Senior IT Security Engineer
We are seeking a highly skilled and hands-on Senior IT Security Engineer to own and operate Niteco's security operations function, strengthen enterprise security management, and support security compliance across infrastructure, cloud, endpoint and identity environments. This role requires a strong engineering mindset, solid experience in security technologies, incident response, vulnerability management, automation, and the ability to collaborate effectively with IT Operations, CloudOps, Engineering, SA, HR and compliance stakeholders.
The role will act as the owner of Security Operations Center activities, lead security incident handling when needed, drive measurable security improvements, and help ensure that Niteco's information security practices remain scalable, auditable and aligned with business needs.
WHAT YOU'LL DO
- Own and operate the Security Operations Center function, including security monitoring, alert triage, incident response, remediation tracking and security automation.
- Operate and optimize Microsoft Defender security platforms, including Defender for Endpoint, Defender for Identity, Defender for Cloud and Defender for Office 365.
- Integrate security monitoring signals from infrastructure, applications, endpoints and observability tools such as Grafana, Prometheus or equivalent platforms.
- Define and maintain SOC policies, procedures, workflows, alert routing, ticketing integration and operational documentation.
- Act as Incident Owner or Incident Commander for security incidents, ensuring full traceability from alert, ticket, remediation, verification and evidence collection.
- Lead post-incident root cause analysis, lessons learned sessions and preventive action tracking until closure.
- Coordinate response to endpoint compromise, malware outbreaks, identity-based attacks, cloud misconfiguration incidents, data leakage and insider-threat scenarios.
- Collaborate with IT Operations on endpoint security, device compliance, software control, encryption compliance, patching and secure device configuration.
- Manage identity and access security using Microsoft Entra ID, MFA, Conditional Access, PIM, access reviews and least-privilege principles.
- Collaborate with PMO and IT Operations to standardize Joiner-Mover-Leaver access processes, approvals, audit logs and SLAs.
- Own the vulnerability management lifecycle across discovery, prioritization, remediation and verification for endpoints, servers, cloud workloads and applications.
- Coordinate with system owners, SA and Engineering teams to drive remediation, risk acceptance, exception management and secure CI/CD practices where applicable.
- Monitor network, perimeter and physical security signals, including firewall logs, access-door logs, server-area records and abnormal activities.
- Support firewall rule reviews, firmware updates, network health monitoring, backup verification and disaster recovery rehearsal activities in collaboration with IT Operations.
- Provide cloud and hybrid security consultation for Azure, AWS, Kubernetes, containers and related security configurations.
- Collaborate with relevant stakeholders in developing and implementing internal Information Security and AI usage policies, ensuring alignment with ISO 27001 controls for data protection, access control, and information classification.
- Support ISO 27001 audits by providing technical input, operational evidence, documentation and follow-up support for findings or penetration-test remediation.
- Leverage AI-driven capabilities in security platforms and build practical automation for alert triage, log analysis, evidence collection, security data processing and compliance reporting.
- Develop and maintain security automation scripts using NodeJS, Python, PowerShell or Bash, and integrate security tools through APIs where appropriate.
- Define and report SOC KPIs, security dashboards, incident trends, vulnerability exposure, compliance status and continuous improvement initiatives.
WHAT YOU SHOULD HAVE
- 5+ years of experience in Cybersecurity, Information Security, SOC, SecOps or IT security operations roles.
- 1-2+ years of experience leading SOC/SecOps functions or security operations within IT or managed services environments.
- Hands-on experience with Microsoft security ecosystem, especially Microsoft Defender for Endpoint, Defender for Identity, Defender for Cloud and Defender for Office 365.
- Strong knowledge of IAM and Microsoft Entra ID, including MFA, Conditional Access, access reviews, privileged access and least-privilege practices.
- Experience with vulnerability scanning, risk-based prioritization, remediation coordination and lifecycle management.
- Solid understanding of Azure and AWS cloud security; GCP experience is an advantage.
- Experience with observability or monitoring tools such as Grafana, Prometheus or equivalent platforms.
- Ability to develop scripts or automation using NodeJS, Python, PowerShell or Bash.
- Strong English communication skills with the ability to work with engineering teams, management, vendors and stakeholders.
- Process-driven mindset, clear documentation skills and good awareness of audit and compliance requirements.
NICE TO HAVE
- Microsoft Sentinel SIEM experience.
- Microsoft Security certifications such as SC-200, SC-300 or SC-100.
- Professional security certifications such as CISSP, CISM or CISA.
- ISO 27001 Foundation, awareness certification or hands-on ISO 27001 compliance support experience.
- Cloud security certifications, preferably on Azure.
- Experience with SonarQube, CI/CD security gates, Infrastructure as Code security scanning or automated security testing frameworks.
BENEFITS AND WORKING ENVIRONMENT
- Attractive salary with bi-yearly review, 13th-month bonus, performance bonus, public holiday bonuses, birthday gift, employee service awards up to $1,000
- A clear career path with proper training courses, workshops, fully sponsored certificate exams
- Extensive AON health insurance (during labor contract) and accident insurance (during probation) in addition to the state-mandated health insurance
- Professional, flexible & dynamic working environment with colleagues of different nationalities that is open-minded, creative, supportive, friendly, and encouraging.
- Regular communication from Management on the company's strategy, development plan, and new opportunities for employees
- Opportunities to join global technical conferences.
- Bright working space with modern facilities including the newest software
- Employees and families are engaged and taken care of by the company via Trade Union activities.
- Summer kick-off at 5-star resort
- Sports & cultural activities all year around to strengthen both your physical & mental health.
- NICEF - our own Charity program where our employees raise funds and help people with difficulties in Vietnam.