Incident Management & Root Cause Analysis: Capable of leading post- incident reviews, conducting root cause analysis, and implementing corrective actions to prevent recurrence.
Policy Development & Implementation: Proven ability to draft, implement, and maintain IT policies and procedures across diverse technical domains including access control, data protection, and third- party risk.
Stakeholder Engagement: Effective communicator with the ability to influence senior leadership and cross- functional teams. Experience in presenting risk scenarios and mitigation strategies to non- technical audiences.
Experience with SOC 1, SOC 2, and control- based reviews.
Bachelor’s degree in information technology, Cybersecurity, or related field. ITIL certification or equivalent experience preferred.
Governance & Compliance: Expertise in designing and enforcing IT governance structures. Deep familiarity with regulatory requirements including SOX, GDPR, and FedRamp, and experience managing audits and control reviews (SOC 1, SOC 2).
Risk Management Expertise: Advanced knowledge of IT risk identification, assessment, and mitigation techniques. Skilled in applying risk frameworks such as NIST RMF, ISO 31000, and COBIT to complex enterprise environments.
Ability to travel as needed to support global and regional operations.
Proven experience in IT risk management, cybersecurity, and governance.
Strong understanding of MITRE ATT&CK or similar frameworks.
Excellent written and oral English and Local Language.
Excellent leadership, organizational, and interpersonal skills with a proven ability to build and mentor high- performing teams.
Tooling & Automation: Hands- on experience with GRC platforms, vulnerability scanners (e.g., Qualys, Tenable), and risk analytics tools. Ability to evaluate and onboard new technologies to enhance risk visibility and control effectiveness.
Cybersecurity Acumen: Strong understanding of threat modeling, vulnerability management, and incident response. Familiarity with MITRE ATT&CK, CVSS scoring, and SOC operations.
Analytical & Reporting Skills: Ability to interpret technical risk data and translate it into actionable insights. Skilled in developing dashboards, KPIs, and executive- level reporting.
***Please note that by submitting an application to us, you consent to our processing of personal data about you that is provided by you and otherwise lawfully collected by us (which may include sensitive data) for our company&039;s recruitment purpose. Where you provide us personal data of others, you further undertake that we are permitted to receive and process such data for the purpose for which you provided it. You may send your queries or request for support concerning our personal data processing activities to hrvn(at)coca- cola.com.vn. To better understand our personal data processing practices, please visit swirecocacola.(com)/en/Others/Privacy- Policies.html to the full Privacy Policy of Coca- Cola Beverages Viet Nam Limited.
Swire Coca- Cola is committed to fostering an environment that values Diversity, Equality, Inclusion, and Belonging. We believe that a diverse workforce drives our goals and contributes to overall success. As an equal opportunity employer, Swire Coca- Cola hires talented individuals from any backgrounds and conditions. We strive to create a work environment that is respectful, inclusive, and free from any form of discrimination, harassment, or intimidation. If you require special assistance due to disability or any other conditions during any stage of the recruitment process, please feel free to contact us via email hrvn(at)coca- cola.com.vn at any time. We appreciate your interest in joining our team and your commitment to contributing to a diverse and inclusive workplace