messenger

Chat Mess

zalo

Chat Zalo

phone

Phone

Gọi ngay: 097.5151.777
messenger

Facebook

messenger

TikTok

Hỗ trợ tư vấn: 097.5151.777
Techcombank

Senior Officer, Information Security (40001098)

TP. Ha Noi Technology Division
Expert

Mô tả công việc

Job Purpose

The job holder is responsible for building, managing, participating in the development of one of the following areas:

a. IS Practice: Evaluate deployment, develop security solutions/Design, test information security/Ensure compliance with security standards (of Vietnam and International)
b. IS Administration: Manage and directly participate in administrative activities on identity and access security/network security/endpoint services and data security
c. IS Engieering: Manage and directly control the implementation of information security policies and standards for applications, infrastructure of Techcombank and its partners and suppliers, ensure compliance with the Bank's information security requirements.
d. IS Red team: Manage and directly perform testing attack activities for technology systems to detect vulnerabilities/weaknesses and provide solution guidance.
e. IS Monitoring: Monitor detecting all attack events/incidents as quickly as possible (realtime) based on events aggregated from security systems as well as other technology components.Then alert relevant departments to investigate and react to that event/incident.

Key Accountabilities (1)

1. Information Security Assurance

  • Participate in projects, developing and deploying technology to ensure Information Security for systems to be built, including stages: analysis, building requirements Information security, design Information security, threat modeling, source code review, testing and building controls to ensure Information Security.
  • Research and develop necessary information security solutions to prevent attacks and incidents Information security, ensure security and safety for the entire information system of the bank.
  • Coordinate with the Information Security supervisory department in handling information security incidents.
  • Set up and monitor the implementation of TCB's information security process, regulations, standards, guidelines and policies in accordance with the regulations of the government and international organizations
  • Implement and maintain compliance with international standards PCI-DSS, ISO, SWIFT CSP.
  • Implement and maintain compliance with TCB's policies, circulars and regulations of the State Bank.
  • Regularly perform compliance and integrity checks

of the security policy configuration in the internal system TCB detects violations or insider attacks.

  • Coordinate with Compliance Assessment and Risk Management units to assess the compliance of technology systems according to policies, regulations, standards, processes, checklists.

Key Accountabilities (2)

2. Information Security Red team:

  • Implement the strategy to ensure information security:

+ Participate in the implementation of the Information Security strategy by providing input data on attack trends, forms of exploitation and risks arising in each period.
+ Participate in the implementation of the annual information security implementation plan, meet the business and operational needs of the bank through the implementation of information security testing programs for the technology activities of the bank. Bank.
+ Develop penetration testing methods, information security scanning scripts and security checks according to international standards such as OSSTMM, Sans and OWASP.
+ Develop new techniques, exploit scripts and programs for automated penetration testing

  • Perform test attack activities:

+ Directly perform vulnerability detection review, vulnerability assessment, and conduct penetration/exploit testing periodically or at the request of the Block leader for all systems/applications ; Penetration testing for system/application after live detection or whenever undergoing a major change. Testing methods must ensure practicality including both technical (technology) and non-technical (people, processes, physical assets). From there, provide CISO as well as other Information Security departments to have programs to deal with the problems of system weaknesses that can be exploited.
+ Perform regular vulnerability scans, information security checks to find vulnerabilities in the system and provide remedial / remedial solutions; supports maintaining compliance with world security standards such as PCI-DSS, ISO27001, SCP (swift).
+ Develop and manage vulnerability management program, threat intelligence database. Collect, track metrics, and analyze trends on cyber defenses, threats, detected attacks, vulnerabilities, and countermeasures/preventions.
+ Actively research / find new vulnerabilities, exploitation techniques and cyber threats; Identify trends in cybersecurity involving tactics, techniques, and processes, targeting for malware development and deployment.
+ Directly participate in the experimental plan of responding to an Information Security incident as an attack unit and in the case of an actual Information Security incident as the response team. Coordinate and provide expert cyber defense engineering skills to resolve cyber attack incidents

Key Accountabilities (3)

3. Information Security Administration

  • Building/adjusting and implementing MTPQ of systems.
  • Develop requirements and measures to control access and protect the bank's data.
  • Develop, maintain and optimize information security policy/rule/configuration for solutions to ensure information security such as: Information security solutions on access identity management (PAM, IAM…); Network information security solutions (Firewall, NAC, APT, NetIPS, DDOS...); Information Security solutions on endpoints (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security…); Information security solutions on data (DLP, FAM...).
  • Assess, evaluate, review:

+ Decentralization enforcement ensures compliance with the decentralized matrix.
+ The issue and withdrawal of privileged accounts and digital certificates on technology systems.
+ Exception requirements related to identity, access rights on technology systems
+ Change requirements on information security assurance solutions.

  • Risk management and compliance

+ Identify risks of the department in the process of operation, ensuring compliance with the processes and regulations of the bank. Coordinate with relevant units to handle risks.
+ Perform risk treatment activities according to reports of internal/external audit departments.

