This job has been added to your Saved jobs.
You have reached the limit of 20 Saved Jobs. If you want to create a new one, please manage your Saved Jobs.
Top 3 reasons to join us
- Full social and unemployment insurance benefits
- Review salary for every six months according to KP
- Annual health check-up
Job description
Role Overview
Fundiin is evolving from a BNPL product into a multi-product consumer financial platform — and with that evolution comes increasing regulatory scrutiny, higher expectations from lenders and partners, and a growing attack surface that needs to be managed proactively.
As Information Security & Compliance Lead, you will play a pivotal role in shaping Fundiin's security function — building on existing practices and certifications to establish a comprehensive, proactive framework that scales with the business. You will own the security and compliance posture end-to-end, working closely with engineering, DevOps, and external vendors to ensure Fundiin can scale into regulated financial services with confidence.
Fundiin already holds ISO 27001 and PCI-DSS certifications and has established security practices in place — this role is not about starting from zero, but about bringing structure, ownership, and a proactive mindset to what exists, and building what is still missing.
For the right person, this is a rare opportunity to own and shape an entire security function at a high-growth fintech — with direct visibility to the CTO and meaningful impact on how Fundiin scales into regulated financial markets.
This is a role for someone who is technically grounded, ownership-oriented, and comfortable leading through influence rather than headcount.
What You Will Do
1. Vulnerability & Threat Management
- Own the vulnerability management program — define scope, tooling, SLAs, and remediation workflows; coordinate with DevOps and vendors for execution
- Monitor CVE feeds and vendor advisories; assess impact on Fundiin's tech stack and drive timely remediation
- Define security requirements and acceptance criteria for CI/CD pipeline — coordinate with DevOps to implement scanning and security gates
2. Security Operations & Access Control
- Define monitoring requirements and detection rules; coordinate with SOC vendor for 24/7 coverage; lead incident response when escalated
- Own the access control framework — enforce least privilege, conduct periodic access reviews, and ensure clean offboarding
- Define and enforce policies for developer access to production environments and sensitive data
3. Data Security & Privacy
- Own the data security framework — define classification, encryption, masking, and export control policies for customer PII and eKYC data
- Drive NĐ 13/2023 compliance — own data mapping, DPIA, and consent management; coordinate with product and engineering for implementation
4. Policy, Governance & Compliance
- Define and maintain security policies, rules, and checklists across the organization
- Own renewal and maintenance of ISO 27001 and PCI-DSS certifications; drive compliance with local regulatory requirements — coordinate with external auditors and consultants as needed
- Define and standardize compliance checklists for lender onboarding; coordinate responses to audit and security questionnaires from partners
- Maintain risk register and track remediation status; report regularly to management
5. Awareness & Reporting
- Define and drive the security awareness program — coordinate training and secure coding sessions for the engineering team
- Deliver regular risk, vulnerability, and remediation status reports to management
- Serve as primary point of contact for internal and external audits
Your skills and experience
Must Have
- 3–5+ years of experience in information security with hands-on technical depth — vulnerability management, access control, log monitoring, and incident response
- Strong understanding of common attack vectors and security controls — OWASP Top 10, CVE management, secure architecture principles
- Experience in fintech, banking, or a regulated financial environment
- Familiarity with at least one compliance framework — ISO 27001, PCI-DSS, or equivalent — sufficient to maintain and operate, not just document
- Able to drive programs forward without a dedicated team — comfortable coordinating across engineering, product, and external vendors to get things done
- Strong ownership mindset — identifies gaps proactively, drives resolution, does not wait to be told what to do
Nice To Have
- Security teams within fintech or financial technology companies: In-house security teams at reputable banks , Reputable security service providers, Fintech security teams in Fintech companies
- Candidates with strong hands-on technical depth in incident response, and combined with exposure to security and compliance frameworks.
- Familiarity with AI-powered security tools — vulnerability scanning (Snyk or equivalent), threat detection, or security operations — and comfortable using LLMs to accelerate security workflows such as threat analysis, policy drafting, and reporting
- Familiarity with GCP security tools — Cloud Audit Logs, Security Command Center, Cloud DLP
- Experience with CI/CD security integration — SAST, DAST, dependency scanning
- Knowledge of NĐ 13/2023 and Vietnamese regulatory requirements for financial services
- Security certifications — CISSP, CISM, ISO 27001 Lead Implementer, or equivalent
Why you'll love working here
At Fundiin, we believe in fostering a dynamic work environment that encourages personal and professional growth.
Empowerment and Growth:
- We offer great autonomy, freedom to make decisions, room to take risks and learn from mistakes.
- Get involved from the ground up in creating and developing new products, leading teams, working on innovative projects, and gaining visibility within the industry.
Competitive Benefits:
- Enjoy a robust benefits package, including meaningful ESOP options.
- Access our premium health care program and annual health checkup.
- Receive a budget of 2,400,000 VND per year for professional development.
- Take advantage of device allowances or financing options covering up to 50% of new device purchases.
Engaging Work Environment:
- Participate in our monthly Town Hall meetings and collaborative sharing sessions.
- 15 days of annual leave to recharge and pursue personal interests, plus an extra day for every 3 years of service.
- Join biannual team-building trips for bonding and connections.
- Enjoy free daily drinks and weekly TGIF snacks and beverages.
FUNDIIN - Financial Services Platform