Share this opportunity
Related Job
- CTV Kinh Doanh (Soundbox), Zalopaythành phố hồ chí minh
- Business Analyst - VNG Gamesthành phố hồ chí minh
- Facility Intern, Data Centerthành phố hồ chí minh
Senior Risk & Compliance Executive, Business Operations
Job description
Job Overview
The Senior Risk and Compliance Executive is primarily responsible for driving certification programs and strengthening the Group’s compliance posture. This role involves leading specific workstreams on international security standards, conducting compliance assessments, and advising stakeholders to ensure frameworks and policies are effectively implemented across the Group.
Key Responsibilities
- Lead the execution and maintenance of certification programs (ISO/IEC
27001, PCI DSS, SOC 2, etc.).
- Conduct compliance reviews, gap assessments to evaluate adherence to standards and frameworks.
- Provide advisory to business and IT teams on compliance requirements and remediation actions.
- Prepare and present risk and compliance reports for management and external auditors.
- Support the delivery of security awareness training and ad-hoc uplift programs as required.
- Contribute to
the continuous improvement of compliance processes, tools, and reporting mechanisms.
- Guide junior members in program documentation and audit readiness activities.
Requirement
- Bachelor’s degree in information security, Computer Science, or related discipline.
- 2–4 years of experience in information security compliance, IT audit, or governance. Strong knowledge of international standards and frameworks (ISO 27001, PCI DSS, SOC 2, NIST, COBIT).
- Experience in certification audits, risk assessments, and compliance reporting.
- Strong analytical, documentation, communications and stakeholder engagement skills.
- Proficient in English.
- Preferred certifications: ISO 27001 Lead Auditor/Implementer, CISA, or other security compliance credentials.
We've received your profile and we do appreciate your interest in our job opportunities. We will screen your application and contact you for further steps if you are short-listed. Otherwise, the application with no response received within 2 weeks is considered unsuitable application, and we will keep your resume in our database and may consider for appropriate future openings. Again, thank you for considering VNG as a potential employer.
