Location

Ho Chi Minh

  • Salary

    Competitive

  • Experience

    Over 3 Years

  • Job level

    Experienced (Non - Manager)

  • Deadline to apply

    31/08/2026

Benefits

  • Insurance
  • Travel
  • Incentive bonus
  • Healthcare
  • Training Scheme
  • Salary review

Job Description

Job Summary

The company is seeking a SecOps Engineer to design, implement, and operate its core security infrastructure and network security, with particular emphasis on securing and hardening the Kubernetes/container platform. This role is both hands-on and strategic: building secure-by-design infrastructure from the ground up before expanding into SOC/DFIR capability as the security baseline matures. The engineer will combine deep systems/platform expertise with security engineering judgment to close foundational gaps

Key Responsibilities

1.       Security Architecture & Infrastructure

  • Design and implement Identity & Access Management (IAM/SSO) architecture and Single Sign-On integration across internal applications.
  • Design and implement Privileged Access Management (PAM) and Zero Trust Network Access (ZTNA) / identity-aware proxy solutions.
  • Design and implement network security architecture, including segmentation, firewalls, VPN, and secure remote access.
  • Build infrastructure using Infrastructure-as-Code (Terraform, Ansible) and version-controlled configuration where applicable.

2.       Platform & Container Security

  • Support the hardening of the company's Kubernetes platform: RBAC design, network policy, workload security baseline, secrets management.
  • Contribute to the rollout of Policy-as-Code (e.g., Kyverno, OPA) for cluster governance.
  • Collaborate with the current Cluster Admin to reduce single-point-of-failure risk and support knowledge transfer / documentation.

3.       SOC Development & Operations

  • Support the design, implementation, and day-to-day operation of the company's SOC capabilities (SIEM, EDR, log management, monitoring pipelines).
  • Contribute to detection rule and alert logic development as SOC capability is built out.

4.       Threat Detection, Response & DFIR

  • Participate in security event investigation, containment, and remediation activities.
  • Contribute to DFIR playbooks, escalation paths, and evidence-handling procedures.

5.       Continuous Improvement & Collaboration

  • Assist in tabletop exercises and simulations to validate incident response readiness.
  • Collaborate with IT, InfraOps, AppSec, and Red Team functions to close security gaps.
  • Document architecture decisions, runbooks, and lessons learned.
  • Contribute to security policies, standards, and compliance initiatives (ISO 27001, etc.) incollaboration with the GRC team.

Job Requirement

We are looking for a highly motivated person with:

  • 2-3+ years of experience in security engineering, infrastructure/platform engineering, SRE, or DevSecOps.
  • Hands-on production experience operating Kubernetes — RBAC design and troubleshooting, network policy, workload/container security fundamentals.
  • Practical experience designing or implementing at least one of: IAM/SSO (e.g., Keycloak, Okta, Azure AD), PAM, ZTNA / identity-aware proxy, or network security architecture (firewall, segmentation, VPN).
  • Strong Linux system administration and scripting/automation skills (Python, Bash, PowerShell, or similar).
  • Familiarity with Infrastructure-as-Code and/or GitOps concepts (Terraform, Ansible, ArgoCD/Flux, or equivalent).
  • A proactive attitude & the ability to think outside of the box.
  • Works in an organized, structured manner; can-do attitude, gets things done.
  • Excellent communication skills with diverse audiences.
  • Strong critical thinking and analytical skills.

Nice-to-have:

  • Experience with SIEM platforms (ELK Stack, Wazuh, Splunk, Graylog) or EDR tools.
  • Foundation skills in log analysis, network traffic analysis, or malware analysis.
  • Solid understanding of security frameworks (MITRE ATT&CK, NIST CSF, CIS Benchmarks).
  • Foundation knowledge in AI integration for security operations.
  • English communication.
  • Relevant certifications: CKA/CKS, Security+, GCIA, GCIH, or equivalent.

Work location

Ho Chi Minh
Con Cưng Super Center, Đường Nguyễn Trãi, Bến Thành, Quận 1, Hồ Chí Minh

More Information

  • Degree: Bachelor
  • Age: Unlimited
  • Salary: Competitive
Feedback