Lead - Cloud Security Engineer
MoMo processes billions of transactions each year for more than tens of millions of users across payments, lending, insurance, and investment products — all running on a multi-cloud platform spanning AWS, GCP, Azure, FPT Cloud, and VNG Cloud.
As a Cloud Security Engineer, you will be the dedicated security practitioner who hardens our cloud and container estate end-to-end: from workload identity and network segmentation in Kubernetes, to supply-chain integrity in CI/CD, to runtime threat detection in production. You will work closely with platform, DevOps, data, and AI engineering teams to harden security by design — embedding guardrails directly into Terraform modules, Helm charts, and deployment pipelines so that secure-by-default is the easy path, not the slow one.
Mô tả công việc
▸ Harden Kubernetes — enforce workload identity, network policies, Pod Security Standards, RBAC, and admission control (OPA / Kyverno) across production and staging clusters.
▸ Secure the software supply chain — implement container image scanning, signing (cosign / Notation), SBOM generation, secret scanning, and automated security gates in CI/CD pipelines.
▸ Own cloud IAM & secrets management — design and enforce least-privilege IAM across AWS, GCP, FPT Cloud, and VNG Cloud; manage secrets at scale with HashiCorp Vault / SOPS including automated rotation and periodic access reviews.
▸ Isolate multi-tenant workloads — architect security boundaries for user-run Jupyter notebooks, Apache Spark jobs, and GPU workloads that execute arbitrary code on shared infrastructure.
▸ Shift security left — codify secure-by-default Terraform modules, Helm charts, and pipeline templates so engineering squads get guardrails instead of gates.
▸ Build detection & response — deploy and tune runtime threat detection (Falco / Tetragon), cloud-native posture management (GCP SCC), centralize audit logs to SIEM, and author incident runbooks.
▸ Govern AI & data access — protect the LLM gateway and feature stores, define access policies for AI model endpoints, and support PCI-DSS Level 1 and BSP / SBV regulatory compliance.
Yêu cầu công việc
▸ Harden Kubernetes — enforce workload identity, network policies, Pod Security Standards, RBAC, and admission control (OPA / Kyverno) across production and staging clusters.
▸ Secure the software supply chain — implement container image scanning, signing (cosign / Notation), SBOM generation, secret scanning, and automated security gates in CI/CD pipelines.
▸ Own cloud IAM & secrets management — design and enforce least-privilege IAM across AWS, GCP, FPT Cloud, and VNG Cloud; manage secrets at scale with HashiCorp Vault / SOPS including automated rotation and periodic access reviews.
▸ Isolate multi-tenant workloads — architect security boundaries for user-run Jupyter notebooks, Apache Spark jobs, and GPU workloads that execute arbitrary code on shared infrastructure.
▸ Shift security left — codify secure-by-default Terraform modules, Helm charts, and pipeline templates so engineering squads get guardrails instead of gates.
▸ Build detection & response — deploy and tune runtime threat detection (Falco / Tetragon), cloud-native posture management (GCP SCC), centralize audit logs to SIEM, and author incident runbooks.
▸ Govern AI & data access — protect the LLM gateway and feature stores, define access policies for AI model endpoints, and support PCI-DSS Level 1 and BSP / SBV regulatory compliance.
▸ Experience with financial-services or fintech security requirements (PCI-DSS, data residency, fraud controls).
▸ Familiarity with AI/ML platform security — model serving, feature stores, prompt-injection defenses, data access governance.
▸ Relevant certifications: CKS, CCSP, GCP Professional Cloud Security Engineer, or AWS Security Specialty.
▸ Exposure to runtime observability stacks (Falco, Tetragon, eBPF-based tooling) or CSPM/CNAPP platforms.
