Apply Edge Start your job search

Senior Leader – Chief Information Security Officer (CISO), Group Member Company

Vingroup JSC · Hanoi, Hanoi, Vietnam

Apply & track with Apply Edge

1. Position ObjectiveThe CISO is responsible for developing and operating the company-wide Information Security and Cybersecurity strategy, protecting systems, customer data, transactions and digital assets, while ensuring regulatory compliance, effective cyber risk management and organizational resilience against security incidents.The CISO serves as a strategic advisor to the CEO, Executive Management and Board of Directors on cybersecurity risks and ensures that security supports business growth in a safe and sustainable manner.2. Key ResponsibilitiesStrategy & GovernanceDevelop the Cybersecurity Strategy, Security Roadmap, information security policies and standards.Establish the cybersecurity governance model, Risk Appetite and cyber risk reporting framework for Executive Management and the Board of Directors.Manage the cybersecurity budget.Cyber Risk & ComplianceManage risks related to technology, applications, Cloud, data, third parties and new products.Ensure compliance with applicable laws, regulations and standards for e-wallet/Fintech operations.Manage security audits, security assessments/testing and remediation activities.Apply appropriate frameworks such as ISO 27001, PCI DSS, NIST CSF, CIS Controls and OWASP.Security Architecture & EngineeringDevelop Security Architecture based on Security by Design, Privacy by Design and Zero Trust principles.Govern IAM/PAM, Network Security, Cloud Security, API Security, Mobile Security, Data Security, Encryption and Key Management.Ensure that critical systems and payment infrastructure are designed and operated securely.Application Security & DevSecOpsIntegrate security throughout the Software Development Life Cycle (SDLC).Implement Secure Coding, Threat Modeling, SAST/DAST/SCA, Penetration Testing and Vulnerability Management.Partner with Engineering teams to establish and continuously improve the DevSecOps model.Security Operations & Incident ResponseCoordinate with VinSOC on cybersecurity operations.Oversee SOC and Security Monitoring, including SIEM/SOAR, EDR/XDR, Threat Intelligence and Threat Hunting capabilities.Establish and operate Incident Response and Cyber Crisis Management capabilities.Monitor and respond to risks including Account Takeover, Credential Stuffing, API Abuse, Data Exfiltration and Insider Threats.Conduct regular Cyber Drills, Tabletop Exercises and Red/Blue Team exercises.Data, Identity & Payment SecurityProtect customer data through Data Classification, Encryption, Tokenization, DLP and Access Governance.Ensure Least Privilege, MFA, PAM and regular Access Reviews.Secure Wallet, Payment Gateway, QR, Card, P2P, Cash-in/Cash-out and API integrations with banks and partners.Work closely with Fraud and Risk teams to reduce Payment Fraud and Account Takeover risks.Third-Party SecurityEstablish a cybersecurity risk assessment and management program covering Cloud/SaaS providers, Fintech partners, Merchants and technology vendors.Define security requirements for vendor onboarding, contracts and SLAs.3. Key KPIsCritical/High Cyber Risks and remediation rate within agreed SLA.MTTD, MTTR, MTTC and number of Major Security Incidents.Vulnerability Remediation Time.Security Monitoring and Detection Coverage.Secure SDLC / Application Security Coverage.MFA/PAM Coverage.Third-Party Security Assessment Coverage.Audit Findings and Closure Rate.Security Awareness and Phishing Simulation Results.Compliance with applicable laws and regulations.5. Candidate Requirements12–15+ years of experience in Cybersecurity, Information Security or Technology Risk.5+ years of senior management experience.Experience in Banking, E-wallet, Fintech, Payment or large-scale technology platforms is preferred.Experience with 24/7 systems, high-volume transactions, Cloud, Microservices and API ecosystems.Proven experience handling major cybersecurity incidents and building enterprise-scale security programs.Deep Expertise in:Cybersecurity Governance & Risk.Security Architecture.Cloud/Application/API/Mobile Security.SOC & Incident Response.IAM/PAM.Data & Payment Security.DevSecOps.Business Continuity & Disaster Recovery.Preferred certifications: CISSP, CISM, CISA, CRISC, CCSP, GIAC, OSCP, ISO 27001 Lead Auditor/Implementer.6. Leadership CompetenciesStrategic thinking, risk management and compliance governance.Strong understanding of the Fintech/Payment business model.Ability to balance Security – Customer Experience – Speed – Cost – Growth.Strong communication and stakeholder management skills with CEO, Board of Directors, regulators and business partners.Proven ability to lead effectively during cybersecurity crises and high-pressure situations.Ability to build, lead and develop a high-performing Cybersecurity organization.