Senior IT Security Engineer
Knoldus Inc.
IT
Ho Chi Minh City, Vietnam
Posted 6+ months ago
Job Description
The IT System Engineer will act in technical duties of NashTech IT system team, providing IT system services across environments, platforms, technologies, and processes.
- Proactive work with CSO, Internal IT team and Internal development team to ensure company’s IT systems and application are integrated and comply with the company’s current information security policies, processes, procedures and standards.
- Implement, review and improve security controls and solutions according to the company’s Security Policy and Practices.
- Act as technical lead for IT Security related works
- Implement, test and improve measures to help protect the company’s IT infrastructure and environments.
- Act as Incident Respond Team (IRT) technical lead to investigate security threats and incidents, identify and implement mitigate actions.
- Security reporting & Conduct Security awareness training.
Qualifications
- University level with bachelor’s degree in computer science or equivalence.
- Has 2+ years of hand-on experience in security:
- System security configurations (IT infrastructure, Websites, WebApps)
- Penetration testing: System and network (internal/external, whitebox/blackbox)
- Vulnerabilities scanning and Security review
- Patching, Update and Hardening
- Security / SIEM monitoring
- Compliance and Audit
- Good knowledge of security principles, tool-sets and techniques and technologies
- Have knowledge of Cloud computing and Security architecture of Cloud computing
- Good understanding of firewall configuration, content filtering and network protocols, design and operations.
- Good understanding of IT system operations, both Linux and Windows, as well as virtualization infrastructure.
- Have experience working with security standards like ISO27001, PCI-DSS or HIPAA is an advantage.
- Good English skills to understand specification (written and oral).
- Good problem-solving skills and attention to detail.
- Strong analytical skills
- Time management skills
- Ability to work independently
- Industrial certifications holder: CISSP, CEH, SCP, GIACs, ComTIA Security+ is an advantage.