IT Security Governance (Senior/Expert)
FE CREDIT
Mô tả công việc
Objectives Implement and maintain governance, policy, and risk management functions across teams within the IT Division — ensuring appropriate policies and controls are in place for effective service delivery and regulatory compliance, while continuously monitoring, coordinating, and executing required enhancements to improve performance, reduce issues, and mitigate IT-wide risks. Key Responsibilities Policy & Regulatory Compliance Develop, review, and update Information Security policies, regulations, and procedures in compliance with State Bank of Vietnam (SBV) requirements, Vietnamese laws (including Decree 13 on Personal Data Protection), and international standards (ISO 27001, PCI-DSS). Prepare and maintain regulatory documentation such as Personal Data Processing Impact Assessment (DPIA) dossiers, and liaise with responsible authorities on personal data protection matters. Advise and guide colleagues across the IT Division on issued policies, procedures, and standards, ensuring they are implemented correctly and consistently. Governance Frameworks & Assessments Execute IT governance frameworks and internal/international standards, monitoring closely to ensure effective implementation across IT functions. Conduct Information Security and IT compliance assessments against legal and regulatory requirements. Perform technology risk assessments based on the company's operational risk management framework; propose appropriate controls to mitigate identified risks. Audit and evaluate the effectiveness of personal data protection measures and security controls. Risk Monitoring & Reporting Collaborate with relevant stakeholders to periodically report Key Risk Indicators (KRIs) and IT risk posture to management. Act as focal point for monitoring and supervising the remediation of findings from internal audits, independent audits, and other inspections. Periodically report on high-risk IT incidents and compliance status. Awareness & Capability Building Develop and deliver Information Security awareness training materials and programs for all staff. Communicate governance activities and policy changes within the IT Division, ensuring teams understand how these affect IT services and deliverables. Continuous Improvement Analyze and improve existing IT policies, procedures, and practices; recommend changes to align with evolving standards and best practices. Stay updated on new regulations and industry best practices to recommend proactive improvements. Work closely with cross-functional IT departments to develop and coordinate a compliance schedule tailored to applicable regulations and standards.
Yêu cầu công việc
Education & Certifications University degree, preferably in Information Security, Information Technology, or a related technical field. Relevant certifications strongly preferred: ISO 27001 Lead Auditor, ITIL 4, Personal Data Protection Expert (VnDPO), or equivalent. Experience Minimum 4 years of experience in IT Governance, IT Risk & Compliance, or Information Security Management — preferably in banking, financial services, or consumer finance. Proven hands-on experience in developing and maintaining Information Security policies aligned with SBV regulations and international standards. Demonstrated experience conducting internal security & compliance audits, IT risk assessments, and supporting external/independent audits. Practical knowledge of Access Control management (user reviews, role matrix, IAM, privileged access management). Experience with third-party/vendor risk management and security compliance assessments. Familiarity with industry frameworks and standards: ISMS (ISO 27001), ITSM (ITIL), PCI-DSS. Experience in process design and documentation. Working knowledge of project methodologies and tools; familiarity with change management processes (e.g., Change Advisory Board participation) is a plus.
Quyền lợi
See yourselves in a new light In essence of joining our company, you will be given the scope to seize every opportunity and helped to acquire specific competencies you’ll need to succeed either you wish to go wide or go deep. Our company prides ourselves on our underpinned principle of nurturing people in not only HR policies but also in our culture. We value innovations and we need people to work on initiatives and carry on our business vision of operating excellence and market leadership. Alongside with these, we believe our staff members deserve a good working condition, so that in addition to social health insurance you will be accessible to health and accident insurance and will be eligible to join in team building every year. We also value your efforts; for this reason, we give you both financial and non-financial rewards such as: KPI bonus, Best Initiatives, Best performer or Best manager of the year, etc. Company's Benefits Financial support: Probation with full salary Lunch allowance Wedding support Family funeral support 13th month salary + KPIs bonus Performance rewards and awards Healthcare Insurance Events and activities: Christmas Year End party Team Building Family Day Sport Day