Security Information Consultant

7 days ago


Hanoi, Vietnam Talentnet Full time

$1,800 - $1,800
- Hi-Tech & IT

**RESPONSIBILITIES**:
**Typical Responsibilities**
- Extensive Information/Cyber Security consultancy experience facing security delivery expertise
- A deep knowledge in at least two of the following: PCI-DSS, ISO27001 (Information Security), Information Assurance, Security Policy, GRC, NIST, GDPR or Data Privacy.

**Preliminary Analysis**
- Identifying all the stakeholders (e.g., IT Project Manager, System admins and Management) of the client to define the pre-requisite and methodology.
- Work with key stakeholders to translate regulatory requirements and standards into policies, processes, and controls.

**Gap Analysis and Scoping**
- Assess changes to regulatory requirements and standards and determine the impact on internal policies, controls, and processes. Make recommendations for associated changes to policies, controls, and processes, and simplify implementation.
- Review of all locations and flows of cardholder data, as well as asset inventories.
- Conducting PCI standards interviews to have a complete map of information/data workflows, processes, and procedures, payment card data flow, information security controls.
- Conducting technical interviews to understand eventual data security problems from the in-depth technical point of view.
- Identify and evaluate technology risks, internal controls to mitigate risks, and related opportunities for continuous control improvement. Facilitate and document risk assessments and communicate key findings
- Producing Scoping and Gap Analysis Documentation.

**Remediation**
- Providing the customer with a remediation plan/gap report.
- Evaluate the implementation of new technologies/processes and agreements with third-party service providers to ensure continual compliance with regulatory requirements.
- Drive audit readiness and provide support for Payment Card Industry Data Security Standard (PCI DSS) assessments, Customer Security and Privacy audits.
- Guiding and supporting all the remediation processes ensuring that the gaps are mitigated correctly.
- Should have experience working with security and technology teams for the annual PCI DSS assessment and monitor the progress. Few follow-up activities are mentioned below.
- VA/PT Testing (Network and Application level both)
- Anti-virus and Malware
- Configuration Management
- File Integrity Monitoring
- Multi-Factor Authentication
- Encryption and Key Management

**Formal Assessment**
- Conducting technical interviews to understand eventual data security problems from the in-depth technical point of view.
- Analysis of network diagrams, asset lists to understand the infrastructure used by the customers.
- Analysis of system configuration, Encryption, Key management.
- Customer Contract reviews and negotiations regarding data protection clauses, related regulations, and compliance commitments.

**Documentation**
- Preparation, validation, of ROC (Reports on Compliance) and AOC (attestation of compliance).
- Preparation of GAP assessment, health check assessment report.

**REQUI**REMENTS**:
**Experience & Education**
- Undergraduate degree in Information Management, Computer Science, Engineering, or emphasis in technology or related field.
- 3+ years of information security experience and/or IT audit / IT security or IT security infrastructure experience.
- Previous experience working as a PCI QSA is mandatory.
- Experience interpreting industry and regulatory requirements and authoring supporting controls.
- Experience with information security-related frameworks (ISO 27001, COSO, Cloud Security Alliance).

**Skills**
- Certifications like CEH, CISA, CISM, CISSP, ISO 27001 LA/LI (any of these).
- Experience in technical skills like Virtualization, Cloud technologies, Cryptography principles, Authentication methods and techniques, Integrity controls, Networking (routing, switching, firewall network filtering), Operating Systems (Linux/Unix, Windows).
- Ability to work with teams to achieve goals and meet deadlines in a fast-paced environment.
- Works well under pressure and time constraints and can prioritize competing priorities appropriately.
- Demonstrable understanding of how to network and develop working relationships with various key stakeholders.
- Strong analytical, research, writing, and communication skills.
- Communicates effectively with meaningful and articulate verbal discussions. Creates clear and coherent written materials. Synthesizes information into succinct, concise and logical summaries and reports.
- Excellent interpersonal skills.
- Strong business and technical acumen.

