng theo hợp đồng đã ký kết với khách hàng.

Negotiation

View details

Senior Staff Engineer

Ho Chi Minh - Viet Nam


Product

  • NestJS
  • Angular
  • Typescript

Revamp and streamline key components throughout the Angular 20 + NestJS codebase. Recognize and integrate architectural enhancements such as modularization, domain distinction, and shared service boundaries. Work closely with the CTO to refine product architecture without disrupting release schedule. Guarantee system efficiency, data integrity, and sustainability through improved design. Analyze crucial code pathways and mentor others in cutting-edge Angular and TypeScript methodologies. Introduce practices that elevate testability, deployment security, and developer productivity. Engage in product design conversations to synchronize engineering endeavors with actual user requirements.

Negotiation

View details