Senior/Expert, IT Security Life Insurance Project

TECHCOMBANK
Mức lương
Đang cập nhật
Địa điểm làm việc
Cầu Giấy, Hà Nội
Kinh nghiệm yêu cầu
Cập nhật
Thông tin cơ bản

Mô tả công việc

Mô tả công việc

Job Purpose

The job holder is responsible for building, managing, participating in the development of one of the following areas:
IS Monitoring: Monitor detecting all attack events/incidents as quickly as possible (realtime) based on events aggregated from security systems as well as other technology components.Then alert relevant departments to investigate and react to that event/incident.
IS Red team: Manage and directly perform testing attack activities for technology systems to detect vulnerabilities/weaknesses and provide solution guidance.
IS Administration: Manage and directly participate in administrative activities on identity and access security/network security/endpoint services and data security
IS Engieering: Manage and directly control the implementation of information security policies and standards for applications, infrastructure of Techcombank and its partners and suppliers, ensure compliance with the Business&039;s information security requirements.
IS Practice: Evaluate deployment, develop security solutions/Design, test information security/Ensure compliance with security standards (of Vietnam and International)

Key Accountabilities (1)

Information Security Assurance
- Coordinate with the Information Security supervisory department in handling information security incidents.
- Participate in projects, developing and deploying technology to ensure Information Security for systems to be built, including stages: analysis, building requirements Information security, design Information security, threat modeling, source code review, testing and building controls to ensure Information Security.
- Implement and maintain compliance with TCB&039;s policies, circulars and regulations of the State Bank.
- Implement and maintain compliance with international standards PCI- DSS, ISO, SWIFT CSP.
- Research and develop necessary information security solutions to prevent attacks and incidents Information security, ensure security and safety for the entire information system of the Business.
- Regularly perform compliance and integrity checks
- Set up and monitor the implementation of TCB&039;s information security process, regulations, standards, guidelines and policies in accordance with the regulations of the government and international organizations
f the security policy configuration in the internal system TCB detects violations or insider attacks.
- Coordinate with Compliance Assessment and Risk Management units to assess the compliance of technology systems according to policies, regulations, standards, processes, checklists.

Key Accountabilities (2)

Information Security Red team:
- Implement the strategy to ensure information security:
+ Participate in the implementation of the Information Security strategy by providing input data on attack trends, forms of exploitation and risks arising in each period.
+ Develop new techniques, exploit scripts and programs for automated penetration testing
+ Participate in the implementation of the annual information security implementation plan, meet the business and operational needs of the bank through the implementation of information security testing programs for the technology activities of the Business.
+ Develop penetration testing methods, information security scanning scripts and security checks according to international standards such as OSSTMM, Sans and OWASP.
- Perform test attack activities:
+ Directly participate in the experimental plan of responding to an Information Security incident as an attack unit and in the case of an actual Information Security incident as the response team. Coordinate and provide expert cyber defense engineering skills to resolve cyber attack incidents
+ Actively research / find new vulnerabilities, exploitation techniques and cyber threats; Identify trends in cybersecurity involving tactics, techniques, and processes, targeting for malware development and deployment.
+ Develop and manage vulnerability management program, threat intelligence database. Collect, track metrics, and analyze trends on cyber defenses, threats, detected attacks, vulnerabilities, and countermeasures/preventions.
+ Perform regular vulnerability scans, information security checks to find vulnerabilities in the system and provide remedial / remedial solutions; supports maintaining compliance with world security standards such as PCI- DSS, ISO27001, SCP (swift).
+ Directly perform vulnerability detection review, vulnerability assessment, and conduct penetration/exploit testing periodically or at the request of the Block leader for all systems/applications ; Penetration testing for system/application after live detection or whenever undergoing a major change. Testing methods must ensure practicality including both technical (technology) and non- technical (people, processes, physical assets). From there, provide CISO as well as other Information Security departments to have programs to deal with the problems of system weaknesses that can be exploited.

Key Accountabilities (3)

Information Security Administration
- Develop, maintain and optimize information security policy/rule/configuration for solutions to ensure information security such as: Information security solutions on access identity management (PAM, IAM…); Network information security solutions (Firewall, NAC, APT, NetIPS, DDOS...); Information Security solutions on endpoints (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security…); Information security solutions on data (DLP, FAM...).
- Develop requirements and measures to control access and protect the Business&039;s data.
- Building/adjusting and implementing MTPQ of systems.
- Assess, evaluate, review:
+ The issue and withdrawal of privileged accounts and digital certificates on technology systems.
+ Exception requirements related to identity, access rights on technology systems
+ Change requirements on information security assurance solutions.
+ Decentralization enforcement ensures compliance with the decentralized matrix.
- Risk management and compliance
+ Identify risks of the department in the process of operation, ensuring compliance with the processes and regulations of the Business. Coordinate with relevant units to handle risks.
+ Perform risk treatment activities according to reports of internal/external audit departments.