**Competencies**
- Problem Solving (analysis, helicopter view, problem setting, decision making)
- Planning and Organization (time management, scheduling, and control)
- Communication (clearness, listening, persuasion)
- Networking (reinforce relationships, use emotional intelligence and personal proximity)

**For more information, please contact**:

- Ms. Nguyen Thi Hoai (84) 24 3936 76



  • Hanoi, Vietnam Talentnet Full time

    Hi-Tech & IT **RESPONSIBILITIES**: **Typical Responsibilities** - Extensive Information/Cyber Security consultancy experience facing security delivery expertise - A deep knowledge in at least two of the following: PCI-DSS, ISO27001 (Information Security), Information Assurance, Security Policy, GRC, NIST, GDPR or Data Privacy. **Preliminary Analysis** -...


  • Hanoi, Vietnam CÔNG TY CỔ PHẦN VINSCHOOL Full time

    **Mô tả công việc**: (Mức lương: Thỏa thuận) The Information Security Director is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. The DIRECTOR will lead the Information Security function, working closely with other senior...


  • Hanoi, Vietnam Talentnet Full time

    **RESPONSIBILITIES**: **Cloud Cybersecurity risk and compliance framework and management**: - Accountable for development of the Cloud Security Design framework for new technology solutions - Responsible for embedding best practice security through evaluation of suppliers - Responsible for establishing security requirements needed to provide services...


  • Hanoi, Vietnam Talentnet Full time

    Hi-Tech & IT **RESPONSIBILITIES**: - Planning/studying/designing and implementing clould strategy/solution/architect on multi cloud - Analyze/Developing prerequisites for cloud - Practice with modern DevSecOps with automation (nice to have) Ability to automate repetitive tasks (scripting skills in Bash/PowerShell/ Python) - Researching and implementing the...


  • Hanoi, Vietnam Talentnet Full time

    $2,100 - $3,500 - Hi-Tech & IT **RESPONSIBILITIES**: - Planning/studying/designing and implementing clould strategy/solution/architect on multi cloud - Analyze/Developing prerequisites for cloud - Practice with modern DevSecOps with automation (nice to have) Ability to automate repetitive tasks (scripting skills in Bash/PowerShell/ Python) - Researching...

  • Security Consultant

    1 week ago


    Hanoi, Vietnam FPT Software Full time

    FPT Software *** - FPT Cau Giay Building, Cau Giay, Ha Noi- F-Town 3, 3 Võ Chí Công, Phường Long Thạnh Mỹ, Thu Duc City, Ho Chi Minh- Tòa nhà FPT Complex, Đường Nam Kỳ Khởi Nghĩa, Phường Hòa Hải, Ngu Hanh Son, Da Nang- At office- Posted 7 hours ago- Skills: - Cloud AWS Azure **Top 3 reasons to join us**: - Global Exposure -...

  • Senior Clerk or Above

    3 weeks ago


    Hanoi, Vietnam Talentnet Full time

    **RESPONSIBILITIES**: - Execute functions and tasks of the IT Security & Risk Management Team - Design and implement security infrastructure. - Implement and manage security solutions. - Perform periodic risk analysis, vulnerability scanning and testing. - Implement and maintain security policies and procedures in line with local regulations, Head Office...


  • Hanoi, Vietnam Talentnet Full time

    $6,000 - $6,000 **RESPONSIBILITIES**: - Execute functions and tasks of the IT Security & Risk Management Team - Design and implement security infrastructure. - Implement and manage security solutions. - Perform periodic risk analysis, vulnerability scanning and testing. - Implement and maintain security policies and procedures in line with local...


  • Hanoi, Vietnam Grant Thornton Full time

    **Information Security Governance, Risk and Compliance**: Grant Thornton - Ứng Tuyển System Engineer Database Networking - Đăng nhập để xem mức lương - 18th Floor, Hoa Binh International Office Building 106 Hoang Quoc Viet Street, Cau Giay, Ha Noi- Xem bản đồ- Linh hoạt- 3 giờ trước **3 Lý Do Để Gia Nhập Công Ty**: -...


