RESPONSIBILITIES
1. Responsible for implementing and reporting on information security management activities as assigned by the Director of Information Security Management, including:
- Building/adjusting and implementing the MTPQ of the systems.
- Building requirements and measures to control access and protect bank data.
- Building, maintaining, optimizing information security policies/rule sets/configurations for information security solutions such as: Information security solutions on access identity management (PAM, IAM…); Information security solutions on networks (Firewall, NAC, APT, NetIPS, DDOS…); Information security solutions on terminals (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security…); Information security solutions on data (DLP, FAM…).
- Assessing, evaluating, reviewing:
– Implementation of decentralization ensures compliance with the decentralization matrix.
– Issuance and revocation of privileged accounts and digital certificates on technology systems.
– Exception requests related to identification and access rights on technology systems.
– Requests for changes to security solutions.
2. Risk management and compliance:
- Identify risks of the department during operations, ensure compliance with the bank’s procedures and regulations. Coordinate with relevant units to handle risks.
- Implement risk handling activities according to reports from internal/external audit departments of the Bank.
REQUIREMENTS
- University degree in IT or telecommunications or related fields.
- Have experience in implementing, managing, operating in-depth policies, rules, and security configuration in at least one of the following areas at financial/service/telecommunications organizations (4-5 years):
– Security solutions for access management (PAM, IAM, etc.);
– Network security solutions (Firewall, NAC, APT, NetIPS, DDOS, etc.);
– Endpoint security solutions (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security, etc.);
– Data security solutions (DLP, FAM, etc.).
- Foreign language: Level 1 or higher – TOEIC below 550.
- Have security certificates from security solution providers such as Microsoft/ Cisco/ PaloAlto/ Checkpoint, etc.