← Công ty Cổ Phần Hạ Tầng Hàng Không Masterise
Senior GRC Specialist (Cyber Security)
Công ty Cổ Phần Hạ Tầng Hàng Không Masterise · Hà Nội
Ứng tuyển tại trang chính thức ↗
Loại hình
Toàn thời gian
Hình thức
Tại văn phòng
Cấp bậc
Nhân viên
Ngành nghề
Ngành nghề khác
Mức lương
Thương lượng
Địa điểm
Hà Nội, Hà Nội, Hà Nội
Tổng quan
- As a Senior GRC Specialist, you are responsible for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).
- Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.
- Role impact: Your work gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.
- Governance, Framework & Policy Management (40%)
- Own the cyber security policy, standard and procedure framework (ISO 27001, IEC 62443 etc)
- Operate the ISMS (ISO 27001) full life cycle: scope, risk methodology, SoA, risk treatment plan, internal audit, management review
- Run the exception and waiver process with compensating controls, risk acceptance and expiry dates
- Risk Management & Third-Party Assurance (30%)
- Maintain the enterprise cyber risk register with scoring, treatment plans and named owners
- Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems
- Determine system security levels under Decree 85/2016 and prepare approval dossiers
- Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal
- Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms
- Track audit, assessment and penetration test findings to closure against severity-based SLAs
- Compliance, Audit & Reporting (30%)
- Coordinate internal audits, external audits, certification assessments and regulator inspections
- Report KRIs, KPIs and security posture to the Steering Committee and executive leadership
- Govern security awareness and the phishing simulation programme, including remediation tracking
Tóm tắt thông tin từ tin tuyển dụng chính thức. Xem bản gốc ↗
Quan tâm đến vị trí này?
Bạn sẽ được chuyển đến trang ứng tuyển chính thức của nhà tuyển dụng.
Ứng tuyển tại trang chính thức ↗
Đây là doanh nghiệp của bạn?
Nhận quản lý trang, yêu cầu chỉnh sửa hoặc gỡ bỏ
→