VNDirect

IPAS - Vulnerability Management Analyst

Hanoi, Vietnam · On site · Mid level

Vietnamese required

Translated automatically from Vietnamese. Read the original

POSITION OBJECTIVE

Operate a centralized vulnerability management process: receive and process results from VA/scan, pentest, internal red team, DevSecOps and third-party assessments; triage, track remediation SLA, consolidate metrics/dashboard for all products.

JOB DESCRIPTION

1. Operate Vulnerability Management Process

  • Receive and consolidate vulnerabilities from all sources: VA/scan, internal pentest and red team, DevSecOps (SAST/DAST/SCA), and third-party assessments.
  • Triage, score CVSS, classify and assign remediation owners.

2. Track SLA and Coordinate Remediation

  • Track remediation progress against SLA, escalate overdue cases.
  • Coordinate with development/operations teams and stakeholders to ensure remediation.

3. Metrics, Dashboard and Reporting

  • Build and maintain vulnerability risk dashboard.
  • Provide periodic reports to Product Security Lead/CISO.

4. Coordinate Third-Party Assessments

  • Coordinate outsourced assessment rounds (pentest, red team, audit): prepare scope, identify points of contact, track progress.
  • Receive, standardize and input findings into vulnerability management system; track remediation.

5. Asset Management and Periodic Scanning

  • Maintain asset inventory and periodic vulnerability scanning schedule.
  • Update threat intelligence and KEV list.

CANDIDATE PROFILE

1. Education:

  • Bachelor's degree in IT, Information Security or related field; equivalent practical experience may substitute.
  • CompTIA Security+, GIAC (GEVA/GCVM), CEH (preferred).
  • Threat intelligence / AI security certification is an advantage.

2. Experience:

  • Minimum 2 years of experience.

3. Knowledge and Professional Skills:

3.1. Professional Skills

  • 2+ years of vulnerability management/security operations.
  • Vuln scanner: Nessus, Qualys, Rapid7.
  • Understand CVSS, CVE, KEV, EPSS; OWASP Top 10.
  • Understand container/image vulnerability scanning (e.g. Trivy) and cloud scanning (CSPM).
  • Data/dashboard skills (Excel/Power BI/SQL); ITSM process (Jira/ServiceNow).
  • Programming/scripting (Python) is an advantage.

3.2. Industry Skills

  • Understanding of financial/regulated environment is an advantage.
  • Understand ISO 27001, PCI-DSS.

3.3. Digital Skills

  • Use AI to classify and prioritize vulnerabilities, automate reporting.
  • SBOM and VEX as exposure data sources; threat intelligence.

4. Other Requirements

  • Independently operate vulnerability management process and coordinate PSIRT under guidance; prioritize risks based on data; coordinate multiple parties on remediation.
  • Good reporting and communication skills.

BENEFITS AND TREATMENT

  • Flexible and Competitive Compensation: Receive fixed salary commensurate with capability and attractive performance-based bonuses based on actual contribution to projects.
  • Clear career development roadmap
  • Benefits and working conditions: Active Cool-down transition mechanism: After campaigns or continuous long-term projects, the company prioritizes creating space and time for you to transition to rest, training and energy recovery, preparing for the next steps.
  • Full insurance, healthcare and benefits according to State regulations and the Group's exclusive policies.
  • Open, transparent and fully digitalized working environment.
  • Premium health insurance package and 24/24 accident insurance beyond BHXH, BHYT, BHTN as per State regulations
  • Training programs for personal capability development, team engagement programs, retreats, teambuilding.
The original, in Vietnamese

MỤC TIÊU VỊ TRÍ

Vận hành quy trình quản lý lỗ hổng tập trung: tiếp nhận & xử lý kết quả từ VA/scan, pentest, red team nội bộ, DevSecOps và đánh giá bên thứ 3; triage, theo dõi SLA khắc phục, tổng hợp metrics/dashboard cho toàn bộ sản phẩm.

MÔ TẢ CÔNG VIỆC

1. Vận hành quy trình Vulnerability Management

  • Tiếp nhận & tổng hợp lỗ hổng từ mọi nguồn: VA/scan, pentest & red team nội bộ, DevSecOps (SAST/DAST/SCA), và đánh giá từ bên thứ 3.
  • Triage, chấm điểm CVSS, phân loại và gán chủ sở hữu khắc phục.