Key Relationships - Direct Manager

Senior Mangaer, Manager, Information Security

Key Relationships - Direct Reports

No

Key Relationships - Internal Stakeholders

Departments in the divisions

Key Relationships - External Stakeholders

Information security solutions/services companies, quick incident response organizations…etc.

Success Profile - Qualification and Experiences

Qualification:

  • Graduated in IT, Computer Science or Telecommunications
  • Foreign language: English: Level 1 – TOEIC under 550
  • Certificates in information security such as OSCP, PCI DSS assessment implementation certificate, ISO
  • Having ISC2 SSCP security certificates is an advantage
  • Having certificates of companies providing security solutions such as Microsoft/Cisco/PaloAlto/Checkpoint/Cyberark/Sailpoint…”
  • Having certificates in information security such as - SANS SEC660, SEC760, SANS SEC642, SANS SEC575, OSCE, OSCP

Experience:

  • Experience in performing security testing in financial / service / telecommunications organizations from 5 years. The experience includes the following aspects:

+ Research, design, implement and evaluate Information security for systems and applications
+ Implement PCI-DSS, ISO, Swift CSP... Participate in the development and control of compliance with security standards for IT systems

  • Experience in performing security testing in financial / service / telecommunications organizations. The experience includes the following aspects:

+ Experience in researching security holes, developing attack techniques/tools, performing attack testing of technology systems by technical and non-technical measures)

  • Having experience in implementing, managing, and operating in-depth in terms of policies, set of rules, configuration of information security at least one of the following areas at financial/service/telecommunications organizations (5 years):
  • Security solutions for access identity management (PAM, IAM...);
  • Network security solutions (Firewall, NAC, APT, NetIPS, DDOS...);
  • Security solutions for terminals (AD GPO, HIPS/HFW, Appcontrol, Web/mail filtering, DB security...);
  • Data security solutions (DLP, FAM...).
  • Experience in information security assessment according to Agile method"

Phân tích kỹ năng cần có

Phân tích kỹ năng — Senior Officer, Information Security @ Techcombank

Vị trí này là Senior Officer trong khối Công nghệ, thuộc nhóm Information Security (IS). Đây là vị trí chuyên gia (specialist/individual contributor) — không quản lý nhân viên nhưng đòi hỏi kinh nghiệm thực chiến 5+ năm. Techcombank chia thành 5 streams và ứng viên sẽ chuyên sâu vào một trong các lĩnh vực sau:

---

🔐 1. Hard Skills theo từng stream

Stream Kỹ năng cốt lõi Công nghệ/Công cụ tiêu biểu
IS Practice Threat modeling, secure SDLC, source code review, security testing OWASP SAMM, STRIDE, PASTA, SonarQube, Veracode, Burp Suite
IS Administration Identity & Access governance, PAM, network security, endpoint, DLP CyberArk, SailPoint, Okta, Palo Alto Firewall, Cisco ASA, Fortinet, TippingPoint, Splunk, Symantec DLP
IS Engineering Security architecture, policy enforcement, vendor compliance ISO 27001, NIST CSF, PCI-DSS, SWIFT CSP, CIS Benchmarks
IS Red Team Pentest, exploit dev, vulnerability research, red team ops Kali, Metasploit, Cobalt Strike, Burp Pro, OSSTMM, OWASP, SANS methodologies
IS Monitoring SOC, SIEM, incident response, threat detection Splunk, QRadar, Elastic, MISP, MITRE ATT&CK, YARA

---

📜 2. Chứng chỉ quan trọng (theo mức ưu tiên)

Nhóm BẮT BUỘC/Ưu tiên cao (nên có ít nhất 1-2):
Chứng chỉ Phù hợp stream Độ khó Ghi chú
OSCP (Offensive Security Certified Professional) Red Team ⭐⭐⭐⭐⭐ "Vàng" cho pentester, rất được TCB đánh giá cao
OSCE Red Team ⭐⭐⭐⭐⭐ Cao hơn OSCP, chứng minh exploit dev
CISSP / SSCP (ISC2) Practice/Admin ⭐⭐⭐⭐ SSCP là yêu cầu lợi thế, CISSP là đỉnh cao
ISO 27001 Lead Implementer/Auditor Practice/Engineering ⭐⭐⭐ Cần thiết nếu làm compliance
PCI-DSS QSA/ISA Practice/Engineering ⭐⭐⭐⭐ Rất giá trị với ngân hàng (TCB có thẻ quốc tế)
SWIFT CSP Engineering ⭐⭐ Bắt buộc nếu làm việc với SWIFT
Nhóm lợi thế cạnh tranh:
Vendor Cert Áp dụng cho Stream
PCNSE (Palo Alto) Network Security Admin/Engineering
CCNP/CCIE Security (Cisco) Network Security Admin/Engineering
CCSA/CCSE (Check Point) Network Security Admin/Engineering
CyberArk CDE/PAM Privileged Access Admin
SailPoint IdentityNow IAM Admin
Microsoft SC-200/SC-100 Cloud/SOC Monitoring
SANS SEC660/SEC760/SEC642/SEC575 Advanced Pentest/Web/Cloud Red Team

