Senior Information Security
Techcombank
Ho Chi Minh, Ho Chi Minh, Vietnam
4 ngày trước

The Job Holder :

  • Scope of activities to ensure security : Developing security solutions / Ensuring compliance with security standards (Vietnam and International)
  • Array of security testing activities : Perform attack and test activities for technology systems to detect vulnerabilities / weaknesses and provide quick and timely remedial solutions.
  • Array of security and security administration activities : Perform administrative activities on identity and access security / network security / terminal device and data security
  • Key Accountabilities (1)

    1. Scope of activities Ensuring Information Security

  • Participate in projects, developing and deploying technology to ensure Information Security for systems to be built, including stages : analysis, building requirements Information security, design Information security, threat modeling, source code review, testing and building controls to ensure Information Security.
  • Research and develop necessary information security solutions to prevent attacks and incidents Information security, ensure security and safety for the entire information system of the bank.
  • Coordinate with the Information Security supervisory department in handling information security incidents.
  • Set up and monitor the implementation of TCB's information security process, regulations, standards, guidelines and policies in accordance with the regulations of the government and international organizations
  • Implement and maintain compliance with international standards PCI-DSS, ISO, SWIFT CSP.
  • Implement and maintain compliance with TCB's policies, circulars and regulations of the State Bank.
  • Regularly perform compliance and integrity checks
  • of the security policy configuration in the internal system TCB detects violations or insider attacks.

  • Coordinate with Compliance Assessment and Risk Management units to assess the compliance of technology systems according to policies, regulations, standards, processes, checklists.
  • Key Accountabilities (2)

    2. Scope of activities Information Security Testing

  • Implement the strategy to ensure information security :
  • Participate in the implementation of the Information Security strategy by providing input data on attack trends, forms of exploitation and risks arising in each period.
  • Participate in the implementation of the annual information security implementation plan, meet the business and operational needs of the bank through the implementation of information security testing programs for the technology activities of the bank. Bank.
  • Develop penetration testing methods, information security scanning scripts and security checks according to international standards such as OSSTMM, Sans and OWASP.
  • Develop new techniques, exploit scripts and programs for automated penetration testing
  • Perform test attack activities :
  • Directly perform vulnerability detection review, vulnerability assessment, and conduct penetration / exploit testing periodically or at the request of the Block leader for all systems / applications ;
  • Penetration testing for system / application after live detection or whenever undergoing a major change. Testing methods must ensure practicality including both technical (technology) and non-technical (people, processes, physical assets).

    From there, provide CISO as well as other Information Security departments to have programs to deal with the problems of system weaknesses that can be exploited.

  • Perform regular vulnerability scans, information security checks to find vulnerabilities in the system and provide remedial / remedial solutions;
  • supports maintaining compliance with world security standards such as PCI-DSS, ISO27001, SCP (swift).

  • Develop and manage vulnerability management program, threat intelligence database. Collect, track metrics, and analyze trends on cyber defenses, threats, detected attacks, vulnerabilities, and countermeasures / preventions.
  • Actively research / find new vulnerabilities, exploitation techniques and cyber threats; Identify trends in cybersecurity involving tactics, techniques, and processes, targeting for malware development and deployment.
  • Directly participate in the experimental plan of responding to an Information Security incident as an attack unit and in the case of an actual Information Security incident as the response team.
  • Coordinate and provide expert cyber defense engineering skills to resolve cyber attack incidents

    Key Accountabilities (3)

    3. Scope of activities of Information Security Administration

  • Building / adjusting and implementing MTPQ of systems.
  • Develop requirements and measures to control access and protect the bank's data.
  • Develop, maintain and optimize information security policy / rule / configuration for solutions to ensure information security such as : Information security solutions on access identity management (PAM, IAM );
  • Network information security solutions (Firewall, NAC, APT, NetIPS, DDOS...); Information Security solutions on endpoints (AD GPO, HIPS / HFW, Appcontrol, Web / mail filtering, DB security );
  • Information security solutions on data (DLP, FAM...).

  • Assess, evaluate, review :
  • Decentralization enforcement ensures compliance with the decentralized matrix.
  • The issue and withdrawal of privileged accounts and digital certificates on technology systems.
  • Exception requirements related to identity, access rights on technology systems
  • Change requirements on information security assurance solutions.
  • Risk management and compliance
  • Identify risks of the department in the process of operation, ensuring compliance with the processes and regulations of the bank.
  • Coordinate with relevant units to handle risks.

  • Perform risk treatment activities according to reports of internal / external audit departments.
  • Báo cáo công việc này
    checkmark

    Thank you for reporting this job!

    Your feedback will help us improve the quality of our services.

    Nộp đơn
    Email của tôi
    Bằng cách nhấp vào "Tiếp tục", tôi đồng ý với neuvoo để xử lý dữ liệu của tôi và gửi cho tôi thông báo qua email, như được nêu chi tiết trong Chính sách bảo mật của neuvoo. Tôi có thể rút lại sự đồng ý của tôi hoặc hủy đăng ký bất cứ lúc nào.
    Tiếp tục
    Mẫu đăng ký