← Niteco Vietnam Co., Ltd
Senior IT Security Engineer
Niteco Vietnam Co., Ltd · Hà Nội
Apply on official site ↗
Type
Full-time
Work mode
On-site
Level
Staff
Industry
Engineering / Mechanical
Salary
Thương lượng
Location
Quận Đống Đa, Hà Nội, Hà Nội
Overview
- Own and operate the Security Operations Center function, including security monitoring, alert triage, incident response, remediation tracking and security automation.
- Operate and optimize Microsoft Defender security platforms, including Defender for Endpoint, Defender for Identity, Defender for Cloud and Defender for Office 365.
- Integrate security monitoring signals from infrastructure, applications, endpoints and observability tools such as Grafana, Prometheus or equivalent platforms.
- Define and maintain SOC policies, procedures, workflows, alert routing, ticketing integration and operational documentation.
- Act as Incident Owner or Incident Commander for security incidents, ensuring full traceability from alert, ticket, remediation, verification and evidence collection.
- Lead post-incident root cause analysis, lessons learned sessions and preventive action tracking until closure.
- Coordinate response to endpoint compromise, malware outbreaks, identity-based attacks, cloud misconfiguration incidents, data leakage and insider-threat scenarios.
- Collaborate with IT Operations on endpoint security, device compliance, software control, encryption compliance, patching and secure device configuration.
- Manage identity and access security using Microsoft Entra ID, MFA, Conditional Access, PIM, access reviews and least-privilege principles.
- Collaborate with PMO and IT Operations to standardize Joiner-Mover-Leaver access processes, approvals, audit logs and SLAs.
- Own the vulnerability management lifecycle across discovery, prioritization, remediation and verification for endpoints, servers, cloud workloads and applications.
- Coordinate with system owners, SA and Engineering teams to drive remediation, risk acceptance, exception management and secure CI/CD practices where applicable.
- Monitor network, perimeter and physical security signals, including firewall logs, access-door logs, server-area records and abnormal activities.
- Support firewall rule reviews, firmware updates, network health monitoring, backup verification and disaster recovery rehearsal activities in collaboration with IT Operations.
- Provide cloud and hybrid security consultation for Azure, AWS, Kubernetes, containers and related security configurations.
- Collaborate with relevant stakeholders in developing and implementing internal Information Security and AI usage policies, ensuring alignment with ISO 27001 controls for data protection, access control, and information classification.
- Support ISO 27001 audits by providing technical input, operational evidence, documentation and follow-up support for findings or penetration-test remediation.
- Leverage AI-driven capabilities in security platforms and build practical automation for alert triage, log analysis, evidence collection, security data processing and compliance reporting.
- Develop and maintain security automation scripts using NodeJS, Python, PowerShell or Bash, and integrate security tools through APIs where appropriate.
- Define and report SOC KPIs, security dashboards, incident trends, vulnerability exposure, compliance status and continuous improvement initiatives.
- Your Skills and Experience
- 5+ years of experience in Cybersecurity, Information Security, SOC, SecOps or IT security operations roles.
- 1-2+ years of experience leading SOC/SecOps functions or security operations within IT or managed services environments.
- Hands-on experience with Microsoft security ecosystem, especially Microsoft Defender for Endpoint, Defender for Identity, Defender for Cloud and Defender for Office 365.
- Strong knowledge of IAM and Microsoft Entra ID, including MFA, Conditional Access, access reviews, privileged access and least-privilege practices.
- Experience with vulnerability scanning, risk-based prioritization, remediation coordination and lifecycle management.
- Solid understanding of Azure and AWS cloud security; GCP experience is an advantage.
- Experience with observability or monitoring tools such as Grafana, Prometheus or equivalent platforms.
- Ability to develop scripts or automation using NodeJS, Python, PowerShell or Bash.
- Strong English communication skills with the ability to work with engineering teams, management, vendors and stakeholders.
- Process-driven mindset, clear documentation skills and good awareness of audit and compliance requirements.
- NICE TO HAVE
- Microsoft Sentinel SIEM experience.
- Microsoft Security certifications such as SC-200, SC-300 or SC-100.
- Professional security certifications such as CISSP, CISM or CISA.
- ISO 27001 Foundation, awareness certification or hands-on ISO 27001 compliance support experience.
- Cloud security certifications, preferably on Azure.
- Experience with SonarQube, CI/CD security gates, Infrastructure as Code security scanning or automated security testing frameworks.
- Why You'll Love Working Here
- Attractive salary with bi-yearly review, 13th-month bonus, performance bonus, public holiday bonuses, birthday gift, employee service awards up to $1,000
Benefits
BonusTraining
Summary of facts from the official posting. View original ↗
Interested in this role?
You'll be taken to the employer's official application page.
Apply on official site ↗
Is this your business?
Claim this page, request edits or removal
→