Việc làm này đã được thêm vào mục Việc làm đã lưu.
Bạn đã lưu tối đa 20 việc làm. Nếu bạn muốn lưu mới, hãy cập nhật Việc làm đã lưu.
3 Lý do để gia nhập công ty
- Full social and unemployment insurance benefits
- Review salary for every six months according to KP
- Annual health check-up
Mô tả công việc
Role Overview
Fundiin is evolving from a BNPL product into a multi-product consumer financial platform — and with that evolution comes increasing regulatory scrutiny, higher expectations from lenders and partners, and a growing attack surface that needs to be managed proactively.
As Information Security & Compliance Lead, you will play a pivotal role in shaping Fundiin's security function — building on existing practices and certifications to establish a comprehensive, proactive framework that scales with the business. You will own the security and compliance posture end-to-end, working closely with engineering, DevOps, and external vendors to ensure Fundiin can scale into regulated financial services with confidence.
Fundiin already holds ISO 27001 and PCI-DSS certifications and has established security practices in place — this role is not about starting from zero, but about bringing structure, ownership, and a proactive mindset to what exists, and building what is still missing.
For the right person, this is a rare opportunity to own and shape an entire security function at a high-growth fintech — with direct visibility to the CTO and meaningful impact on how Fundiin scales into regulated financial markets.
This is a role for someone who is technically grounded, ownership-oriented, and comfortable leading through influence rather than headcount.
What You Will Do
1. Vulnerability & Threat Management
- Own the vulnerability management program — define scope, tooling, SLAs, and remediation workflows; coordinate with DevOps and vendors for execution
- Monitor CVE feeds and vendor advisories; assess impact on Fundiin's tech stack and drive timely remediation
- Define security requirements and acceptance criteria for CI/CD pipeline — coordinate with DevOps to implement scanning and security gates
2. Security Operations & Access Control
- Define monitoring requirements and detection rules; coordinate with SOC vendor for 24/7 coverage; lead incident response when escalated
- Own the access control framework — enforce least privilege, conduct periodic access reviews, and ensure clean offboarding
- Define and enforce policies for developer access to production environments and sensitive data
3. Data Security & Privacy
- Own the data security framework — define classification, encryption, masking, and export control policies for customer PII and eKYC data
- Drive NĐ 13/2023 compliance — own data mapping, DPIA, and consent management; coordinate with product and engineering for implementation
4. Policy, Governance & Compliance
- Define and maintain security policies, rules, and checklists across the organization
- Own renewal and maintenance of ISO 27001 and PCI-DSS certifications; drive compliance with local regulatory requirements — coordinate with external auditors and consultants as needed
- Define and standardize compliance checklists for lender onboarding; coordinate responses to audit and security questionnaires from partners
- Maintain risk register and track remediation status; report regularly to management
5. Awareness & Reporting
- Define and drive the security awareness program — coordinate training and secure coding sessions for the engineering team
- Deliver regular risk, vulnerability, and remediation status reports to management
- Serve as primary point of contact for internal and external audits
Yêu cầu công việc
Must Have
- 3–5+ years of experience in information security with hands-on technical depth — vulnerability management, access control, log monitoring, and incident response
- Strong understanding of common attack vectors and security controls — OWASP Top 10, CVE management, secure architecture principles
- Experience in fintech, banking, or a regulated financial environment
- Familiarity with at least one compliance framework — ISO 27001, PCI-DSS, or equivalent — sufficient to maintain and operate, not just document
- Able to drive programs forward without a dedicated team — comfortable coordinating across engineering, product, and external vendors to get things done
- Strong ownership mindset — identifies gaps proactively, drives resolution, does not wait to be told what to do
Nice To Have
- Security teams within fintech or financial technology companies: In-house security teams at reputable banks , Reputable security service providers, Fintech security teams in Fintech companies
- Candidates with strong hands-on technical depth in incident response, and combined with exposure to security and compliance frameworks.
- Familiarity with AI-powered security tools — vulnerability scanning (Snyk or equivalent), threat detection, or security operations — and comfortable using LLMs to accelerate security workflows such as threat analysis, policy drafting, and reporting
- Familiarity with GCP security tools — Cloud Audit Logs, Security Command Center, Cloud DLP
- Experience with CI/CD security integration — SAST, DAST, dependency scanning
- Knowledge of NĐ 13/2023 and Vietnamese regulatory requirements for financial services
- Security certifications — CISSP, CISM, ISO 27001 Lead Implementer, or equivalent
Tại sao bạn sẽ yêu thích làm việc tại đây
At Fundiin, we believe in fostering a dynamic work environment that encourages personal and professional growth.
Empowerment and Growth:
- We offer great autonomy, freedom to make decisions, room to take risks and learn from mistakes.
- Get involved from the ground up in creating and developing new products, leading teams, working on innovative projects, and gaining visibility within the industry.
Competitive Benefits:
- Enjoy a robust benefits package, including meaningful ESOP options.
- Access our premium health care program and annual health checkup.
- Receive a budget of 2,400,000 VND per year for professional development.
- Take advantage of device allowances or financing options covering up to 50% of new device purchases.
Engaging Work Environment:
- Participate in our monthly Town Hall meetings and collaborative sharing sessions.
- 15 days of annual leave to recharge and pursue personal interests, plus an extra day for every 3 years of service.
- Join biannual team-building trips for bonding and connections.
- Enjoy free daily drinks and weekly TGIF snacks and beverages.
FUNDIIN - Financial Services Platform