SOC Management Specialist

ABOUT CLIENT

Our client is a leading cyber security company in Vietnam

JOB DESCRIPTION

Quản lý và kiểm soát chất lượng dịch vụ: Đảm bảo chất lượng các dịch vụ an toàn thông tin (ATTT) cung cấp cho nhóm khách hàng của công ty, bao gồm: Giám sát ATTT 24/7, Xử lý sự cố, Threat Hunting, Threat Intelligence, ...
Quản lý mức độ trưởng thành ATTT: Thực hiện đánh giá, tư vấn và đề xuất giải pháp nhằm nâng cao mức độ trưởng thành về ATTT cho khách hàng.
Quản lý rủi ro và mối đe dọa ATTT: Theo dõi, phân tích và quản lý rủi ro ATTT cũng như tiếp xúc liên tục với các mối đe dọa đối với hệ thống của khách hàng.
Nhận diện và xử lý vấn đề ATTT: Phát hiện và quản lý các vấn đề phát sinh liên quan đến ATTT trong quá trình giám sát vận hành và xử lý sự cố.
Phối hợp liên phòng ban: Đại diện Trung tâm Giám sát (TTGS) làm việc với các bộ phận nội bộ VCS như Triển khai, Phát triển giải pháp, Quản lý dự án (PM), Kinh doanh, Pre-sale, Account Manager (AM), Chăm sóc khách hàng (CSKH), ... và khách hàng để phối hợp xử lý các vấn đề trong phạm vi dịch vụ cung cấp.
Đảm bảo cam kết dịch vụ (SLA): Theo dõi và đảm bảo các chỉ số SLA được thực hiện đúng theo hợp đồng đã ký kết với khách hàng.

JOB REQUIREMENT

Trình độ học vấn:
Tốt nghiệp Đại học chuyên ngành: An toàn thông tin; Công nghệ thông tin, Khoa học máy tính, Toán - Tin…
Tiếng Anh tương đương 650 TOEIC trở lên
Yêu cầu/Năng lực:
Trên 4 năm kinh nghiệm về Giám sát ATTT (SOC) hoặc MỘT trong các chuyên môn: Đánh giá rủi ro ATTT, Xử lý sự cố, Pentest, System Security…
Có kỹ năng giao tiếp tốt, kinh nghiệm tương tác với khách hàng và phối hợp làm việc với các phòng ban trong doanh nghiệp
Ưu tiên (không bắt buộc):
Có kiến thức về An toàn thông tin, tương đương chứng chỉ Security+
Có kiến thức về hacking technique, tương đương chứng chỉ CEH
Có kinh nghiệm quản lý rủi ro ATTT trong doanh nghiệp là lợi thế
Ưu tiên có các chứng chỉ về quản lý dự án, chứng chỉ về ATTT (CISSP, CISM, CEH…)
Kỹ năng mềm:
Có kỹ năng làm việc nhóm, chịu áp lực tốt
Khả năng tìm kiếm thông tin
Tuân thủ kỷ luật, giờ giấc và mức độ commitment

WHAT'S ON OFFER

Mức thu nhập hàng năm cạnh tranh
Cơ hội làm việc với khách hàng đa dạng trong và ngoài nước
Đánh giá và điều chỉnh lương hàng năm vào tháng 3
Bảo hiểm sức khỏe và tai nạn cá nhân với Hạn mức chi trả lên đến 600 triệu/năm
Kiểm tra sức khỏe hàng năm
Giải thưởng cho năng lực và đóng góp xuất sắc
Hỗ trợ chi phí 100% cho các chứng chỉ chuyên môn quốc tế, khen thưởng đặc biệt cho nhân viên đạt chứng chỉ chuyên môn quốc tế
Đầu tư liên tục vào học liệu mới nhất về lĩnh vực ATTT từ các nhà cung cấp uy tín hàng đầu thế giới
Cung cấp tài khoản Elearning từ Udemy cho mọi nhân viên
Miễn phí tham gia các chương trình chia sẻ kiến thức chuyên ngành và hội thảo chuyên môn
Văn phòng tiêu chuẩn hạng A tại tòa nhà Landmark 72 với không gian xanh và khu vực giải trí, gym
Thời gian thư giãn hàng ngày với hoạt động Happy hours
Các hoạt động thể thao và giải trí như câu lạc bộ bóng đá, bi-a, pocker, pes, v.v.
12 ngày phép năm theo quy định Luật Lao Động, và thêm 3 ngày nghỉ mát cùng các ngày lễ truyền thống
Tổ chức sinh nhật cá nhân với quà tặng và bánh sinh nhật từ công ty
Tham gia các sự kiện và hoạt động như Teambuilding, Sinh nhật hàng tháng, Year End Party, nghỉ mát, ngày lễ 08/03, 20/10 và ngày sinh nhật tập đoàn

