Skip to content
Tuyển Dụng
← Công ty Cổ Phần Hạ Tầng Hàng Không Masterise

Senior GRC Specialist (Cyber Security)

Công ty Cổ Phần Hạ Tầng Hàng Không Masterise · Hà Nội
Apply on official site ↗
Type
Full-time
Work mode
On-site
Level
Staff
Industry
Other
Salary
Thương lượng
Location
Hà Nội, Hà Nội, Hà Nội

Overview

  • As a Senior GRC Specialist, you are responsible for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).
  • Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.
  • Role impact: Your work gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.
  • Governance, Framework & Policy Management (40%)
  • Own the cyber security policy, standard and procedure framework (ISO 27001, IEC 62443 etc)
  • Operate the ISMS (ISO 27001) full life cycle: scope, risk methodology, SoA, risk treatment plan, internal audit, management review
  • Run the exception and waiver process with compensating controls, risk acceptance and expiry dates
  • Risk Management & Third-Party Assurance (30%)
  • Maintain the enterprise cyber risk register with scoring, treatment plans and named owners
  • Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems
  • Determine system security levels under Decree 85/2016 and prepare approval dossiers
  • Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal
  • Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms
  • Track audit, assessment and penetration test findings to closure against severity-based SLAs
  • Compliance, Audit & Reporting (30%)
  • Coordinate internal audits, external audits, certification assessments and regulator inspections
  • Report KRIs, KPIs and security posture to the Steering Committee and executive leadership
  • Govern security awareness and the phishing simulation programme, including remediation tracking

Summary of facts from the official posting. View original ↗

Interested in this role?

You'll be taken to the employer's official application page.

Apply on official site ↗
Is this your business? Claim this page, request edits or removal