**Working Location:**
- Hanoi: TechnoPark Tower, Vinhomes Ocean Park, Gia Lam, Hanoi
- Ho Chi Minh City: Vincom Dong Khoi, Ho Chi Minh City
**Job Overview**
The Chief Information Security Officer (CISO) holds the highest accountability for Governance, Risk \& Compliance (GRC), Cyber Risk, and information security governance across the Company — ensuring regulatory compliance and protecting systems, data, transactions, and organizational resilience against cyber incidents.
The CISO serves as the primary advisor to the CEO, Board of Management, and Board of Directors on information security matters, while working closely with VinSOC — the Group's dedicated Security Operations unit — to deploy and operate the organization's cyber defense capabilities.
**Key Responsibilities**
***1\. GRC \& Cyber Risk***
- Develop the information security strategy, security roadmap, policies, and Risk Appetite for the Company.
- Identify, assess, and monitor cyber risks across the organization.
- Report regularly and on an ad\-hoc basis on cyber risk posture to the Board of Management and Board of Directors.
***2\. Compliance \& Audit***
- Ensure the Company's compliance with applicable laws and Fintech/Payment industry standards related to information security.
- Manage audit activities and security assessments, and track remediation progress.
- Build, maintain, and continuously improve the information security governance framework in line with international standards such as ISO 27001, PCI DSS, and NIST CSF.
***3\. Security Operations***
- Serve as the primary point of coordination with VinSOC for security monitoring, detection, and incident response.
- Govern and evaluate the operational effectiveness of the SOC, along with SIEM/SOAR and EDR/XDR capabilities.
***4\. Security Governance***
- Direct and oversee the Company's overall security architecture.
- Govern IAM/PAM capabilities, as well as Cloud, Application, API, and Data Security.
- Oversee the implementation of DevSecOps practices and the Vulnerability Management program.
***5\. Cyber Resilience***
- Lead Incident/Crisis Management for major cybersecurity incidents.
- Develop and maintain Business Continuity Plans/Disaster Recovery (BCP/DR), and organize periodic Cyber Drills.
***6\. Third\-party Risk***
- Manage information security risk related to Cloud/SaaS providers, banking partners, Fintech Partners, and Merchants.
- Establish processes to assess and monitor third\-party information security risk throughout the partnership lifecycle.
***7\. Security Capability, KPI \& Budget Management***
- Build the KPI framework, budget, and information security governance capabilities for the Company.
**Qualifications**
*Required*
- 12–15\+ years of experience in Cybersecurity/Information Security/Technology Risk; at least 5 years in a senior management role.
- Strong foundation in GRC, Cyber Risk \& Compliance; experience building enterprise\-level information security governance frameworks.
- Deep understanding of Security Operations/SOC \& Incident Response; able to govern and evaluate the performance of a dedicated security operations unit.
- Strong knowledge of Security Architecture, Cloud/Application/API Security, IAM/PAM, Data Security, DevSecOps, and BCP/DR.
- Experience in Banking, E\-wallet, Fintech, Payment, or large\-scale, 24/7 technology operations preferred.
- Able to work directly with the CEO/Board of Directors, regulators, auditors, and partners; able to balance Risk – Compliance – Security – Business priorities.
- One or more professional certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001 Lead Auditor/Implementer.
**Apply Via:**
For more information, please contact the Talent Acquisition Department — VinSmartFuture