MÔ TẢ CÔNG VIỆC
-
- Lead vulnerability management activities, including vulnerability identification, assessment, prioritization, and remediation tracking across applications, infrastructure, and cloud environments.
- Conduct security assessments and collaborate with Engineering, DevOps, and Product teams to strengthen security posture and reduce risks.
- Establish and maintain vulnerability management processes aligned with OWASP, NIST, ISO 27001, and Secure SDLC best practices.
- Monitor emerging threats, coordinate penetration testing activities, and provide security reporting, metrics, and remediation guidance to stakeholders.
QUYỀN LỢI
-
- Competitive salary package of up to VND 33,000,000 per month.
- No probation period – employees are onboarded as official staff from day one with 100% salary and full statutory insurance coverage (Social Insurance, Health Insurance, Unemployment Insurance).
- Attractive bonus schemes, including seniority bonus, project bonus, 13th-month salary, and annual performance bonus.
- Participate in company activities such as monthly/quarterly gatherings, team building events, company trips, and retreats.
- Opportunity to work on large-scale, advanced systems and enhance technical expertise through complex, high-impact projects.
- Performance and salary reviews conducted twice a year.
- Clear career growth path with promotion and salary increase opportunities based on performance and capability.
- Exposure to ambitious international projects, cutting-edge technologies, and collaboration with highly skilled professionals.
- Access to professional training programs, including AWS, Microservices, English, Japanese, and other technical and soft-skill courses.
YÊU CẦU
-
- Minimum 2 years of experience in Vulnerability Management, Application Security, or related cybersecurity roles.
- Strong knowledge of OWASP Top 10, ISO 27001, NIST frameworks, Secure SDLC, and vulnerability remediation processes.
- Hands-on experience with vulnerability assessment tools, penetration testing, security scanning, and risk management.
- Experience with Cloud platforms (AWS/Azure/GCP), Kubernetes, DevSecOps, or Fintech environments is highly preferred; security certifications (CISSP, CISM, CEH, SANS) are a plus.
- Strong analytical, problem-solving, and communication skills, with good English proficiency and the ability to work effectively with both technical and business teams.
.png)