Head of Information Security

    Key Responsibilities

    Information Security Governance

    • Define and maintain Information Security policies, standards, and governance frameworks.
    • Ensure compliance with regulatory requirements, Head Office policies, and regional standards.
    • Lead security assessments, compliance reviews, gap analyses, and remediation programs.
    • Promote a strong security culture through awareness and governance initiatives.
    • Identify control gaps and improve security processes and capabilities.

    Technology Risk & Controls

    • Oversee technology risk management and first-line security controls.
    • Provide security and risk advisory for business initiatives, technology projects, and third-party engagements.
    • Monitor key security controls, including access management, privileged access, vulnerability management, and operational security.
    • Drive risk reporting, KRIs, control testing, and remediation tracking.

    Cyber Security Operations

    • Lead cyber security operations, monitoring, incident response, and cyber resilience programs.
    • Strengthen cyber defence capabilities through security technologies, threat monitoring, and continuous improvement.
    • Coordinate incident investigations, cyber exercises, and escalation processes.

    Audit & Stakeholder Management

    • Lead regulatory examinations, internal/external audits, and regional security reviews.
    • Manage audit remediation and regulatory reporting.
    • Partner with regulators, Head Office, regional teams, and business stakeholders to deliver security initiatives.
    • Lead strategic Information Security and cybersecurity transformation projects.

    Scope

    • Own Information Security governance, Cyber Security, Technology Risk, and IT Controls across Vietnam Branches.
    • Lead and develop the Information Security team.
    • Oversee security policies, compliance, audit activities, and management reporting.
    • Drive cybersecurity strategy, roadmap, security metrics, and Key Risk Indicators (KRIs).
    • Coordinate implementation of regional and global cybersecurity standards and programs.

    Requirements

    Education

    • Bachelor's degree or above in Information Security, Cyber Security, Computer Science, IT, or a related discipline.
    • Relevant security certifications are an advantage.

    Experience

    • 10+ years in Information Security, Cyber Security, IT Risk, or IT Governance.
    • 5+ years leading security or risk teams.
    • Banking, financial services, or other regulated industry experience.
    • Strong background in audits, regulatory compliance, and security risk management.

    Skills

    • Expertise in Information Security governance, cyber security, and technology risk.
    • Strong knowledge of access management, vulnerability management, incident response, and IT controls.
    • Experience leading compliance, security transformation, and governance initiatives.
    • Excellent leadership, stakeholder management, and communication skills.
    • Ability to collaborate effectively with senior management, regulators, auditors, and regional teams.

    HOW TO APPLY: Please send your CV to the consultant in charge:

    Ms. Nhu Hoa

    E-mail: nhuhoa.nguyen@ev-search.com

    All applications will be considered without regard to race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, parental status, military service, or any other non-merit factor.

    Interested in this position?

    Get in touch with us now!

    Quick Apply
    Email