← NICE Credit Information Co., Ltd
Information Security Manager
NICE Credit Information Co., Ltd · Hà Nội
Ứng tuyển tại trang chính thức ↗
Loại hình
Toàn thời gian
Hình thức
Tại văn phòng
Cấp bậc
Trưởng / Phó phòng
Ngành nghề
Ngành nghề khác
Mức lương
Thương lượng
Địa điểm
Hà Nội, Hà Nội, Hà Nội
Tổng quan
- Develop Information Security Policies, Standards, and Regulations
- Participate in the development, review, and update of the information security (IS) and personal data protection strategies, policies, procedures, standards, and guidelines.
- Monitor and analyze domestic and international regulations, standards, and best practices relating to information security, cybersecurity, and personal data protection, and recommend appropriate adoption across the NCI.
- Translate regulatory (e.g., Law on Cybersecurity 2025, Decree 85/2016/NĐ-CP, Circular 12/2022/TT-BTTTT, Circular 09/2020/TT-NHNN), governance, and technical requirements into internal policies, control requirements, implementation guidelines, and operational standards.
- Monitor Information Security Compliance
- Plan and participate in information security compliance reviews, audits, and assessments, such as information security assessments and information security risk assessments, personal data protection compliance assessments.
- Track and follow up on the remediation of identified non-conformities, security vulnerabilities, compliance gaps, and information security risks.
- Prepare compliance reports, risk alerts, and recommendations to strengthen information security governance.
- Coordinate the implementation of, and ensure the protection of, data subjects' rights.
- Coordinate the preparation and updating of Personal Data Processing Impact Assessment (DPIA) dossiers and Cross-Border Personal Data Transfer Impact Assessment (CDTIA) dossiers.
- Information Security Risk Management
- Participate in identifying, assessing, classifying, and monitoring information security risks affecting critical information systems, data assets, business services, and technology platforms.
- Recommend appropriate risk treatment and mitigation measures based on risk impact and likelihood.
- Develop and monitor the implementation of risk mitigation plans.
- Information Security Review for IT Systems, Projects, and Solutions
- Review information security requirements incorporated into the design, architecture, and technical solutions of IT systems and projects.
- Participate in security assessments of IT solutions, products, services, and information systems before and during implementation.
- Recommend security control requirements based on system criticality, data sensitivity, and implementation scope.
- Monitor Information Security Incidents and Corrective Actions
- Organize the implementation of technical measures for personal data security, personal data protection standards and technical standards, and incident response plans for personal data protection incidents.
- Monitor the Security Information and Event Management (SIEM) system to enable the early detection of cybersecurity threats.
- Monitor, consolidate, and analyze information security incidents, policy violations, and security weaknesses identified during system operations.
- Participate in information security incident response, coordinate with technical teams and system owners to identify root causes, contain the incident, assess business impact, and implement corrective actions.
- Recommend preventive measures at the policy, process, technology, and organizational levels to prevent recurrence.
- Receive reports of, report to the competent authorities on, and coordinate the handling of personal data protection violations or personal data breaches/leakage incidents.
- Implement Information Security Programs
- Participate in organizing information security assessments, security exercises, awareness campaigns, training programs, personal data protection training and capacity-building programs, and communication initiatives.
- Support the development of a strong information security culture and promote security compliance throughout the organization.
- Participate in the Company's data protection activities.
Quyền lợi
Đào tạo
Tóm tắt thông tin từ tin tuyển dụng chính thức. Xem bản gốc ↗
Quan tâm đến vị trí này?
Bạn sẽ được chuyển đến trang ứng tuyển chính thức của nhà tuyển dụng.
Ứng tuyển tại trang chính thức ↗
Đây là doanh nghiệp của bạn?
Nhận quản lý trang, yêu cầu chỉnh sửa hoặc gỡ bỏ
→