Role Description
This is a full-time, hybrid Cyber Security Analyst role based in Ho Chi Minh City, Vietnam, with flexibility for some remote work as you will work directly with our bid data healthcare Australian Client. The Cyber Security Analyst will be responsible for protecting the company's digital assets, monitoring potential security risks, analyzing threats, and implementing strategies to secure applications and networks. The role also involves performing regular security assessments, providing recommendations to enhance system resiliency, and collaborating with cross-functional teams to mitigate vulnerabilities.
Responsibilities
Security Operations & Incident Response
- Work with managed service providers to investigate cyber security incidents, perform root cause analysis, and support containment, remediation, and recovery activities.
- Monitor security events and alerts using SIEM and Microsoft security tooling to detect suspicious or anomalous activity.
- Support the response to security incidents involving FLG information, SaaS platforms and various ICT systems.
- Work with managed service providers and internal technology teams to remediate vulnerabilities identified through scans, testing, and audits.
- Contribute to operational security procedures, runbooks, and incident response playbooks.
Compliance & Governance
- support the treatment of cyber security risks identified through ICT projects, digital initiatives, and BAU activities.
- Proactively identify and assess cyber security risks associated with member‑facing platforms, corporate systems, and operational environments.
- Support compliance and assurance activities aligned to our security frameworks, contractual obligations, and privacy requirements.
Vulnerability, Third‑Party & Supply‑Chain Risk
- Conduct security risk assessments for new technologies, digital platforms, and business initiatives.
- Support third‑party and supply‑chain security assessments.
- Proactively follow up remediation actions with internal stakeholders and vendors to ensure timely treatment of identified risks.
- Clearly communicate cyber security risks, impacts, and recommendations to technology, legal, digital, and business stakeholders.
Security Culture & Awareness
- Support the delivery of our Cyber Security Awareness Program.
- Assist with the development and delivery of security training materials tailored to corporate, digital, and operational teams.
- Promote secure behaviours across the organisation, including phishing awareness, password hygiene, and secure handling of member information.
Personal Specifications
Qualifications & Experience
- Tertiary qualification in Information Technology, Computer Science, Cyber Security, or equivalent practical experience.
- Desirable Certifications
- CompTIA Security+ or CySA+
- AZ‑500, AZ‑305, SC-300, SC-200
- Experience with Microsoft Purview advantageous
- Technical & Professional Competencies
- Strong collaboration and interpersonal skills, with the ability to work across technology, digital, legal, and business teams.
- Analytical and pragmatic problem‑solver with a risk‑based mindset.
- Ability to work autonomously while contributing effectively within a small, high‑impact cyber function.
- Strong written and verbal communication skills, with the ability to explain cyber security concepts in clear, practical terms.
- High level of discretion when handling sensitive information, including member and commercial data.
- Cyber Security Knowledge
- Solid understanding of cyber security principles, risk management practices, and security control frameworks.
- Working knowledge of relevant standards and legislation, including:
- ISO/IEC 27001
- ACSC Essential Eight
- Australian privacy legislation
- NIST Cybersecurity Framework (CSF)
- Experience with Microsoft Azure IaaS and PaaS in an enterprise or consumer‑facing environment
Experience
- Minimum 3-5+ years experience in cyber security operations, governance, risk, compliance, or third‑party security.
- Experience supporting audit, assurance, or compliance activities.
- Experience working with outsourced IT or managed security service providers.
- Exposure to agile delivery environments and working across multiple initiatives simultaneously.
- Demonstrated commitment to continuous learning in emerging cyber security technologies, automation, and AI‑enabled security tools.
- Advanced English (verbal & written)
What we offer
- Great working environment, big Data AU client.
- Attractive Salary and Benefits, Full equipment provided.
- 13th salary + yearly review + lunch allowance
- Fully paid for Social Insurance, PVI Insurance
- 1215 annual leaves, Yearly health check, Holidays as per law.
- Free in-house food and beverage.
- Team Building, Events, Party, Sport Clubs, etc.
- And many more align with the US head office.
- Monday - Friday. - Hybrid (2/3 days at office, the rest for work from home)
- Address: IPC Tower, 1489 Nguyen Van Linh, Tan Phong, District 7, HCM (New Tan Hung)
Interview Process: 2 online rounds + 1 Test (optional) (MS Teams)