Mô tả công việc
CG Quản trị ANBM

Main responsibilities

1. Cybersecurity risk and compliance framework and management:

  • Work with VPB Risk Division to develop and adopt risk management framework.
  • Perform the role of Cybersecurity Advisory to new and existing systems to reduce cybersecurity risks on a regular basis.
  • Produce cybersecurity requirements for all systems to protect and reduce the cybersecurity risk for the Bank.
  • Ensure that third party risks are managed
  • Manage the relevant stakeholders so that they understand the risks and be guided in making the right risk decisions for the Bank.
  • Ensure all Cybersecurity Risk are recorded, tracked and addressed in the agreed timeline.
  • Ensure that the IT Security services are effectively implemented

2. Cybersecurity Policy & Standards   

  • Ensure that Cybersecurity Policies and Standards are aligned to SBV requirements and the desired cybersecurity posture of the Bank.
  • Co-ordinate with other teams to develop technical policies, standards, procedures align with VPB Cybersecurity requirements.
  • Develop guidelines to provide directions to stakeholders.

3. Cybersecurity Awareness    

  • Ensure that the Awareness program is implemented effectively.
  • Review and update the Awareness program to ensure relevancy to the current cybersecurity threats.
  • Engage the target audience with the relevant cybersecurity materials and methods to instill a cybersecurity mindset. 

4.Reporting and Administration    

  • Control approves the request/changes related to security, control activities of IT security: implementing, operating, vulnerabilities management
  • Work with both internal/external audit during audit programs
  • Collect, analyze and produce report for IT Security every month    

5. Leadership    

  • Demonstrate and guide the team to achieving the cybersecurity goals to secure the Bank.
  • Develop the team members to ensure that their skills meet the requirements of Business initiatives

6. Projects   

Build up the cybersecurity capabilities to strengthen the cybersecurity posture of the Bank

Educational Background

Đại học in Công nghệ thông tin or Quản trị kinh doanh

Job requirements

Educational background: 

• Bachelor's or Technical Degree Required (IT, Cryptography, computer science, information systems, business administration or other industry-related curriculum)
• IT Security and project management certificates is an advance.

Relevant Experiences: 

• 8 years or more of working experience in IT security banking, good knowledge international IT security standards (ISO 270001, PCI DSS, SBV regulation…)
• 5 years or more of working experience in at least one of domains: Identity Access management, risk management, compliance management, program management, cyber security advisory.
• 3 years or more of working experience in managing team members, including coaching, mentoring, and developing staff.

• Have good knowledge about: Compliance, risk, access, cloud security, data security and third-party management.
• Have basic IT security technical knowledge: Security controls for network, system, application, identity management.
• Knowledge of cybersecurity management framework: NIST, CIS... is preferred.
• Have experience of IT security related procedure, process, policy, regulation development, reviewing, and updating.
• Have good knowledge of Cyber security defense model of the bank.
• Have experience in software development lifecycle.
• Have good knowledge in the organization model of the bank.