---

🗣️ 3. Soft Skills

  • Communication: Phối hợp với nhiều phòng ban (Risk, Compliance, IT, Business) — phải giải thích được vấn đề kỹ thuật cho người không chuyên.
  • Analytical thinking: Phân tích threat, đánh giá rủi ro, threat modeling.
  • Ownership & Accountability: Senior Officer chịu trách nhiệm trực tiếp về kết quả security testing/policy.
  • Continuous learning: Lĩnh vực security thay đổi từng ngày — cần tự update CVE, threat intel.
  • English: JD ghi TOEIC "dưới 550" — nhiều khả năng đây là lỗi đánh máy và yêu cầu thực tế là ≥550 hoặc ≥600. Tài liệu kỹ thuật (NIST, OWASP, SANS) đều tiếng Anh, cộng thêm làm việc với vendor quốc tế.

---

🎓 4. Bằng cấp nền tảng

  • Tốt nghiệp ĐH chuyên ngành CNTT, Khoa học Máy tính, Viễn thông, An toàn thông tin.
  • Ưu tiên từ các trường: HUST (BK), PTIT, UET, HCMUS, hoặc ĐH có chương trình đào tạo Security (như MMU, FPTU).

---

📊 Bảng tóm tắt "Mức độ sẵn sàng" cho ứng viên

Tiêu chí Tối thiểu Nên có Lý tưởng
Kinh nghiệm 3 năm security 5 năm (đúng yêu cầu) 7+ năm ở ngân hàng/Telecom
Chứng chỉ 1 cert vendor OSCP hoặc ISO 27001 2-3 cert: OSCP + ISO + CISSP
Kiến thức PCI/SWIFT Biết khái niệm Triển khai 1 dự án Audit/QSA
Pentest Dùng tool Tự viết exploit Cobalt Strike custom
Lương kỳ vọng $1,500-2,000 $2,000-3,500 $3,500-5,000+ (Senior 5y+ ngân hàng)

Chuẩn bị phỏng vấn

Hướng dẫn phỏng vấn — Senior Officer, Information Security @ Techcombank

📋 Quy trình tuyển dụng TCB (thường áp dụng cho vị trí Senior)

Techcombank có quy trình 4-5 vòng chuẩn cho vị trí công nghệ cấp Senior:

Vòng Hình thức Người phỏng vấn Thời lượng Mục đích
1. HR Screen Phone/Video Talent Acquisition 20-30 phút Lý lịch, mức lương, basic fit
2. Technical Test Online/Onsite Hiring Manager 60-90 phút Kiến thức kỹ thuật nền tảng
3. Technical Deep-dive Onsite Hiring Manager + Senior team 60-90 phút Case study, scenario handling
4. Manager Round Onsite Division Manager (CISO hoặc Senior Manager) 45-60 phút Strategic thinking, culture fit
5. Final/HR Offer Onsite/Phone HRBP 20-30 phút Đàm phán lương, benefit

---

🎤 Câu hỏi hay gặp theo từng vòng

Vòng 1 — HR Screen
  • Bạn biết gì về Techcombank? (Ôn: lịch sử, chiến lược chuyển đổi số, dự án cloud, hợp tác AWS, sản phẩm nổi bật)
  • Vì sao rời đơn vị cũ / muốn vào TCB?
  • Mức lương hiện tại và kỳ vọng? (TCB thường deal dựa trên % tăng, chuẩn bị con số thực tế)
  • Availability đi làm?
Vòng 2 — Technical Test (câu hỏi kỹ thuật nền tảng)
  • Network Security: Phân biệt IDS vs IPS, Stateful vs Stateless firewall, mô tả cách xử lý một packet đi qua Palo Alto Firewall.
  • Cryptography: Phân biệt symmetric vs asymmetric, giải thích TLS handshake, điểm yếu của MD5/SHA-1.
  • Web Security: OWASP Top 10 2021 — giải thích chi tiết 3 lỗ hổng (SQLi, XSS, IDOR, SSRF). Cách khai thác và remediation.
  • Pentest: Quy trình pentest theo PTES/OSSTMM, khi nào dùng black-box vs grey-box vs white-box.
  • IAM/PAM: So sánh RBAC vs ABAC, cách thiết kế least privilege, CyberArk vault hoạt động thế nào.
  • Compliance: Khác nhau giữa ISO 27001, PCI-DSS, NIST CSF, SWIFT CSP. TCB tuân thủ những chuẩn nào?
  • Incident Response: Các bước theo NIST IR (Preparation → Detection → Containment → Eradication → Recovery → Lessons Learned).
  • Linux/Windows: Đọc log, dùng command cơ bản, hardening OS.
Vòng 3 — Technical Deep-dive / Case Study
  • Cho một scenario: "Một email phishing được gửi cho nhân viên TCB, sau đó phát hiện có traffic bất thường ra ngoài từ workstation. Bạn là Senior IS Officer, bạn xử lý từng bước thế nào?"
  • Cho một design challenge: "Thiết kế kiến trúc IAM cho 20,000 users, bao gồm nhân viên + đối tác + khách hàng doanh nghiệp. Đề xuất giải pháp."
  • Cho một policy review: "Review một bộ firewall rules và chỉ ra những rule nguy hiểm (any-any, outdated services, shadow rules...)"
  • Cho một pentest report: "Đây là kết quả pentest có 12 findings, bạn phân loại severity và đề xuất remediation plan trong 30 ngày thế nào?"
  • Câu hỏi Agile security: Bạn đã làm security assessment trong môi trường Agile/Scrum như thế nào? (JD có đề cập Agile method)
Vòng 4 — Manager Round (Senior Manager / CISO)
  • Tầm nhìn security 3-5 năm tới, đặc biệt trong cloud transformation của TCB?
  • Kinh nghiệm xử lý sự cố lớn nhất bạn từng tham gia? (CISO TCB muốn nghe real story)
  • Nếu được chọn stream (Practice/Admin/Engineering/Red Team/Monitoring), bạn chọn cái nào và vì sao?
  • TCB đang chuyển sang cloud (AWS partnership), bạn có kinh nghiệm cloud security (AWS Security Specialty, Azure SC-200) không?
  • Cách quản lý rủi ro khi business yêu cầu go-live nhanh nhưng security chưa review xong?

