VSOL provides top-notch services while strictly adhering to international standards. We remain in the public eye as experts in “the next big technologies”. VNG Solutions will provide you with a creative environment with an emphasis on B2B services, where you will have the opportunity to foster your abilities and learn about various technologies to advance your career
Responsibilities:
- Design and implement cloud security strategies, with a focus on GCP and multi-cloud environments.
- Research and apply security standards, best practices, and emerging technologies.
- Conduct vulnerability assessments, risk analysis, and security testing.
- Enhance and maintain compliance, security controls, and reporting quality.
- Promote and oversee the implementation of IT security initiatives.
- Evaluate and integrate new security tools and technologies.
- Automate tasks using Bash, PowerShell, or Python; apply DevSecOps practices where applicable.
Major Activities:
- Cloud Cybersecurity risk and compliance framework and management
- Develop and maintain GCP security architecture frameworks for new and existing solutions.
- Implement and manage cloud-native security controls (e.g., IAM, VPC, Audit Logs, Security Command Center).
- Embed security best practices through supplier evaluations and solution reviews.
- Ensure compliance with ISO 27001, SOC 2, NCA, and define risk/security requirements.
- Drive cybersecurity strategy and policy compliance across cloud environment.
- Align with audit activities and regulatory expectations; liaise with auditors and regulators.
- Identify, assess, and remediate information security risks
Policy, Standards and Processes
- Enforce and monitor execution of the Information Security Strategy and Plans.
- Ensure adherence to security processes, including risk management and operation of security tools.
- Review and approve security-related changes, including implementations and vulnerability management.
- Support internal/external audits and contribute to the IT Security Dashboard.
- Deliver IT security awareness training and produce monthly security reports.
Operations, Reporting and Administration
- Implement and oversee the Information Security Strategy and operational plans.
- Ensure adherence to security processes, including risk management and use of security tools.
- Approve and control security-related changes, including implementation and vulnerability management.
- Collaborate with internal/external audits and contribute to the security dashboard.
- Deliver security awareness training and provide expert advisory support.
- Collect, analyze, and report monthly security metrics and insights to management.