Yêu cầu công việc

Yêu cầu công việc

Qualification:
- Having certificates of companies providing security solutions such as Microsoft/Cisco/PaloAlto/Checkpoint/Cyberark/Sailpoint…”
- Certificates in information security such as OSCP, PCI DSS assessment implementation certificate, ISO
- Having ISC2 SSCP security certificates is an advantage
- Having certificates in information security such as- SANS SEC660, SEC760, SANS SEC642, SANS SEC575, OSCE, OSCP
- Graduated in IT, Computer Science or Telecommunications
- Foreign language: English: Level 1 – TOEIC under 550
Experience:
- Experience in performing security testing in financial / service / telecommunications organizations from 5 years. The experience includes the following aspects:
+ Implement PCI- DSS, ISO, Swift CSP... Participate in the development and control of compliance with security standards for IT systems
+ Research, design, implement and evaluate Information security for systems and applications
- Experience in performing security testing in financial / service / telecommunications organizations. The experience includes the following aspects:
+ Experience in researching security holes, developing attack techniques/tools, performing attack testing of technology systems by technical and non- technical measures)
- Having experience in implementing, managing, and operating in- depth in terms of policies, set of rules, configuration of information security at least one of the following areas at financial/service/telecommunications organizations (5 years):
- Data security solutions (DLP, FAM...).
- Security solutions for access identity management (PAM, IAM...);
- Security solutions for terminals (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security...);
- Experience in information security assessment according to Agile method
- Network security solutions (Firewall, NAC, APT, NetIPS, DDOS...);

Quyền lợi

Tại sao bạn sẽ yêu thích làm việc tại đây

WHY BECOME IT/DATA EXPERTS AT TECHCOMBANK?

Investing over 500 million USD to develop large- scale IT projects, Techcombank is one of the leading bank in Technology trends in Vietnam
Techcombank is the Top 2 Best place to work in the banking industry where you can experience various exciting activities throughout the year: Company anniversary, Team building, Active Saturday , Year End Party, etc.
Techcombank provides a rewarding remuneration structure that commensurate with your achievement and contribution
You will grow with Techcombank by having the opportunity to learn from top experts from across the world

Cập nhật gần nhất lúc: 2025-08-23 19:35:03

Xem thêm

Đặc điểm công việc

Hạn nộp hồ sơ
26/09/2025
Hình thức làm việc
Đang cập nhật
Cấp bậc
Nhân Viên
Số lượng cần tuyển
Đang Cập Nhật
Ngành nghề
IT phần mềm
Khu vực
Cầu Giấy, Hà Nội
Xem thêm
Xem thêm
Người tìm việc lưu ý:
Bạn đang xem tin Senior/Expert, IT Security Life Insurance Project - Mã tin đăng: 5231113. Mọi thông tin liên quan tới tin tuyển dụng này là do người đăng tin đăng tải và chịu trách nhiệm. Chúng tôi luôn cố gắng để có chất lượng thông tin tốt nhất, nhưng chúng tôi không đảm bảo và không chịu trách nhiệm về bất kỳ nội dung nào liên quan tới tin việc làm này. Nếu người tìm việc phát hiện có sai sót hay vấn đề gì xin hãy báo cáo cho chúng tôi

Các tìm kiếm khác liên quan đến công việc It security

TECHCOMBANK

Quy mô: 200 - 500
Trụ sở: 191 Bà Triệu, Hai Ba Trung, Ha Noi

Bí kíp tìm việc an toàn

Dưới đây là những dấu hiệu của các tổ chức, cá nhân tuyển dụng không minh bạch:
1. Dấu hiệu phổ biến:
Hình ảnh 1
Nội dung mô tả công việc sơ sài, không đồng nhất với công việc thực tế
Hình ảnh 2
Hứa hẹn "việc nhẹ lương cao", không cần bỏ nhiều công sức dễ dàng lấy tiền "khủng"
Hình ảnh 3
Yêu cầu tải app, nạp tiền, làm nhiệm vụ
Hình ảnh 4
Yêu cầu nộp phí phỏng vấn, phí giữ chỗ...
Hình ảnh 5
Yêu cầu ký kết giấy tờ không rõ ràng hoặc nộp giấy tờ gốc
Hình ảnh 6
Địa điểm phỏng vấn bất bình thường
2. Cần làm gì khi gặp việc làm, công ty không minh bạch:
- Kiểm tra thông tin về công ty, việc làm trước khi ứng tuyển
- Báo cáo tin tuyển dụng với 123job thông qua nút "Báo cáo tin tuyển dụng" để được hỗ trợ và giúp các ứng viên khác tránh được rủi ro
- Hoặc liên hệ với 123job thông qua kênh hỗ trợ ứng viên của 123job:
Hotline: 0961.469.398

Việc làm đề xuất liên quan

Việc làm đã xem gần đây

Từ khóa tìm việc làm tại 123Job