Responsibilities
- Oversee security event platforms, leverage EDR tools, and review alerts for anomalous activity, intrusion indicators, and policy violations across Windows and Linux servers to mitigate threats and protect business operations.
- Triage and investigate EDR alerts and endpoint detections, escalating confirmed incidents to US-based IT leadership and supporting containment and remediation efforts.
- Maintain and execute incident response plans and playbooks; participate in post-incident reviews and contribute to lessons-learned documentation to drive continuous improvement.
- Monitor threat intelligence advisories and convert emerging risks into actionable recommendations to help the team proactively reduce security vulnerabilities and protect operations.
- Leverage vulnerability scanning tools to perform regular assessments across a substantial server fleet running mixed Windows and Linux workloads.
- Engage with infrastructure teams to optimize patch management and software deployment workflows, enabling timely remediation of identified vulnerabilities.
- Monitor remediation progress and communicate status updates against defined SLAs and risk thresholds.
- Facilitate information sharing and response efforts with vendors and third-party partners during vulnerability disclosure exercises to support effective remediation.
- Coordinate remediation efforts with both infrastructure and application development teams, translating vulnerability findings into actionable guidance appropriate for each audience and tracking progress through to closure.
- Play a vital role in developing, maintaining, and sharing network and data security policies, standards, and procedures aligned with industry frameworks (NIST CSF, CIS Controls, or similar).
- Proactively review policies to help maintain relevance and keep ahead of changing regulatory requirements.
- Inspire a culture of security awareness across the organization by designing engaging training materials and dynamic internal communications.
- Drive the consistent enforcement of network security standards across firewalls, VPNs, segmentation, and access controls in partnership with the Senior Network Engineer and the US team.
- Conduct security reviews for new projects, system changes, and cloud migrations, ensuring guidance aligns with organizational standards.
- Embed security practices into DevOps workflows and cloud-based environments (AWS and Azure).
- Prepare weekly security reports that summarize monitoring findings, incident activity, vulnerability posture, and remediation progress for IT leadership.
- Maintain thorough documentation for security configurations, processes, runbooks, and incident records.
- Develop security metrics and KPIs to communicate the organization's risk posture over time.
Requirements
- Solid foundation in network and information security
- Experience with EDR tools and security event platforms
- Experience triaging and investigating security alerts and incidents
- Experience with vulnerability scanning and patch management
- Experience monitoring and responding to threat intelligence
- Experience maintaining incident response plans and playbooks
- Experience with security policy development and governance aligned with industry frameworks such as NIST CSF or CIS Controls
- Ability to collaborate with infrastructure and application development teams on remediation
- Experience conducting security reviews for system changes and cloud migrations
- Experience documenting security configurations, processes, and incident records
- Experience preparing security reports and metrics for leadership
Nice to Have
- Growth-oriented mindset with readiness to take on broader ownership over time
- Ability to become CES's primary security subject matter expert in the region
Work Arrangement
Remote (City/Region) — Ho Chi Minh
Additional Information
- Position based in Ho Chi Minh office
- Collaboration with co-located Senior Network Engineer
- Partnership with U.S.-based IT leadership on security priorities, escalations, and strategic initiatives
- Operating within an established security environment