---

💡 Tips chuẩn bị

1. Ôn lại CV thật kỹ — Manager TCB sẽ đào sâu từng dự án, đặc biệt là dự án có số liệu (số lượng system, user, budget, số finding xử lý).
2. Show impact, không show effort: "Tôi đã xử lý 200 findings, giảm 40% high-risk trong 6 tháng" thay vì "Tôi đã làm nhiều việc".
3. Nghiên cứu TCB trước: Đọc bài viết về Techcombank + AWS, chiến lược "AI-first banking", Techcombank Mobile app, thương vụ Masan/Vinamilk partnership — để hiểu bối cảnh business.
4. Mang theo portfolio: Demo pentest report (ẩn thông tin nhạy cảm), diagram kiến trúc security bạn đã thiết kế, list chứng chỉ.
5. Chuẩn bị câu hỏi cho interviewer:

  • "Hiện tại team IS của TCB đang mature ở stream nào nhất?"
  • "Roadmap security của TCB trong 12 tháng tới là gì?"
  • "Budget cho training & certification có được support không?"

---

👔 Dress Code

  • Vòng HR / Online: Smart casual (sơ mi + quần tây, không cần vest).
  • Vòng onsite / Manager: Business formal (vest + sơ mi, giày tây). Techcombank culture khá formal cho vòng quyết định.
  • Tóc gọn gàng, không đeo trang sức quá nổi bật.

Lộ trình ôn thi

Lộ trình ôn tập 2 tuần cho Senior Officer, Information Security @ Techcombank

🎯 Nguyên tắc: Đừng học lan man — target đúng JD

Vị trí Senior IS ở TCB rất rộng (5 streams), nên bạn cần chọn 1-2 streams chính mình mạnh nhất rồi ôn sâu. Vòng phỏng vấn cho phép bạn nói rõ: "Tôi chuyên sâu về Red Team và Practice, với 5 năm kinh nghiệm ở [tên ngân hàng/telecom]".

---

📅 Lộ trình 14 ngày

Ngày 1-3: Nền tảng bắt buộc (mọi stream)
Chủ đề Tài liệu Thời gian
Network Security fundamentals "Network Security: PRIVATE Communication in a PUBLIC World" (Kaufman), CCNA Security syllabus 3h/ngày
Cryptography cơ bản "Cryptography Engineering" (Ferguson), Khan Academy crypto 2h/ngày
OWASP Top 10 (2021) owasp.org/Top10, "Web Hacking 101" (Peter Yaworski miễn phí) 2h/ngày
Linux/Windows hardening CIS Benchmarks, Lin.Security (GitHub) 1h/ngày
Ngày 4-7: Chuyên sâu theo stream (chọn 1-2)

Nếu chọn Red Team / Pentest:

  • Tài liệu: TryHackMe (Offensive Pentesting path), HackTheBox academy, PortSwigger Web Security Academy (free, rất tốt)
  • Sách: "The Web Application Hacker's Handbook" (Stuttard), "Hacking: The Art of Exploitation" (Erickson)
  • Lab: OSCP-style practice (Proving Grounds OffSec)
  • Ôn đặc biệt: Buffer overflow, SQLi blind/time-based, XSS filter bypass, JWT attack, SSRF, deserialization

Nếu chọn IS Administration / Engineering:

  • Đọc whitepaper Palo Alto Firewall, CyberArk PAM architecture, SailPoint IdentityNow
  • Thực hành: Cài thử Splunk/Elastic SIEM trong lab
  • Compliance: Đọc tóm tắt PCI-DSS v4.0 (32 yêu cầu), ISO 27001:2022 Annex A (93 controls), SWIFT CSP 2024
  • Công cụ: Nessus, Qualys, OpenVAS

Nếu chọn IS Monitoring:

  • Học Splunk (free version), ELK Stack
  • Đọc MITRE ATT&CK Framework (attack.mitre.org)
  • Thực hành: Parse log Apache, detect brute-force, phân tích PCAP bằng Wireshark
Ngày 8-10: Compliance & ngân hàng
  • PCI-DSS v4.0: Ôn 12 yêu cầu chính, focus network segmentation, encryption, logging
  • ISO 27001:2022: Đọc Annex A, ôn risk treatment plan
  • SWIFT CSP: 3 mandatory + 2 advisory controls
  • Luật An toàn thông tin Việt Nam: Nghị định 13/2023/NĐ-CP về bảo vệ dữ liệu cá nhân, Thông tư 17/2024/TT-NHNN của NHNN
  • Circular 13/2018/TT-NHNN về quản lý rủi ro công nghệ ngân hàng
Ngày 11-12: Case study & scenario
  • Luyện trả lời các case study thực tế:
  • "Ngân hàng bị ransomware, phải làm gì trong 24h đầu?"
  • "Phát hiện insider trade data, cách điều tra?"
  • "Triển khai Zero Trust cho 10,000 endpoint trong 6 tháng"
  • Đọc report: Verizon DBIR 2024, IBM Cost of Data Breach 2024 (để có số liệu trong phỏng vấn)
Ngày 13-14: Mock interview & polish
  • Tự mock phỏng vấn với timer, 60 phút
  • Review CV: Mỗi dự án phải có (1) vấn đề (2) cách làm (3) kết quả có số liệu
  • Chuẩn bị "cheat sheet" 1 trang A4 tóm tắt điểm mạnh

---

📚 Top 10 tài liệu tham khảo ưu tiên

# Tài liệu Free? Mức ưu tiên
1 OWASP Top 10 2021 + Web Security Testing Guide ⭐⭐⭐⭐⭐
2 PortSwigger Web Security Academy ⭐⭐⭐⭐⭐
3 TryHackMe Offensive Pentesting path Free + Premium ⭐⭐⭐⭐⭐
4 NIST CSF 2.0 (Feb 2024) ⭐⭐⭐⭐
5 MITRE ATT&CK + D3FEND ⭐⭐⭐⭐
6 PCI-DSS v4.0 Quick Reference ⭐⭐⭐⭐
7 Splunk Security Use Cases ⭐⭐⭐
8 "Hacking Exposed 7" (web/network) Sách ⭐⭐⭐⭐
9 "Penetration Testing" (Georgia Weidman) Sách ⭐⭐⭐⭐
10 Verizon DBIR + SANS Threat Reports ⭐⭐⭐

---

🌐 Resources miễn phí cho tiếng Anh kỹ thuật

  • Xem các video NahamSec, John Hammond, IppSec trên YouTube — vừa học pentest vừa luyện tai nghe tiếng Anh kỹ thuật.
  • Đọc blog PortSwigger Research, NCC Group Research, Google Project Zero — toàn bằng tiếng Anh chuyên ngành.

---

⚡ Lưu ý quan trọng

  • Không nên học hết tất cả streams — chọn 1 stream chính + 1 stream phụ, ôn sâu thay vì ôn rộng.
  • JD ghi "5 năm" — nếu bạn mới có 3-4 năm, vẫn có thể apply nếu portfolio dự án tốt; TCB đánh giá chất hơn số năm.
  • Nếu không có cert quốc tế, bạn có thể compensate bằng: (1) write-up trên blog cá nhân, (2) project cá nhân trên GitHub (về security tool, lab setup), (3) CVE finding (nếu có).

Tư vấn nghề nghiệp

Lời khuyên sự nghiệp — Senior Officer, Information Security

🚀 Lộ trình thăng tiến trong ngân hàng

Vị trí Senior Officer nằm ở tầng giữa của career path tại TCB. Dưới đây là typical progression cho track chuyên gia (Individual Contributor - IC) và track quản lý:

```
┌─────────────────────────┐
│ Director / CISO │ ← C-level
└─────────────────────────┘

┌─────────────────────────┐
│ Senior Manager / VP │ ← Lãnh đạo cấp cao
└─────────────────────────┘

┌─────────────────────────┐
│ Manager │ ← Quản lý nhóm (3-10 người)
└─────────────────────────┘

┌─────────────────────┴─────────────────────┐
│ │
┌────────────────────┐ ┌──────────────────────┐
│ Senior Officer │ ← BẠN Ở ĐÂY │ Senior Specialist │ ← Track IC sâu
└────────────────────┘ └──────────────────────┘
▲ ▲
┌────────────────────┐ ┌──────────────────────┐
│ Officer │ │ Specialist │
└────────────────────┘ └──────────────────────┘

┌────────────────────┐
│ Officer/Associate │
└────────────────────┘
```

Tại Techcombank, Senior Officer thường mất 3-5 năm để lên Manager nếu thể hiện tốt. Track IC sâu (Senior Specialist) phù hợp với người thích kỹ thuật không muốn quản lý.