2. Theo dõi SLA & điều phối khắc phục

  • Theo dõi tiến độ khắc phục theo SLA, escalate trường hợp quá hạn.
  • Phối hợp đội phát triển/vận hành và các bên liên quan để đảm bảo khắc phục.

3. Metrics, dashboard & báo cáo

  • Xây dựng & duy trì dashboard rủi ro lỗ hổng.
  • Báo cáo định kỳ cho Product Security Lead/CISO.

4. Điều phối đánh giá bên thứ 3

  • Điều phối các đợt đánh giá thuê ngoài (pentest, red team, audit): chuẩn bị phạm vi, đầu mối, theo dõi tiến độ.
  • Tiếp nhận, chuẩn hóa và đưa phát hiện vào hệ quản lý lỗ hổng; theo dõi khắc phục.

5. Quản lý tài sản & quét định kỳ

  • Duy trì asset inventory & lịch quét lỗ hổng định kỳ.
  • Cập nhật threat intel và danh sách KEV.

CHÂN DUNG ỨNG VIÊN

1. Trình độ học vấn:

  • Tốt nghiệp Đại học chuyên ngành CNTT, An toàn thông tin hoặc chuyên ngành liên quan; kinh nghiệm thực tế tương đương có thể thay thế.
  • CompTIA Security+, GIAC (GEVA/GCVM), CEH (định hướng).
  • Chứng chỉ threat intelligence / AI security là lợi thế.

2. Kinh nghiệm:

  • Tối thiểu 2 năm kinh nghiệm.

3. Kiến thức & Kỹ năng chuyên môn:

3.1.  Kỹ năng chuyên môn

  • 2+ năm quản lý lỗ hổng/security operations.
  • Vuln scanner: Nessus, Qualys, Rapid7.
  • Nắm CVSS, CVE, KEV, EPSS; OWASP Top 10.
  • Nắm quét lỗ hổng container/image (vd. Trivy) và cloud (CSPM).
  • Kỹ năng dữ liệu/dashboard (Excel/Power BI/SQL); quy trình ITSM (Jira/ServiceNow).
  • Biết lập trình/scripting (Python) là lợi thế.

3.2. Kỹ năng theo ngành

  • Hiểu môi trường tài chính/regulated là lợi thế.
  • Nắm ISO 27001, PCI-DSS.

3.3. Kỹ năng số

  • Dùng AI phân loại & ưu tiên lỗ hổng, tự động hóa báo cáo.
  • SBOM & VEX làm nguồn dữ liệu phơi nhiễm; threat intelligence.

4. Yêu cầu khác

  • Vận hành độc lập quy trình quản lý lỗ hổng & điều phối PSIRT dưới định hướng; ưu tiên rủi ro dựa dữ liệu; điều phối nhiều bên khắc phục.
  • Kỹ năng báo cáo & giao tiếp tốt.

ĐẶC QUYỀN & ĐÃI NGỘ

  • Thu nhập linh hoạt & Cạnh tranh: Nhận mức lương cố định tương xứng với năng lực và các khoản thưởng hấp dẫn dựa trên hiệu suất đóng góp thực tế tại các dự án.
  • Lộ trình phát triển sự nghiệp rõ ràng
  • Phúc lợi & điều kiện làm việc: Cơ chế chuyển đổi trạng thái (Active Cool-down): Sau các chiến dịch hoặc dự án dài hạn liên tục, công ty ưu tiên tạo không gian và thời gian để bạn chuyển đổi trạng thái sang nghỉ ngơi, đào tạo và phục hồi năng lượng, chuẩn bị cho những nấc thang tiếp theo.
  • Đầy đủ các chế độ bảo hiểm, y tế, phúc lợi theo quy định của Nhà nước và các chính sách ưu việt riêng của Tập đoàn.
  • Môi trường làm việc cởi mở, minh bạch và số hóa toàn diện.
  • Gói bảo hiểm sức khỏe cao cấp và bảo hiểm tai nạn 24/24 ngoài chính sách BHXH, BHYT theo quy định của nhà nước BHTN
  • Các chương trình đào tạo phát triển năng lực cá nhân, chương trình gắn kết đội ngũ, retreat, teambuilding.

Get access to all 2,144 jobs.

Free, with your email. New roles that fit you, every Monday.

OV members also see who works at each company and can ask them for a short chat.

Apply to join

OV member? Use the email you use for OV.

Hiring? Reach Overseas Vietnamese.Post roles