About this role
<p style="margin:0.0in 0.0in 8.0pt 0.0px;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Scope & Dimension</span></strong></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Overall responsibility for Information Security governance, Cyber Security, Technology Risk, and Technology Controls across Vietnam Branches.</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Manage the Information Security team, including staff development, performance, and resource planning.</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Oversee Information Security policies, controls, risk management, regulatory compliance, and audit activities.</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Lead local and regional Information Security initiatives and provide regular management reporting on security risks, incidents, controls, and remediation progress.</span></li> <li style="text-align:justify;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Address the regulatory requirements on Information security matters.</span></li> <li style="text-align:justify;background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Develop and maintain branch cybersecurity strategy, roadmap, security metrics, and Key Risk Indicators (KRIs).</span></li> </ul> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;text-align:justify;line-height:15.0pt;background-color:white;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:10.5pt;font-family:'Segoe UI', sans-serif;color:black">Collaborate with Regional Information Security and act as the branch lead to coordinate and drive implementation of regional and global cybersecurity initiatives, standards, tools, and programs</span></li> </ul> <p style="background-color:white;margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Key Responsibilities</span></strong></p> <p style="background-color:white;margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">a. Information Security Governance & Compliance</span></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Establish and maintain Information Security policies, standards, procedures, and governance frameworks.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Ensure compliance with applicable regulations, Head Office requirements, and regional standards.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Lead regulatory impact assessments, compliance gap analyses, remediation plans, and regulatory reporting.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Promote security awareness and foster a strong security culture across Vietnam Branches.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Identify process/capabilities gaps and inefficiencies within IT and IS frameworks; recommend and implement pragmatic improvements to enhance security posture and risk management</span></li> </ul> <p style="background-color:white;margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">b. Technology Risk & Control Management</span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="background-color:white;margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Provide effective first-line challenge (1LOD) on risk identification, prioritisation, and remediation, and deliver risk opinions and recommendations to management and second line of defence (2LOD).</span></li> <li style="background-color:white;margin:0.0in 0.0in 0.0in 0.0px;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Support 2LOD in strengthening risk governance practices, including the development of Key Risk Indicators (KRIs), enhancement of the Technology Risk Management framework, and ongoing monitoring and reporting.</span></li> <li style="background-color:white;margin:0.0in 0.0in 8.0pt 0.0px;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Oversee Technology and Security GRC activities across APAC entities, including consolidation of risk reporting, support for internal and external audits, and review of risk acceptance requests.</span></li> </ul> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Provide security and risk advisory support for business initiatives, technology projects, risk acceptances, and third-party engagements.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Ensure effective implementation and monitoring of key security controls, including access management, privileged ID controls, security reviews, vulnerability management, and operational control testing.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Monitor control remediation activities and report risk and control status to management.</span></li> </ul> <p style="background-color:white;margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">c. Cyber Security Operations</span></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Lead cyber security programmes, security monitoring, cyber resilience initiatives, and incident management.</span></li> <li style="background-color:white;margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif;color:black">Oversee threat monitoring, security investigations, cyber exercises, and incident escalation processes.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Drive continuous enhancement of cyber defence capabilities and deployment of security technologies and tools.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">d. Audit, Stakeholder & Strategic Project Management</span></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Serve as the primary liaison for Information Security audits, regulatory examinations, and regional reviews.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Coordinate audit responses, remediation tracking, and closure of findings.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Partner with regional teams, Head Office, business units, and external stakeholders to implement security standards and initiatives.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Lead and support strategic Information Security projects and regional standardisation programmes.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.0px;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Hiring requirements</span></strong></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><u><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Education & Certifications</span></u></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Bachelor's degree or higher in Information Security, Cyber Security, IT, Computer Science, or related fields.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Knowledge of data protection and privacy regulations is an advantage.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><u><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Experience</span></u></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">10+ years of experience in Information Security, Cyber Security, IT Risk, or IT Governance.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">5+ years of leadership or people management experience.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Experience in banking, financial services, or other regulated industries.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Hands-on experience in audits, regulatory compliance, and security risk management.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><u><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Competencies</span></u></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Strong knowledge of Information Security governance, cyber security, and technology risk management.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Experience with access management, security monitoring, vulnerability management, and incident response.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Understanding of IT controls, outsourcing risk, and regulatory requirements.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Ability to lead security transformation and compliance initiatives.</span></li> </ul> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Strong leadership, stakeholder management, and team development skills.</span></li> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Ability to work effectively with management, regulators, auditors, and regional teams.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><u><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Preferrable</span></u></p> <ul style="margin-top:0.0in;margin-bottom:0.0in" type="disc"> <li style="margin-top:0.0in;margin-right:0.0in;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Experience in a foreign bank, multinational financial institution, or regional environment.</span></li> </ul> <p><span style="font-size:11.5pt;line-height:115%;font-family:Calibri, sans-serif">Proven ability to build and lead an Information Security function</span></p>