Develop strategies and lead Threat Hunting, Threat Intelligence, Exposure Management, and Incident Response activities across the entire Vingroup ecosystem.
Direct Threat Hunting and Threat Intelligence activities, proactively detect abnormal behaviors, track attack actors/campaigns, and turn results into detection and defense capabilities.
Manage Attack Surface and Security Exposure, identify, assess, and prioritize remediation of exposure points; collaborate with the Red Team to simulate attacks to validate control effectiveness.
Act as Incident Commander for serious incidents; coordinate containment, eradication, recovery, and crisis management across multiple member units.
Build and maintain Digital Forensics \& Malware Analysis capabilities to support investigations, determine causes, and reconstruct attack chains on Endpoints, Network, and Cloud.
Build, drill, and continuously improve the Incident Response Playbook for critical scenarios like Ransomware, Supply Chain Attacks, Credential Compromise, and Data Breaches.
Lead Post\-Incident Reviews, making sure lessons learned are turned into fixes and improvements in detection/defense capabilities.
Guide the use of AI and Automation in Threat Hunting, analysis, investigation, and incident response.
Develop and grow the team’s expertise and readiness for 24/7 incident response.
**Requirements**
University graduate in Cybersecurity, IT, or related fields.
At least 10 years of experience in Cybersecurity, including 4 years leading UPSC, Digital Forensics, Threat Hunting, or equivalent teams.
Direct experience handling and managing serious cybersecurity incidents, especially those affecting business operations.
Strong expertise in Incident Response, Threat Hunting, Digital Forensics, and Threat Intelligence; good understanding and application of the NIST Incident Response Framework and MITRE ATT\&CK.
Experience investigating on Endpoint, Network, and Cloud, analyzing logs, and reconstructing attack timelines; knowledge of Malware Analysis.
Knowledge or experience in Exposure Management, Attack Surface Management, and Attack Simulation.
Understanding of AI/ML applications and Automation in analysis, investigation, and incident response.
Ability to make decisions in crisis situations, coordinate multiple parties, and report/discuss with senior leadership.
Priority given to certificates: CISSP, CISM, GCIA, GCDA, GDAT, CompTIA CySA\+, Splunk, or equivalent.
**Preferred Qualifications**
Experience in Incident Response or Digital Forensics in OT/ICS environments.
Experience in investigating and responding to incidents in Multi\-Cloud environments.
Experience building Threat Hunting or Exposure Management Programs from the ground up.
Experience handling Ransomware, Data Breach, or large\-scale incidents.
Experience coordinating with regulatory agencies/authorities during cybersecurity incident handling.
**Why Join Us?**
Opportunity to work on high\-impact security transformation programs across a major ecosystem.
Exposure to large\-scale enterprise technology modernization.
Join cutting\-edge AI for Security product initiatives.
Work with top engineering and security talent in Vietnam.
Competitive compensation and strong career growth opportunities.