← Công ty Cổ Phần Hạ Tầng Hàng Không Masterise
Senior GRC Specialist (Cyber Security)
Công ty Cổ Phần Hạ Tầng Hàng Không Masterise · Hà Nội
Apply on official site ↗
Type
Full-time
Work mode
On-site
Level
Staff
Industry
Other
Salary
Thương lượng
Location
Hà Nội, Hà Nội, Hà Nội
Overview
- As a Senior GRC Specialist, you are responsible for translating regulatory obligation and enterprise risk appetite into a working, auditable control environment across enterprise IT, cloud, and operational technology (OT).
- Your mission is to make compliance a by-product of well-run operations rather than a periodic scramble: one rationalised control library mapped to ISO/IEC 27001, IEC 62443, Decree 85/2016/ND-CP, Decree 53/2022/ND-CP and PDPD/PDPL, evidenced continuously, and reported transparently to leadership and regulators.
- Role impact: Your work gives airlines and partners assurance they can verify, and directly reduces the likelihood and impact of incidents affecting passenger safety, passenger data, and operational continuity.
- Governance, Framework & Policy Management (40%)
- Own the cyber security policy, standard and procedure framework (ISO 27001, IEC 62443 etc)
- Operate the ISMS (ISO 27001) full life cycle: scope, risk methodology, SoA, risk treatment plan, internal audit, management review
- Run the exception and waiver process with compensating controls, risk acceptance and expiry dates
- Risk Management & Third-Party Assurance (30%)
- Maintain the enterprise cyber risk register with scoring, treatment plans and named owners
- Facilitate risk assessments for new IT, cloud, OT, biometric and passenger data systems
- Determine system security levels under Decree 85/2016 and prepare approval dossiers
- Conduct DPIAs and cross-border transfer dossiers under PDPD/PDPL together with Legal
- Own vendor risk: tiering, due diligence and ISO 27001 review, contractual security terms
- Track audit, assessment and penetration test findings to closure against severity-based SLAs
- Compliance, Audit & Reporting (30%)
- Coordinate internal audits, external audits, certification assessments and regulator inspections
- Report KRIs, KPIs and security posture to the Steering Committee and executive leadership
- Govern security awareness and the phishing simulation programme, including remediation tracking
Summary of facts from the official posting. View original ↗
Interested in this role?
You'll be taken to the employer's official application page.
Apply on official site ↗
Is this your business?
Claim this page, request edits or removal
→