Senior Security Engineer

LinkedIn|VinSmart Future|Ho Chi Minh City, Vietnam|12 Aug 2026
Apply Now →

JOB DESCRIPTION

VinSmart Future vận hành hạ tầng đa cloud trên nhiêu nền tảng: AWS, GCP,... phục vụ hệ sinh thái sản phẩm trong nước và quốc tế. Đội Security Engineering chịu trách nhiệm về bảo mật lớp hạ tầng, bao gồm cloud posture management, IAM governance, network security và ứng phó sự cố.

III. Trách Nhiệm Chính

3.1 Phối hợp trực tiếp với DevOps trong xử lý lỗ hổng bảo mật

  • Làm việc cùng DevOps engineer để phân tích nguyên nhân gốc rễ (root cause analysis) của từng security finding, xác định phạm vi ảnh hưởng và xây dựng phương án remediation phù hợp với từng môi trường.
  • Trực tiếp triển khai các thay đổi kỹ thuật: chỉnh sửa IAM policy, Security Group, bucket policy, network ACL, Kubernetes RBAC, Terraform module
  • Theo dõi và xác nhận kết quả sau remediation (validation & verification) trên môi trường staging và production; lập biên bản đóng lỗi có đầy đủ bằng chứng kỹ thuật.
  • Hỗ trợ review và hardening Dockerfile, GitLab CI/CD pipeline, Jenkins Shared Library liên quan đến cloud workload security (secret management, image signing, least privilege execution).

3.2 Đánh giá bảo mật định kỳ trên đa cloud

  • Thực hiện cloud security assessment theo CIS Benchmark và best practice của từng cloud provider (AWS Well-Architected Security Pillar, GCP Security Foundations, Huawei Cloud Security White Paper).
  • Rà soát cấu hình IAM: phân tích over-permission, cross-account trust relationship, service account key exposure, privilege escalation path.

3.3 Tự động hoá và tích hợp DevSecOps

  • Xây dựng và duy trì preventive control dưới dạng code: AWS Service Control Policy (SCP), GCP Organization Policy, Huawei Config Rule.
  • Phát triển detective control tự động: OPA/Rego policy, AWS Config custom rule, Security Command Center custom module — phát hiện sai lệch so với baseline ngay khi xuất hiện.
  • Xây dựng và duy trì dashboard bảo mật cloud, thiết lập alert threshold cho CSPM findings, GuardDuty, Security Hub, Security Command Center.

3.4 Ứng phó sự cố và phát hiện mối đe dọa

  • Điều tra security finding từ các công cụ phát hiện: AWS GuardDuty, GCP Security Command Center,...
  • Tham gia Incident Response khi có sự cố liên quan đến cloud infrastructure: phân tích log, tracing lateral movement, đánh giá blast radius, phối hợp containment.

3.5 Governance và tài liệu hoá

  • Soạn thảo và cập nhật tài liệu kiến trúc bảo mật cloud, runbook xử lý sự cố, hướng dẫn cấu hình an toàn cho từng cloud service.
  • Tham gia threat modeling cho hệ thống mới hoặc thay đổi kiến trúc lớn, đặc biệt các dự án có sử dụng managed cloud service, serverless, hoặc container platform.
  • Báo cáo định kỳ trạng thái bảo mật cloud (posture report) gửi Security Engineering Lead và các bên liên quan; theo dõi trend và đề xuất cải tiến.

IV. Yêu Cầu

4.1 Kinh nghiệm & kỹ năng bắt buộc

  • Tối thiểu 2 năm kinh nghiệm thực tế trong vai trò Cloud Security Engineer, Cloud Engineer, hoặc DevOps Engineer với trọng tâm bảo mật.
  • Có kinh nghiệm thực tế trên cac AWS, GCP,... AWS, GCP,...
  • Hiểu sâu IAM model của ít nhất một cloud provider: roles, policies, trust relationships, STS (AWS) / Workload Identity (GCP) / Service Account.
  • Có khả năng đọc, review và chỉnh sửa Terraform: hiểu resource dependency, module structure, state management.
  • Nắm vững Kubernetes security: RBAC, NetworkPolicy, Admission Controller, Pod Security Standard, secret management (External Secrets, Vault Agent).
  • Biết sử dụng ít nhất một CSPM tool: AWS Security Hub, GCP Security Command Center, hoặc third-party (Wiz, Orca, Lacework, Prisma Cloud).

4.2 Kỹ năng mở rộng (lợi thế cạnh tranh)

  • Đã viết OPA/Rego policy hoặc AWS Config custom rule trong môi trường production.
  • Kinh nghiệm cloud penetration testing: AWS privilege escalation, GCP lateral movement, metadata service exploitation.
  • Chứng chỉ chuyên ngành: AWS Security Specialty, Google Professional Cloud Security Engineer, CCSP, hoặc tương đương.