Job Description
<Job Responsibilities> - Maintain an information management and protection framework for an effective global supply chain-wide governance program - Identify, track, and oversee internal and external compliance and regulatory requirements (Cyber Security Laws, Privacy Laws, etc.) for the global supply chain, including compliance with established policies, procedures, standards, baselines, and controls - Act as the primary Vietnam Information Security representative for production offices, factories, logistics providers and supply chain partners - Drive security governance, risk remediation, incident management and security maturity improvement across Vietnam supply chain partners - Manage day-to-day security activities, including vendor security onsite audits, remote assessments and ad-hoc investigations - Follow up with global production teams and partner factories to remediate findings - Track and manage remediation of audit findings - Engage factory management, FIC teams and production stakeholders to ensure timely closure of security risks and escalation of overdue findings - Coordinate local security incident reporting, investigation support, root cause analysis and corrective action management with factories and regional/global ISO teams - Build strong relationships with Production, Factory Inspection Center, factory management and local business stakeholders to promote security awareness and implementation of security requirements - Develop and deliver security awareness programs, incident response workshops, Minimum Security Requirement trainings and factory education programs to promote a culture of security and best practices within production-related organizations - Coordinate deployment and adoption of global security initiatives, such as Enterprise Browser / Island Browser, account governance controls and security monitoring initiatives, across Vietnam factories - Assist other ISO members to respond to security incidents in the Vietnam supply chain, including personal/confidential information leakage, system compromise, employee information leakage, information breach, factory physical security and production-related security concerns
Job Requirement
<Necessary Skill / Experience> - Educational Background: Bachelor's or Master's Degree in IT, Security, Audit, Computer Science or other related majors - Language: English - Business Level - Experience: + At least 5+ years of experience in information security governance, risk management, audit, compliance or third-party security role, with focused experience in risk assessment, remediation management, compliance and training + Knowledge and Experience in information security governance frameworks such as ISO27001 (or any other recognized security governance frameworks) + Knowledge and Experience in information security incident response + Experience in developing and enforcing security policies and procedures + Knowledge in Operational Technology systems and their security implications + Experience performing security assessments, risk reviews, compliance assessments, audits or supplier/vendor governance activities - Others: + Excellent communication skills to convey complex security concepts to technical and non-technical stakeholders + A proactive and adaptable mindset, with a willingness to stay updated on emerging threats and technologies