The Chief Information Security Officer (CISO) \- Fintech Product, based within VinSmart Future (VSF), is responsible for defining and leading the enterprise\-wide cybersecurity strategy, governance, risk management, compliance, and resilience agenda. The role ensures the protection of critical platforms, customer data, financial transactions, and digital assets while maintaining compliance with applicable regulatory and industry requirements.
As a trusted advisor to the CEO, Executive Leadership Team, and Board of Directors, the CISO provides strategic oversight of cybersecurity risks and business resilience. The role works in close partnership with VinSOC as the Group's cybersecurity center of excellence, leveraging shared security capabilities while ensuring that VSF's business, technology, and regulatory security requirements are effectively addressed.
**Key Responsibilities**
- GRC \& Cyber Risk: Define cybersecurity strategy, roadmap, policies and Risk Appetite; identify, assess and report cyber risks to Executive Management and the Board.
- Compliance \& Audit: Ensure compliance with applicable Fintech/Payment regulations and standards; oversee audits, security assessments and remediation. Strong knowledge of ISO 27001, PCI DSS and NIST CSF.
- Security Operations \& VinSOC: Partner with VinSOC to oversee security monitoring, detection and incident response capabilities, including SOC, SIEM/SOAR, EDR/XDR, Threat Intelligence and Threat Hunting.
- Security Governance: Govern Security Architecture, IAM/PAM, Cloud, Application/API and Data Security, DevSecOps and Vulnerability Management.
- Cyber Resilience: Lead Cyber Crisis Management, BCP/DR and cyber exercises; coordinate with VinSOC on major cybersecurity incidents.
- Third\-party Risk: Govern cybersecurity risks across Cloud/SaaS providers, banks, Fintech partners, merchants and technology vendors.
- Establish cybersecurity KPIs, budget and governance mechanisms, ensuring internal teams and VinSOC operate against agreed risk, SLA and performance requirements.
**Requirements**
- Bachelor's degree or equivalent experience in Information Technology.
- 12–15\+ years of experience in Cybersecurity, Information Security or Technology Risk, including 5\+ years in senior leadership roles.
- Strong expertise in GRC, Cyber Risk Management and Compliance, with proven experience building enterprise security governance frameworks.
- Strong understanding of Security Operations, SOC and Incident Response, with the ability to govern and challenge specialized cybersecurity functions.
- Solid knowledge of Security Architecture, Cloud/Application/API Security, IAM/PAM, Data Security, DevSecOps and BCP/DR.
- Experience in Banking, E\-wallet, Fintech, Payments or large\-scale, 24/7 technology environments is highly preferred.
- Ability to engage effectively with CEO/Board, regulators, auditors and strategic partners, balancing Risk, Compliance, Security and Business Growth.
- Certifications such as CISSP, CISM, CISA, CRISC, CCSP or ISO 27001 Lead Auditor/Implementer are preferred.