Khám phá việc làm Cloud & Infrastructure nổi bật.
Xem ngay

(Senior/Lead) Information Security Engineer

Fundiin
Tầng 7, tòa Lottery Tower, 77 Trần Nhân Tôn, An Đông, TP Hồ Chí Minh
Tại văn phòng
Đăng 4 giờ trước
Chuyên môn:
Lĩnh vực:
Ngân Hàng
Dịch Vụ Tài Chính

3 Lý do để gia nhập công ty

  • Full social and unemployment insurance benefits
  • Review salary for every six months according to KP
  • Annual health check-up

Mô tả công việc

Role Overview

Fundiin is evolving from a BNPL product into a multi-product consumer financial platform — and with that evolution comes increasing regulatory scrutiny, higher expectations from lenders and partners, and a growing attack surface that needs to be managed proactively.

As Information Security & Compliance Lead, you will play a pivotal role in shaping Fundiin's security function — building on existing practices and certifications to establish a comprehensive, proactive framework that scales with the business. You will own the security and compliance posture end-to-end, working closely with engineering, DevOps, and external vendors to ensure Fundiin can scale into regulated financial services with confidence.

Fundiin already holds ISO 27001 and PCI-DSS certifications and has established security practices in place — this role is not about starting from zero, but about bringing structure, ownership, and a proactive mindset to what exists, and building what is still missing.

For the right person, this is a rare opportunity to own and shape an entire security function at a high-growth fintech — with direct visibility to the CTO and meaningful impact on how Fundiin scales into regulated financial markets.

This is a role for someone who is technically grounded, ownership-oriented, and comfortable leading through influence rather than headcount.

What You Will Do

1. Vulnerability & Threat Management

  • Own the vulnerability management program — define scope, tooling, SLAs, and remediation workflows; coordinate with DevOps and vendors for execution
  • Monitor CVE feeds and vendor advisories; assess impact on Fundiin's tech stack and drive timely remediation
  • Define security requirements and acceptance criteria for CI/CD pipeline — coordinate with DevOps to implement scanning and security gates

2. Security Operations & Access Control

  • Define monitoring requirements and detection rules; coordinate with SOC vendor for 24/7 coverage; lead incident response when escalated
  • Own the access control framework — enforce least privilege, conduct periodic access reviews, and ensure clean offboarding
  • Define and enforce policies for developer access to production environments and sensitive data

3. Data Security & Privacy

  • Own the data security framework — define classification, encryption, masking, and export control policies for customer PII and eKYC data
  • Drive NĐ 13/2023 compliance — own data mapping, DPIA, and consent management; coordinate with product and engineering for implementation

4. Policy, Governance & Compliance

  • Define and maintain security policies, rules, and checklists across the organization
  • Own renewal and maintenance of ISO 27001 and PCI-DSS certifications; drive compliance with local regulatory requirements — coordinate with external auditors and consultants as needed
  • Define and standardize compliance checklists for lender onboarding; coordinate responses to audit and security questionnaires from partners
  • Maintain risk register and track remediation status; report regularly to management

5. Awareness & Reporting

  • Define and drive the security awareness program — coordinate training and secure coding sessions for the engineering team
  • Deliver regular risk, vulnerability, and remediation status reports to management
  • Serve as primary point of contact for internal and external audits

Yêu cầu công việc

Must Have

  • 3–5+ years of experience in information security with hands-on technical depth — vulnerability management, access control, log monitoring, and incident response
  • Strong understanding of common attack vectors and security controls — OWASP Top 10, CVE management, secure architecture principles
  • Experience in fintech, banking, or a regulated financial environment
  • Familiarity with at least one compliance framework — ISO 27001, PCI-DSS, or equivalent — sufficient to maintain and operate, not just document
  • Able to drive programs forward without a dedicated team — comfortable coordinating across engineering, product, and external vendors to get things done
  • Strong ownership mindset — identifies gaps proactively, drives resolution, does not wait to be told what to do

Nice To Have

  • Security teams within fintech or financial technology companies: In-house security teams at reputable banks , Reputable security service providers, Fintech security teams in Fintech companies
  • Candidates with strong hands-on technical depth in incident response, and combined with exposure to security and compliance frameworks.
  • Familiarity with AI-powered security tools — vulnerability scanning (Snyk or equivalent), threat detection, or security operations — and comfortable using LLMs to accelerate security workflows such as threat analysis, policy drafting, and reporting
  • Familiarity with GCP security tools — Cloud Audit Logs, Security Command Center, Cloud DLP
  • Experience with CI/CD security integration — SAST, DAST, dependency scanning
  • Knowledge of NĐ 13/2023 and Vietnamese regulatory requirements for financial services
  • Security certifications — CISSP, CISM, ISO 27001 Lead Implementer, or equivalent

Tại sao bạn sẽ yêu thích làm việc tại đây

At Fundiin, we believe in fostering a dynamic work environment that encourages personal and professional growth.

Empowerment and Growth:

  • We offer great autonomy, freedom to make decisions, room to take risks and learn from mistakes.
  • Get involved from the ground up in creating and developing new products, leading teams, working on innovative projects, and gaining visibility within the industry.

Competitive Benefits:

  • Enjoy a robust benefits package, including meaningful ESOP options.
  • Access our premium health care program and annual health checkup.
  • Receive a budget of 2,400,000 VND per year for professional development.
  • Take advantage of device allowances or financing options covering up to 50% of new device purchases.

Engaging Work Environment:

  • Participate in our monthly Town Hall meetings and collaborative sharing sessions.
  • 15 days of annual leave to recharge and pursue personal interests, plus an extra day for every 3 years of service.
  • Join biannual team-building trips for bonding and connections.
  • Enjoy free daily drinks and weekly TGIF snacks and beverages.

FUNDIIN - Financial Services Platform

Mô hình công ty
Sản phẩm
Lĩnh vực công ty
Dịch Vụ Tài Chính
Quy mô công ty
51-150 nhân viên
Quốc gia
Singapore
Thời gian làm việc
Thứ 2 - Thứ 6
Làm việc ngoài giờ
Không có OT

Việc làm tương tự dành cho bạn

Nhận các việc làm tương tự qua email Nhận thông báo