---

💰 Mức lương kỳ vọng theo cấp bậc (TCB + thị trường ngân hàng Việt Nam 2024-2025)

> ⚠️ Lưu ý: Con số là ước tính từ thị trường. Lương TCB thường cạnh tranh top 2-3 trong nhóm ngân hàng tư nhân (cùng VPBank, MBB, ACB).

Cấp bậc Kinh nghiệm Mức lương gross (VND) Mức lương USD (gross)
Officer 1-3 năm 18-30 triệu $750-1,200
Senior Officer 4-6 năm 30-55 triệu $1,200-2,200
Senior Officer (top tier, có OSCP/CISSP) 5-7 năm 55-80 triệu $2,200-3,300
Manager 7-10 năm 70-130 triệu $3,000-5,500
Senior Manager 10-15 năm 130-250 triệu $5,500-10,000
CISO/Director 15+ năm 250-500 triệu+ $10,000-20,000+

Các khoản phụ cấp thường có ở TCB (theo chia sẻ thị trường):

  • 13th month salary (tháng lương thứ 13)
  • Performance bonus (Tết Âm lịch, thường 1-3 tháng lương)
  • Lunch allowance ~1 triệu/tháng
  • Premium health insurance (PVI/Bảo Việt gói cao cấp)
  • Wellness budget (phí gym, English class)
  • Teambuilding budget

---

🎯 Kỹ năng cần phát triển thêm để lên Manager

Nếu mục tiêu của bạn trong 3 năm tới là Manager Information Security tại TCB hoặc ngân hàng lớn tương đương:

Kỹ năng cứng (Hard skills)

1. Lấy thêm 1-2 cert quan trọng:

  • CISSP (nếu chưa có) — "hộ chiếu" vào management
  • CISM (Certified Information Security Manager) — chuyên cho quản lý
  • CRISC nếu muốn sang track GRC/risk

2. Cloud Security: TCB chuyển sang cloud (AWS partnership) — lấy AWS Security Specialty hoặc Azure SC-100 để tăng giá trị.

3. GRC (Governance, Risk, Compliance): Hiểu sâu ISO 27001 ISMS, NIST RMF, risk register, treatment plan.

4. AI Security & DevSecOps: Xu hướng 2024-2026, đặc biệt với TCB có chiến lược AI-first.

Kỹ năng mềm (Soft skills)

1. Stakeholder management: TCB có cỡ ~20,000 nhân viên, làm Senior Officer là phải giao tiếp với Manager các phòng ban.
2. Project management: Đã lead ít nhất 2-3 dự án security end-to-end.
3. People mentoring: Bắt đầu mentor Officer mới vào.
4. Business acumen: Hiểu banking product (thẻ, lending, payment), không chỉ tech.
5. Public speaking / Presentation: Trình bày security report cho Ban lãnh đạo.

---

🔄 Cơ hội chuyển ngang

Nếu muốn "nhảy" sang:

Hướng Lương tăng Lương cùng Đánh đổi
VCBS, Vietcombank, BIDV +10-20% Yếu tố thương hiệu NHNN, ổn định Có thể giảm bonus
Big4 (EY, PwC, Deloitte, KPMG) +20-40% Làm security audit/consulting Cường độ cao, travel nhiều
FPT, VinAI, KMS +20-30% Cloud, AI security Mất "ngân hàng" trong CV
Tech Big Tech (Google, Microsoft VN, AWS) +50-100% Làm security cho cloud platform Khó vào, cần nhiều CV/portfolio
Singapore/HK banks (DBS, HSBC, Standard Chartered) +100-200% (USD) Đỉnh cao career Visa, relocation, work-life balance

---

💎 Lời khuyên thực tế

1. Đừng nhảy việc quá sớm — Senior Officer là vị trí cần ổn định 3-4 năm để build track record. Nếu bạn nhảy mỗi 1-2 năm, recruiter sẽ flag.

2. Build personal brand — Viết blog (tiếng Việt + tiếng Anh) về case study, tham gia cộng đồng VietSec, VCS Cybersec, Viettel Cyber Security. Đây là "hidden" advantage khi deal lương.

3. Luôn có "next cert" trong roadmap — Cert chỉ có giá trị nếu bạn dùng kiến thức thực tế. Đừng lấy cert chỉ để khoe.

4. Networking nội bộ cũng quan trọng — TCB có cộng đồng tech nội bộ, tham gia brown bag, tech talk để được nhớ tới bởi các quản lý cấp cao.

5. Work-life balance — Cỡ TCB/MBB/VPBank thường work 45-50h/tuần, có on-call cho SOC. Cân nhắc nếu bạn cần thời gian cho gia đình.

6. Lương thỏa thuận là một tín hiệu tốt — TCB không public range, nghĩa là họ sẵn sàng negotiate. Đừng "lowball" mình; đưa ra con số dựa trên research (đã làm ở mục trên).

Câu hỏi thường gặp

Em mới ra trường ngành An toàn thông tin, chưa có 5 năm kinh nghiệm thì có nên apply vị trí Senior Officer này không?

