Protect customer information and company confidential information by establishing and maintaining an effective information security governance program across the Vietnam supply chain, ensuring compliance with security policies and regulations while driving security maturity improvements.
- Maintain an information management and protection framework for an effective global supply chain-wide governance program - Identify, track, and oversee internal and external compliance and regulatory requirements (Cyber Security Laws, Privacy Laws, etc.) for the global supply chain, including compliance with established policies, procedures, standards, baselines, and controls - Act as the primary Vietnam Information Security representative for production offices, factories, logistics providers and supply chain partners - Drive security governance, risk remediation, incident management and security maturity improvement across Vietnam supply chain partners - Manage day-to-day security activities, including vendor security onsite audits, remote assessments and ad-hoc investigations - Follow up with global production teams and partner factories to remediate findings - Track and manage remediation of audit findings - Engage factory management, FIC teams and production stakeholders to ensure timely closure of security risks and escalation of overdue findings - Coordinate local security incident reporting, investigation support, root cause analysis and corrective action management with factories and regional/global ISO teams - Build strong relationships with Production, Factory Inspection Center, factory management and local business stakeholders to promote security awareness and implementation of security requirements - Develop and deliver security awareness programs, incident response workshops, Minimum Security Requirement trainings and factory education programs to promote a culture of security and best practices within production-related organizations - Coordinate deployment and adoption of global security initiatives, such as Enterprise Browser / Island Browser, account governance controls and security monitoring initiatives, across Vietnam factories - Assist other ISO members to respond to security incidents in the Vietnam supply chain, including personal/confidential information leakage, system compromise, employee information leakage, information breach, factory physical security and production-related security concerns
- Educational Background: Bachelor's or Master's Degree in IT, Security, Audit, Computer Science or other related majors - Language: English - Business Level - Experience: + At least 5+ years of experience in information security governance, risk management, audit, compliance or third-party security role, with focused experience in risk assessment, remediation management, compliance and training + Knowledge and Experience in information security governance frameworks such as ISO27001 (or any other recognized security governance frameworks) + Knowledge and Experience in information security incident response + Experience in developing and enforcing security policies and procedures + Knowledge in Operational Technology systems and their security implications + Experience performing security assessments, risk reviews, compliance assessments, audits or supplier/vendor governance activities - Others: + Excellent communication skills to convey complex security concepts to technical and non-technical stakeholders + A proactive and adaptable mindset, with a willingness to stay updated on emerging threats and technologies