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security, System, Network

Location:

Ho Chi Minh, Ha Noi - Viet Nam

Working Policy:

Onsite

Job ID:

J01960

Status:

Close

Related Job:

Senior AI DevSecOps Engineer

Ho Chi Minh - Viet Nam


Product

  • Devops
  • AWS
  • Azure
  • Security

Management of CI/CD Pipeline: Ensure automation, security, and scalability across all stages of the development lifecycle. Infrastructure & Security: Design and implement secure multi-cloud infrastructure solutions leveraging cloud services, containerization, and orchestration tools. Policy as Code: Define and enforce security and compliance policies across Kubernetes clusters using OPA or Kyverno, ensuring guardrails are automated and auditable. AI & Platform Automation: Drive the adoption of AI-powered tools and workflows to automate infrastructure operations, optimize CI/CD pipelines, accelerate root cause analysis, improve security posture, and enhance engineering productivity. Observability & Alerting: Build and maintain a comprehensive observability stack with proactive alerting, dashboards, and runbooks for critical business flows and security events. Secret & Credential Management: Design and enforce secrets management practices across all environments ensuring zero hardcoded credentials in codebases and pipelines. Incident Response & On-Call: Own and continuously improve incident response processes, define runbooks, lead post-mortems, track MTTR, and participate in on-call rotation to maintain platform reliability and SLO adherence. Threat Modelling & Penetration Testing: Conduct regular threat modelling sessions with engineering teams and coordinate or perform penetration testing activities to proactively identify attack surfaces before they reach production. Code Security: Conduct regular code reviews and static/dynamic analysis to identify and remediate security vulnerabilities. Compliance and Best Practices: Ensure compliance with industry standards and best practices. Collaboration: Collaborate with development, operations, and security teams to foster a culture of automation and security-first thinking. Mentorship: Mentor junior engineers and other team members on security best practices. Documentation: Maintain thorough and up-to-date documentation of security policies, procedures, and incident reports. Trend Scouting: Stay updated with the latest trends in technology and AI to integrate innovative solutions into our processes.

Negotiation

View details

Head of Engineering - Marketing Technology

Ho Chi Minh - Viet Nam


Product

  • Management

Develop an integrated roadmap for strategic execution based on the organization's strategic aspirations and lead the implementation process from planning to delivery. Manage multiple engineering teams throughout the organization to achieve desired outcomes, hence having knowledge of the organization's specific areas of operation is an advantage. Collaborate closely with business teams and product owners to verify requirements before and after delivery through showcases and post-production monitoring. Take responsibility for both the development and operation of applications in production, providing active operational support and establishing a clear support model with a focus on site reliability engineering. Direct and oversee the implementation of cybersecurity updates, including keeping software versions current and patching infrastructure regularly. Oversee investment allocation across the organization to maintain alignment, ensure effective spending, and offer insights on the effectiveness and prioritization of investments. Integrate engineering excellence with domain expertise in marketing while pursuing strategic technology objectives.

Negotiation

View details

Lead Penetration Tester

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments. Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues. Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices. Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks. Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments. Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved. Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation. Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices. Lead the planning, scoping, and execution of penetration testing activities across assigned projects. Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements. Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions. Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value. Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams. Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders. Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities. Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices. Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

Negotiation

View details