Không nên apply trực tiếp Senior Officer. Vị trí này yêu cầu 5 năm kinh nghiệm thực chiến ở tổ chức tài chính/dịch vụ/telecom, và đã từng làm compliance PCI-DSS/ISO/SWIFT. Em nên target các vị trí Officer / Junior trong cùng khối IS của TCB hoặc các ngân hàng khác trước (VPBank, MBB, ACB). Trong 3-4 năm đầu, em tập trung: (1) Lấy 1 cert nền tảng như CompTIA Security+ hoặc eJPT, (2) Làm 1-2 dự án security thực tế (có thể là bên vendor security, SOC công ty an ninh mạng như Viettel Cyber Security, VNPT ISC, FPT IS), (3) Build lab cá nhân trên TryHackMe/HackTheBox, (4) Viết blog chia sẻ kiến thức. Sau 3-5 năm, khi đã đủ "depth", quay lại apply Senior Officer sẽ tự tin hơn rất nhiều. Apply vội vào Senior khi chưa đủ kinh nghiệm dễ bị reject ở vòng technical và ảnh hưởng brand với TCB.

Mức lương cho vị trí Senior Officer Information Security tại Techcombank khoảng bao nhiêu? Thỏa thuận thì đàm phán thế nào?

Theo thị trường 2024-2025, Senior Officer IS ở ngân hàng top (TCB, VPBank, MBB) dao động 30-55 triệu gross cho người 5 năm kinh nghiệm. Có OSCP/CISSP và làm ở fintech/big tech trước đó có thể đẩy lên 55-80 triệu. Khi JD ghi "Thỏa thuận", bạn nên: (1) Research trên các nguồn như VietnamWorks, ITviec, các group Facebook lương ngân hàng, (2) Đưa ra con số range chứ không fix cứng — ví dụ "Tôi kỳ vọng 50-65 triệu gross tùy package", (3) Đừng nói lương hiện tại thấp hơn nhiều vì TCB sẽ anchor vào đó. Tips: TCB thường offer 13-14 tháng lương (gồm tháng 13 + bonus Tết), cộng premium insurance, nên tổng package có thể cao hơn gross monthly 20-30%.

Tôi đang làm ở công ty an ninh mạng (vendor) 5 năm, muốn chuyển sang làm in-house ngân hàng. Có khó không và cần chuẩn bị gì?

Hoàn toàn khả thi và là hướng đi phổ biến. Nhiều Senior IS ở TCB/VPBank/MBB đến từ các vendor như Viettel Cyber Security, FPT IS, VNPT ISC, Kaspersky VN, Fortinet VN, Palo Alto VN. Lợi thế của bạn khi đến từ vendor: (1) Hiểu sâu sản phẩm, (2) Có quan hệ với vendor khác, (3) Đã từng xử lý nhiều case thực tế đa dạng ngành. Tuy nhiên cần chuẩn bị thêm: (1) Hiểu compliance ngân hàng (PCI-DSS, SWIFT CSP, Thông tư 17/2024 của NHNN) — vendor thường chỉ biết technical, ít phải đụng compliance. (2) Business context: Ngân hàng có app mobile, internet banking, thẻ, lending — khác với pentest cho ecommerce hay SaaS. (3) Process và governance: Môi trường ngân hàng nặng về policy, audit, approval — bạn sẽ phải làm việc với Risk, Compliance, Audit nhiều. (4) Tốc độ release chậm hơn vendor — đây là điều nhiều bạn từ vendor sang ngân hàng "sốc" nhất. Trong phỏng vấn, hãy nhấn mạnh kinh nghiệm end-to-end project chứ không chỉ "tôi biết tool X".

JD này có 5 stream (Practice, Admin, Engineering, Red Team, Monitoring), tôi chỉ giỏi Red Team thì có hợp không?

Hoàn toàn hợp. TCB thường tuyển riêng cho từng stream, không bắt buộc ứng viên giỏi cả 5. Tuy nhiên bạn cần hiểu: Red Team ở ngân hàng khác Red Team ở vendor/security firm. Ở ngân hàng in-house: (1) Bạn sẽ pentest hệ thống nội bộ của TCB + vendor/partner (đôi khi có NDA rất chặt), (2) Kết quả pentest bạn tìm được phải báo cáo cho CISO + đề xuất remediation plan, không phải chỉ gửi report xong rồi qua case khác. (3) Đặc biệt ở ngân hàng, Red Team phải phối hợp với Blue Team (SOC) để cải thiện detection — nên bạn cần hiểu cả SOC/SIEM ở mức cơ bản. Khi apply Red Team ở TCB, focus vào: OSCP/OSCE cert, write-up public (blog/personal GitHub), kinh nghiệm pentest hệ thống payment/banking nếu có, và show rằng bạn hiểu cả 2 phía (offense + defense).

Tôi đang ở vị trí Officer, làm 3 năm tại ngân hàng khác. Cơ hội apply Senior Officer ở TCB có cao không?

