Overview
Lead Security Engineer Jobs in Ho Chi Minh City, Vietnam at VinSmart Future
Title: Lead Security Engineer
Company: VinSmart Future
Location: Ho Chi Minh City, Vietnam
Senior Security Engineer, Lead – DevSecOps (RWA)
Location: Hanoi or HCMC, onsite
Language: English (working level)
About the team:
Defensive security is a part of the RWA team — Vingroup's tokenized real-world-asset platform. We partner with the central SOC team and focus on pentest defense, attack surface management, and compliance.
What you'll do:
- Own the defensive security roadmap for RWA: hardening, IaC security, ASM, vulnerability management.
- Drive remediation of pentest findings and external audit gaps to closure.
- Build and maintain secure baselines for AWS (EKS, IAM, network) and CI/CD pipelines.
- Run the on-chain ops security program: key management, multisig hygiene, deployment pipeline, RPC/node hardening (you manage external smart-contract audits, not write Solidity).
- Translate legal and regulatory requirement documents into concrete technical action items; self-audit against them and guide other team members to stay compliant.
- Translate regulatory sandbox and financial-grade control requirements into engineering work; supply evidence on request.
- Mentor other teammates; partner daily with the central SOC team, Platform, and external auditors.
Required:
- 7+ years total experience, with 4+ in DevOps/SRE/Platform and 3+ in security (overlap counts).
- Production AWS at scale (IAM, VPC, KMS, GuardDuty) and Kubernetes (EKS) hardening.
- Strong IaC (Terraform) with security scanning in CI (tfsec/Checkov/Trivy).
- Hands-on with at least one ASM/vulnerability-management program in a regulated environment.
- Track record leading pentest remediation across multiple teams.
- Proven ability to read legal/regulatory documents and convert them into technical controls and self-audit checklists.
Preferred:
- AWS Security Specialty, CKS, OSCP, or CISSP.
- Financial services, fintech, or blockchain/RWA exposure.
- Familiarity with regulatory sandbox programs, ISO 27001, or NIST CSF control mapping.
First 90 days:
- Baseline current attack surface; publish a prioritized remediation roadmap.
- Stand up an IaC + container security gate in CI/CD that blocks high-severity issues.
- Define on-call/handoff interface with the central SOC team.