  • Hanoi, Vietnam Công Ty Cổ Phần Đầu Tư TNG Holdings Việt Nam Full time

    **Mô tả công việc**: (Mức lương: Thỏa thuận) 1. Advise and consult the Board of Directors and develop strategies, policies, and security tools: - Develop strategies and operational plans related to information security and safety system administration - Develop security policies for the system and monitor policy implementation at units -...

  • Information Security

    3 weeks ago


    Hanoi, Vietnam ABBANK Full time

    **Information Security**: ABBANK - Ứng Tuyển Database English System Admin - Đăng nhập để xem mức lương - 36 Hoàng Cầu, Dong Da, Ha Noi- Xem bản đồ- Tại văn phòng- 5 giờ trước **3 Lý Do Để Gia Nhập Công Ty**: - Lương/ thưởng hấp dẫn - Cơ hội thăng tiến nghề nghiệp cao - Môi trường làm việc...


  • Hanoi, Vietnam EBSCO Information Services Full time

    EBSCO International is the international operations group of EBSCO Information Services (EIS). EIS provides a complete and optimized research solution comprised of e-journals, e-books, and research databases - all combined with the most powerful discovery service to support the information needs and maximize the research experience of our end-users....


  • Hanoi, Vietnam CyStack Security Full time

    CyStack's solutions focus on data protection, cyber attack prevention, and security risk management in the enterprise which won prestigious awards in the cybersecurity industry. Our researchers are regular speakers at world-known cyber security conferences and also talented bug hunters who discovered many critical vulnerabilities in the products and are...

  • Frontend Engineer

    2 days ago


    Hanoi, Vietnam CyStack Security Full time

    CyStack's solutions focus on data protection, cyber attack prevention, and security risk management in the enterprise which won prestigious awards in the cybersecurity industry. Our researchers are regular speakers at world-known cyber security conferences and also talented bug hunters who discovered many critical vulnerabilities in the products and are...

  • Marketing Manager

    7 days ago


    Hanoi, Vietnam CyStack Security Full time

    CyStack's solutions focus on data protection, cyber attack prevention, and security risk management in the enterprise which won prestigious awards in the cybersecurity industry. Our researchers are regular speakers at world-known cyber security conferences and also talented bug hunters who discovered many critical vulnerabilities in the products and are...


  • Hanoi, Vietnam CyStack Security Full time

    CyStack's solutions focus on data protection, cyber attack prevention, and security risk management in the enterprise which won prestigious awards in the cybersecurity industry. Our researchers are regular speakers at world-known cyber security conferences and also talented bug hunters who discovered many critical vulnerabilities in the products and are...

  • Data Protection

    7 days ago


    Hanoi, Vietnam Talentnet Full time

    $3,000 - $3,000 - Financial Services **RESPONSIBILITIES**: **PMO of PDPD implementation project** - Lead the project working team for the task implementation and delivery of the deliverables successfully - Cooperate with K.Phan, legal & compliance, and HQ Data Governance & DPO (Pinhatai) for the project planning and PDPD implementation requirements and...


  • Hanoi, Vietnam Techcombank Full time

    Techcombank *** - C5 Building Tower, D’Capitale Tower, 119 Tran Duy Hung, Cau Giay, Ha Noi- Số 23 Lê Duẩn, phường Bến Nghé, District 1, Ho Chi Minh- At office- Posted 44 minutes ago- Skills: - Security Software Architect Solution Architect **Top 3 reasons to join us**: - Top-tier banking environment in Vietnam - Challenging opportunities...


  • Hanoi, Vietnam CyStack Security Full time

    CyStack's solutions focus on data protection, cyber attack prevention, and security risk management in the enterprise which won prestigious awards in the cybersecurity industry. Our researchers are regular speakers at world-known cyber security conferences and also talented bug hunters who discovered many critical vulnerabilities in the products and are...


  • Hanoi, Vietnam CyStack Security Full time

    CyStack's solutions focus on data protection, cyber attack prevention, and security risk management in the enterprise which won prestigious awards in the cybersecurity industry. Our researchers are regular speakers at world-known cyber security conferences and also talented bug hunters who discovered many critical vulnerabilities in the products and are...