Back to search
VinSmart Future Linkedin · Posted 2d ago

Senior Security Engineer

Ho Chi Minh City

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

VinSmart Future vận hành hạ tầng đa cloud trên nhiêu nền tảng: AWS, GCP,... phục vụ hệ sinh thái sản phẩm trong nước và quốc tế. Đội Security Engineering chịu trách nhiệm về bảo mật lớp hạ tầng, bao gồm cloud posture management, IAM governance, network security và ứng phó sự cố.

III. Trách Nhiệm Chính

3.1 Phối hợp trực tiếp với DevOps trong xử lý lỗ hổng bảo mật

  • Làm việc cùng DevOps engineer để phân tích nguyên nhân gốc rễ (root cause analysis) của từng security finding, xác định phạm vi ảnh hưởng và xây dựng phương án remediation phù hợp với từng môi trường.
  • Trực tiếp triển khai các thay đổi kỹ thuật: chỉnh sửa IAM policy, Security Group, bucket policy, network ACL, Kubernetes RBAC, Terraform module
  • Theo dõi và xác nhận kết quả sau remediation (validation & verification) trên môi trường staging và production; lập biên bản đóng lỗi có đầy đủ bằng chứng kỹ thuật.
  • Hỗ trợ review và hardening Dockerfile, GitLab CI/CD pipeline, Jenkins Shared Library liên quan đến cloud workload security (secret management, image signing, least privilege execution).

3.2 Đánh giá bảo mật định kỳ trên đa cloud

  • Thực hiện cloud security assessment theo CIS Benchmark và best practice của từng cloud provider (AWS Well-Architected Security Pillar, GCP Security Foundations, Huawei Cloud Security White Paper).
  • Rà soát cấu hình IAM: phân tích over-permission, cross-account trust relationship, service account key exposure, privilege escalation path.

3.3 Tự động hoá và tích hợp DevSecOps

  • Xây dựng và duy trì preventive control dưới dạng code: AWS Service Control Policy (SCP), GCP Organization Policy, Huawei Config Rule.
  • Phát triển detective control tự động: OPA/Rego policy, AWS Config custom rule, Security Command Center custom module — phát hiện sai lệch so với baseline ngay khi xuất hiện.
  • Xây dựng và duy trì dashboard bảo mật cloud, thiết lập alert threshold cho CSPM findings, GuardDuty, Security Hub, Security Command Center.

3.4 Ứng phó sự cố và phát hiện mối đe dọa

  • Điều tra security finding từ các công cụ phát hiện: AWS GuardDuty, GCP Security Command Center,...
  • Tham gia Incident Response khi có sự cố liên quan đến cloud infrastructure: phân tích log, tracing lateral movement, đánh giá blast radius, phối hợp containment.

3.5 Governance và tài liệu hoá

  • Soạn thảo và cập nhật tài liệu kiến trúc bảo mật cloud, runbook xử lý sự cố, hướng dẫn cấu hình an toàn cho từng cloud service.
  • Tham gia threat modeling cho hệ thống mới hoặc thay đổi kiến trúc lớn, đặc biệt các dự án có sử dụng managed cloud service, serverless, hoặc container platform.
  • Báo cáo định kỳ trạng thái bảo mật cloud (posture report) gửi Security Engineering Lead và các bên liên quan; theo dõi trend và đề xuất cải tiến.

IV. Yêu Cầu

4.1 Kinh nghiệm & kỹ năng bắt buộc

  • Tối thiểu 2 năm kinh nghiệm thực tế trong vai trò Cloud Security Engineer, Cloud Engineer, hoặc DevOps Engineer với trọng tâm bảo mật.
  • Có kinh nghiệm thực tế trên cac AWS, GCP,... AWS, GCP,...
  • Hiểu sâu IAM model của ít nhất một cloud provider: roles, policies, trust relationships, STS (AWS) / Workload Identity (GCP) / Service Account.
  • Có khả năng đọc, review và chỉnh sửa Terraform: hiểu resource dependency, module structure, state management.
  • Nắm vững Kubernetes security: RBAC, NetworkPolicy, Admission Controller, Pod Security Standard, secret management (External Secrets, Vault Agent).
  • Biết sử dụng ít nhất một CSPM tool: AWS Security Hub, GCP Security Command Center, hoặc third-party (Wiz, Orca, Lacework, Prisma Cloud).

4.2 Kỹ năng mở rộng (lợi thế cạnh tranh)

  • Đã viết OPA/Rego policy hoặc AWS Config custom rule trong môi trường production.
  • Kinh nghiệm cloud penetration testing: AWS privilege escalation, GCP lateral movement, metadata service exploitation.
  • Chứng chỉ chuyên ngành: AWS Security Specialty, Google Professional Cloud Security Engineer, CCSP, hoặc tương đương.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search