Cyber Security Engineer
We're looking for a hands-on security professional to help strengthen and operate enterprise defensive capabilities across a growing digital platform environment.
This position works closely with regional and local technology teams to identify, investigate, and respond to threats while continuously improving detection, monitoring, and security operations capabilities. The role spans multiple domains including endpoint protection, network controls, monitoring platforms, threat intelligence, vulnerability management, and defensive engineering.
What You'll Be Doing
-
Monitor, triage, investigate, and respond to security alerts and incidents.
-
Operate and manage security technologies including
EDR, IDS/IPS, WAF, DLP
, and related monitoring capabilities.
-
Perform vulnerability assessments and support remediation and patch management activities.
-
Implement and maintain
CIS hardening standards
across endpoints, servers, containers, network appliances, and cloud environments.
-
Participate in incident investigation, containment, recovery activities, and post-incident reviews.
-
Work closely with detection teams to improve existing use cases and develop new detection rules.
-
Leverage
threat intelligence
to improve detection, containment, and response capabilities.
-
Conduct proactive
threat hunting
activities to uncover suspicious behaviour, hidden threats, and indicators of compromise.
-
Develop automation and scripting solutions to improve operational efficiency.
-
Support periodic security governance activities including firewall reviews, account reviews, and compliance-related assessments aligned with frameworks such as
PCI DSS
,
ISO 27001
, and regulatory requirements.
What We're Looking For
Experience
-
4+ years of experience across security operations and defensive security functions.
-
Experience in production environments supporting business-critical systems.
-
Comfortable collaborating across technical and non-technical teams within regulated environments.
Technical Expertise
-
Hands-on experience with
WAF, CDN, Firewall, SIEM, EDR, and Cloud
technologies.
-
Strong understanding of
network security
, including firewalls, IDS/IPS, segmentation, and system security across Windows, Linux, virtualized, containerized, and cloud environments.
-
Experience with
SIEM & EDR
administration, log analysis, threat detection, investigation, and tuning.
-
Familiarity with
MITRE ATT&CK
and modern adversary tactics, techniques, and procedures.
-
Experience with vulnerability and patch management programs.
-
Knowledge of CIS benchmarks and hardening practices.
-
Ability to investigate suspicious files and perform basic malware analysis.
Nice to Have
-
Experience within
Banking, FinTech, or highly regulated industries
.
-
Exposure to
AWS Security
and broader cloud security practices.
-
Scripting and automation using
Python, PowerShell, or Bash
.
-
Experience with
Threat Hunting
, Detection Engineering, Security Automation, or
SOAR
platforms.
-
Industry certifications such as
Security+, CySA+, GCIA, GCIH, GCED
, or equivalent.
What Success Looks Like
-
Taking ownership of incidents from detection through resolution.
-
Maintaining composure during active security events.
-
Communicating technical findings clearly to both technical and business stakeholders.
-
Continuously improving defensive controls, detection coverage, and operational processes.
Working Arrangement
-
Hybrid work model (4 days on-site, 1 day remote)
-
Ho Chi Minh City, Vietnam
-
Competitive compensation package
-
Healthcare coverage, learning allowance, training opportunities, and additional employee benefits
Argyll Scott Asia is acting as an Employment Agency in relation to this vacancy.