Senior Security Operations Engineer
Daiichi Life Việt Nam
Mô tả công việc
The Security Operations Engineer is responsible for security monitoring, incident investigation, vulnerability management, security platform operations, and governance and compliance activities across infrastructure, cloud, endpoint, and application environments. The role also takes part in expanding the security team's ownership of security platforms currently operated by other IT teams. This position requires a strong foundation in cybersecurity fundamentals, hands-on experience operating enterprise security platforms, and the ability to work with internal teams, external service providers, and business stakeholders. Experience in application security or penetration testing is a strong advantage. KEY RESPONSIBILITIES: 1 - Security Platform Operations & Engineering: Operate, configure, and maintain security platforms such as SIEM, XDR/EDR, PAM, DLP, and Secure Web Gateway. Tune policies, alerts, dashboards, and platform integrations, and troubleshoot platform issues. Design, implement, test, document, and continuously improve security controls, hardening baselines, and detection use cases. Work with internal IT teams and service providers on platform operations. Act as the technical escalation point for incidents affecting security platforms or security services, and coordinate until service is restored. Support security projects and technology evaluations by contributing operational requirements, technical assessments, implementation support, and post-deployment. 2 - Security Monitoring & Incident Response Monitor and triage security alerts and events and escalate confirmed incidents following the incident response process. Investigate incidents by analysing logs and indicators of compromise, identify root cause, and support containment and remediation. Coordinate containment and remediation with IT Teams, and complete post-incident follow-up. Improve detection rules, alerting, and response playbooks based on incident findings and lessons learned. 3 - Vulnerability Management & Security Assessment Coordinate vulnerability scanning across infrastructure, cloud, endpoint, and application environments, and review scan results to assess risk and prioritise remediation. Track remediation actions to closure with system owners, validate closure evidence, and report overdue or risk-accepted items to management. Coordinate penetration tests and security assessments, including scope preparation, scheduling, result review, and tracking of remediation. 4- Governance, Compliance & Reporting Support security audits and compliance reviews by preparing evidence and following up on action items. Maintain security documentation, including standards, procedures, and operational runbooks. Prepare security reports and metrics for management, monitor agreed service levels and operational deliverables, and coordinate with service providers on service delivery.
Yêu cầu công việc
Education: Bachelor's degree in Information Security, Information Technology, Computer Science, or a related field. Experience: At least 3 – 5 years of experience in Security Operations, Security Engineering, or a closely related cybersecurity role. Experience operating enterprise security platforms in a production environment. Experience operating production systems in an environment with strict operational standards and formal change control. Technical skills: Solid understanding of network security, operating system security, identity and access management, security monitoring, incident response, vulnerability management, and common cyber-attack techniques. Hands-on experience administering several enterprise security technologies, such as SIEM, XDR/EDR, Secure Web Gateway, Web Application Firewall, PAM, DLP, with the ability to learn and operate additional platforms as required. Hands-on experience in security monitoring, log analysis, alert triage, security investigation, and incident response. Basic scripting or automation skills (PowerShell, Python, or Bash). Language and personal skills Good English reading and writing skills, and the ability to join technical discussions in English. Clear communication with both technical and business stakeholders. Structured problem solving and analytical thinking. Able to work under pressure during security incidents and service disruptions, and to decide what matters first. Ability to document work clearly and follow issues through to closure. NICE TO HAVE: Strongly preferred Experience in Application Security, including OWASP Top 10, Secure SDLC, threat modelling, SAST/DAST. Hands-on experience with security testing tools such as Burp Suite, OWASP ZAP, Nmap, or Metasploit. Also considered Knowledge of cloud security (e.g., Azure, AWS, GCP). Experience in security operations for organizations in a regulated sector such as banking, insurance, or financial services, either in-house or as part of a managed security service provider. Familiarity with security frameworks and standards such as ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, or MITRE ATT&CK. Relevant security certifications such as Security+, CySA+, or vendor certifications on the security platforms in use.
Quyền lợi
Salary for 13th month, Bonus & Special Bonus Full of social welfare under Vietnamese Labor Law (Insurance, annual leave,...) Healthcare for yourself & Your Family Annual travel and team building activities 15-16 annual leave days Company will buy Life Insurance Contract for yourself after 1 year working Training: Trained in soft and technical skills International, challenging, and friendly working environment