Senior Cyber Security Specialist
Zimaw LLC · Da Nang City, Vietnam
Apply & track with Apply EdgeWe are looking for a senior cybersecurity professional to take technical ownership of the Endpoint Vulnerability Management area. This is not an operational patching role. The client wants someone with broad, holistic cybersecurity expertise who understands how vulnerabilities turn into business risk. That person should be able to shape strategy, architecture and governance, and then turn them into products that measurably reduce exposure across the organization.Who you areYou are a senior cybersecurity professional with a broad foundation. You have worked across several security domains and see vulnerability management as part of a bigger picture that includes threats, architecture, identity, cryptography, incident response and governance. You combine technical depth with the ability to think strategically and communicate risk to management.Your main areas of responsibility:Risk-based vulnerability management. Define how vulnerabilities are classified and prioritized, combining threat intelligence, exploitability, asset criticality and business impact. Focus remediation on what actually reduces risk, especially for business-critical assets.Coverage across the full digital ecosystem. Ensure visibility across on-prem data centers, end-user devices, Azure/AWS/GCP, remote and mobile devices, and factory/OT environments. Make informed trade-offs where resources are limited.Security architecture and technology strategy. Hold holistic responsibility for tool selection, configuration and effectiveness. Lead the move to an updated monitoring architecture and tech stack, and assess new technologies and suppliers from a security perspective.Root cause and systematic improvement. Go beyond individual findings to find root causes and structural weaknesses in configuration, processes and architecture. Drive long-term improvements together with IT, application and infrastructure teams.Governance and compliance. Take an active part in developing, refining and maintaining the vulnerability management governance framework, and align it with the client's cybersecurity strategy and relevant frameworks and regulations.Reporting at every level. Build executive dashboards, KPIs and risk reports that give leadership clear visibility, while also giving operational teams actionable detail down to individual assets.Threat awareness and enablement. Translate critical vulnerabilities and emerging threats into guidance, playbooks (including for factory and OT contexts) and training for stakeholders.Product development. Work with Product Management on new and improved product concepts, proofs of concept, feasibility assessments, and management of dependencies and risks.Required experience and competenceMany years of experience in cybersecurity, with a broad background from roles such as security engineer, security architect, information security officer or security consultantSolid experience in vulnerability assessment and risk-based vulnerability management in large, complex enterprise environmentsUnderstanding of the attacker's perspective, for example through penetration testing, security testing, threat analysis (e.g. TARA) or incident response and forensicsKnowledge of security frameworks and standards such as ISO 27001, CIS Controls, NIST and ISA/IEC 62443, and the ability to apply them in practiceExperience with endpoint security and vulnerability technologies such as Qualys, Tenable or Microsoft Defender for Endpoint, and an understanding of how they are architected, integrated and optimized, including their dependency on asset management dataUnderstanding of modern hybrid environments, with segmented on-prem networks, multi-cloud (Azure/AWS), identity and Zero Trust principlesProven ability to build risk reporting, dashboards and KPIs tailored to executives, stakeholders and operational teamsExperience acting as a technical leader or subject matter expert, including mentoring colleagues and guiding stakeholdersExcellent communication skills in English, including the ability to explain complex technical risks in business termsMeritoriousExperience from manufacturing, industrial or OT security environmentsSecurity certifications such as CISSP, CISA, CISM, CRISC, OSCP, CEH or ISO 27001 Lead Implementer/AuditorExperience with SIEM, SOC operations or threat intelligence integrationKnowledge of PKI, cryptography or application securityExperience working in agile product teamsScripting/automation (e.g. Python, PowerShell)Patch management and remediation coordination