The Role
Assesses information security controls, manages cybersecurity and third-party risks, oversees IAM initiatives, and maintains security policies compliant with ISO 27001, PCI-DSS, and regulations. Develops security awareness programs, reviews security-related IT requests, creates risk and performance dashboards, prepares reports, monitors vulnerability remediation, and supports cybersecurity enhancement projects.
Summary Generated by Built In
ACG_3763_JOB
Our client, a leading company in financial services sector in Vietnam, is looking for a qualified candidate to join their firm.
Job Purpose
Responsible for assessing the effectiveness of information security controls, developing and implementing appropriate security measures, and minimizing cybersecurity and information security risks. The role also supports the development and oversight of Identity & Access Management (IAM) initiatives while ensuring security controls remain compliant and effective.
Key Responsibilities
- Coordinate with Risk Management teams to implement the information security risk management framework, assess cybersecurity risks, manage third-party risks, and monitor remediation of security vulnerabilities.
- Develop, maintain, and implement information security policies, standards, and procedures in compliance with relevant regulations and international standards such as ISO 27001 and PCI-DSS.
- Plan and oversee the implementation of Identity & Access Management (IAM) programs across the organization.
- Develop and deliver information security awareness and training programs for employees.
- Review and approve IT service requests related to information security.
- Develop dashboards and security performance indicators, including KRI, SLA, RPO, and RTO, and prepare required regulatory or management reports.
- Support and guide security enhancement projects aimed at strengthening the organization’s cybersecurity capabilities.
Requirements
- Bachelor’s degree or higher in Information Technology, Information Security, Cryptography, Computer Science, System Administration, or a related field.
- At least 5 years of experience in Information Security within the Banking or Financial Services sector.
- Strong knowledge of international security standards such as ISO 27001 and PCI-DSS, as well as relevant regulatory requirements.
- At least 5 years of hands-on experience in one or more of the following areas: Identity & Access Management, Risk Management, Compliance Management, or Information Security program/project management.
- Good understanding of information security controls across networks, systems, applications, and identity management.
- Experience developing, reviewing, and updating information security policies and procedures.
- Understanding of the Software Development Life Cycle (SDLC).
- Good English communication and technical reading skills.
- Strong analytical, planning, stakeholder-management, and cross-functional coordination skills.
- Strong management reporting and presentation skills.
- Able to work independently and collaboratively in a high-pressure environment with a strong commitment to confidentiality and information security.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent.
- Project management certification such as PMP is an advantage.
Skills Required
- Bachelor’s degree or higher in Information Technology, Information Security, Cryptography, Computer Science, System Administration, or a related field
- At least 5 years of information security experience in the banking or financial services sector
- Strong knowledge of ISO 27001, PCI-DSS, and relevant regulatory requirements
- At least 5 years of hands-on experience in Identity and Access Management, Risk Management, Compliance Management, or Information Security program/project management
- Understanding of information security controls across networks, systems, applications, and identity management
- Experience developing, reviewing, and updating information security policies and procedures
- Understanding of the Software Development Life Cycle
- Good English communication and technical reading skills
- Strong analytical, planning, stakeholder-management, and cross-functional coordination skills
- Strong management reporting and presentation skills
- Ability to work independently and collaboratively in a high-pressure environment with strong confidentiality and information security commitment
- CISSP, CISM, CRISC, CISA, or equivalent certification
- PMP or another project management certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Aloha Consulting Group (ACG) is a consulting firm specializing in digital transformation, technology, marketing, investment, and financial services. Its mission is to make finding rewarding jobs easier and to be a leading firm in Southeast Asia by leveraging human elements and technology.