Cơ hội trung bình, không cao nhưng cũng không phải không có. JD yêu cầu "5 năm" nhưng TCB đánh giá chất hơn số. Nếu bạn đã: (1) Làm ở ngân hàng tên tuổi (VCBS, BIDV, MBB, VPBank, ACB...), (2) Có cert (OSCP, CISSP, ISO 27001), (3) Chứng minh được impact qua số liệu (ví dụ: "đã giảm 40% high-risk findings trong 12 tháng", "triển khai SIEM cho 5000 endpoint"), (4) Có sự ủng hộ của quản lý hiện tại (reference letter), thì hoàn toàn có thể được consider. Tuy nhiên, có rủi ro: nếu TCB tuyển Senior nhưng bạn mới ở level Officer, lương có thể không tăng nhiều và bạn sẽ bị "stretch" trong performance review đầu tiên. Lời khuyên: Nếu chưa đủ confidence, apply vào các vị trí Officer / Senior Officer cấp thấp ở TCB trước, hoặc target các ngân hàng nhỏ hơn để có "Senior" title, sau 1-2 năm quay lại TCB ở level cao hơn.

Công việc IS ở ngân hàng có áp lực / on-call nhiều không? Work-life balance ra sao?

Phải nói thật: Áp lực khá cao, đặc biệt ở TCB vì là ngân hàng top với 20,000+ nhân viên và khách hàng hàng chục triệu. Cụ thể: (1) On-call: SOC team (stream Monitoring) thường xuyên on-call 24/7 theo rotation, có thể 1 tuần/tháng. Red Team thì ít on-call hơn nhưng khi có incident lớn phải tham gia response. (2) Audit pressure: Ngân hàng bị audit trong/ngoài liên tục (NHNN, SWIFT, PCI-DSS QSA), nên IS team lúc nào cũng trong trạng thái "sẵn sàng đón đoàn". (3) Work hours: Trung bình 9-10h/ngày (8h30-18h hoặc 9h-19h), có tuần cao điểm lên 12h. (4) Weekend: Hiếm nhưng có thể xảy ra khi có sự cố hoặc audit ngay cuối năm. So sánh với: VPBank/MBB/ACB tương tự; BIDV/VCBS nhà nước nhẹ hơn nhưng lương thấp hơn; Fintech (MoMo, ZaloPay, VNPay) áp lực cao tương đương nhưng bonus có thể cao hơn. Nếu bạn cần work-life balance tốt, có thể cân nhắc làm ở Big4 (audit security) hoặc vendor với dự án 9-6.

Nếu tôi được nhận, sau 1 năm ở TCB thì cần làm gì để tạo ấn tượng tốt và chuẩn bị cho lộ trình Manager?

Sau 1 năm ở vị trí Senior Officer IS, bạn nên đạt được: (1) Deliver ít nhất 2 dự án lớn end-to-end (ví dụ: roll-out PAM cho 1000 tài khoản privileged; hoặc pentest toàn bộ mobile app + báo cáo cho CISO). (2) Lấy thêm 1 cert quan trọng (OSCP nếu Red Team, CISSP nếu muốn Manager, AWS Security Specialty nếu cloud). (3) Xây dựng network nội bộ: Tham gia brown bag, kết nối với Manager các phòng IT, Risk, Compliance. (4) Được nhắc tên trong các quyết định cross-team — tức là không chỉ làm trong team IS mà được consult các team khác. (5) Có "win" cá nhân để kể trong performance review: bắt được 1 critical bug, ngăn chặn 1 cuộc tấn công, tiết kiệm chi phí license X tỷ. Để chuẩn bị cho Manager: Bắt đầu mentoring Officer mới, đề xuất initiative mới cho team (không phải chờ Manager giao), học soft skills qua các khóa như stakeholder management, presentation cho c-level. Sau 2-3 năm Senior Officer với track record tốt, bạn có thể apply Manager role ở TCB hoặc nhảy sang ngân hàng khác lên Manager.

OSCP có thực sự cần thiết không, hay chỉ là "nice to have"? Tôi có kinh nghiệm 5 năm nhưng chưa có cert này.

OSCP với vị trí Red Team ở TCB là gần như bắt buộc, không phải nice to have. Đây là JD nói rõ "Certificates in information security such as OSCP". Tuy nhiên nếu bạn ở các stream khác (Admin, Engineering, Monitoring), OSCP không cần thiết, cert phù hợp hơn sẽ là: CyberArk (Admin), CCSP/ISO 27001 (Engineering), Splunk/Elastic cert (Monitoring). Nếu bạn apply stream Red Team mà không có OSCP, khả năng cao sẽ bị HR loại ở vòng đầu. Workaround: (1) Đăng ký thi OSCP ngay, 2024-2025 OffSec đã thay đi format (PEN-200 mới), có thể học trong 3-6 tháng. (2) Trong CV cover letter, show các chứng minh tương đương: write-up public, lab cá nhân, CVE published, các CTF đã đạt giải (HTB Pro Hacker rank, TryHackMe Elite rank). (3) Nếu bạn đã có OSCE, GPEN, GWAPT thì có thể thay thế OSCP ở mức độ nhất định. Kết luận: OSCP = "passport" vào Red Team ở ngân hàng lớn. Nếu nghiêm túc với Red Team track, hãy đầu tư thi trong 6 tháng tới.