Key Responsibilities:
- Perform cybersecurity assessments and conformity evaluations for IoT, OT, and ICS products, including VAPT, code review, and threat modelling.
- Support the scoping of assessment engagements and define appropriate testing approaches based on product architecture, risk profile, and regulatory requirements.
- Support client engagements and pre-sales activities by providing input on cybersecurity, compliance, and service capabilities.
- Conduct conformity assessments, including technical evaluations and structured reviews of product documentation.
- Interpret and apply regulatory standards such as ETSI, IEC, NIST, CRA, and RED to practical assessment activities.
- Review manufacturer risk assessments, identify gaps, and assess their adequacy against applicable requirements.
- Take ownership of assigned assessment activities, proactively identify gaps, resolve issues, and drive assigned workstreams to completion.
- Troubleshoot technical challenges during hands-on assessments, including incomplete or ambiguous system conditions.
- Provide technical input and knowledge sharing within assigned projects and support team capability development.
- Contribute to the development and improvement of cybersecurity service offerings, methodologies, and technical capabilities.
- Support the translation of business and regulatory requirements into practical workflows, methodologies, and technical solutions.
- Participate in customer and external technical engagements as a technical representative.
- Collaborate with teams to ensure consistent and effective service delivery.
Key Requirements:
- Bachelor's degree in Computer Science, Information Security, Computer/Information Engineering, or a related field.
- 2–4 years of experience in cybersecurity, with exposure to IoT, OT, ICS, or product security environments.
- Experience in cybersecurity assessments and testing, including VAPT, vulnerability assessment, threat modelling, or code review.
- Experience or exposure to client-facing activities, technical advisory, assessment scoping, or pre-sales support.
- Good familiarity with cybersecurity frameworks and regulatory standards such as OWASP, NIST, MITRE, CIS, ETSI, IEC 62443, CRA, and RED.
- Understanding of risk assessment methodologies and their practical application.
- Experience or exposure to conformity assessment, certification, or regulatory compliance is an advantage.
- Ability to analyze and troubleshoot technical issues and work effectively in dynamic and evolving environments.
- Strong analytical, problem-solving, communication, and technical documentation skills.
- Ability to translate technical and regulatory requirements into practical assessment approaches.
- Experience or interest in cybersecurity service development and technical capability building is an advantage.
- Relevant certifications such as Security+, eJPT, PenTest+, CEH, CISA, or equivalent are an advantage.
Benefits:
- Working in an international dynamic and friendly environment
- 15 annual leaves, 15 paid sick leaves, Christmas leave
- 13th-month salary, bonus based on performance and business result
- Social insurance, health insurance, unemployment insurance base on full basic salary (Vietnamese Law)
- Insurance benefit package (Accident insurance 24/7, Health care insurance, Business travel insurance), annual health check
- Free parking
- Ad-hoc staff engagement events, team-building activities, company trip
- Participate in the company’s training programs, LinkedIn Learning license holder (fee supported by company base on company’s policy)