Senior - Security Engineer

Trung tâm Công nghệ Thông tin
Hồ Chí Minh
26-ITC-0541
The Senior Security Engineer is responsible for protecting the organization's entire information system against cybersecurity threats, while also spearheading the application of AI (Claude) in SIEM/SOAR log analysis and forensic investigation to improve detection and incident response efficiency (reducing MTTI). 

Mô tả công việc

Security Operations & Infrastructure

  • Recommend, design, manage, and document system security requirements; configure and troubleshoot security infrastructure
  • Ensure management and the BOD are notified promptly of security incidents
  • Run security tests (audit/pentest) on web, mobile, and desktop applications; identify and exploit vulnerabilities
  • Review code/application flows and recommend fixes; work with teams to remediate vulnerabilities and meet compliance standards
  • Investigate security incidents and produce findings reports

Knowledge Sharing & Governance

  • Research emerging threats and techniques (hacking, malware, bug bounty, etc.)
  • Write security best-practice standards for developers; train staff to enforce security policy

AI Integration into Security (Claude-Powered)

  • Design Claude-integrated workflows for alert triage, log analysis, and incident investigation across SIEM/SOAR platforms (Splunk, QRadar, Elastic, XSOAR)
  • Build prompt engineering pipelines to parse, correlate, and summarize logs, reducing analyst workload and MTTI
  • Develop playbooks that turn raw alerts into structured incident summaries, root-cause hypotheses, and response recommendations
  • Enable natural-language log querying so analysts can investigate without deep SPL/KQL expertise
  • Auto-generate incident reports, threat intel summaries, and post-mortems from raw event data
  • Manage Claude API integrations, context windows, and token efficiency; refine prompts via analyst feedback loops

Digital Forensics

  • Apply memory analysis, disk imaging, log correlation, and timeline reconstruction to investigate breaches
  • Conduct malware analysis and reverse engineering to identify attack vectors and build detection signatures
  • Maintain forensic chain of custody per legal/compliance requirements; produce forensic reports for management, legal, and regulators

Yêu cầu công việc

Experience & Core Knowledge

  • Proven experience as a System/Information Security Engineer; solid grasp of CIA principles (Confidentiality, Integrity, Availability)
  • Understanding of complex, cross-platform system architectures; experience in risk assessment and system hardening

Networking & Infrastructure

  • Deep networking knowledge: switching, routing, encryption/tunneling protocols (IPSec, SSL VPN, TLS, GRE)
  • Experience with security systems — firewalls, IDS, anti-virus, IAM/PAM, NAC, log management, content filtering, DLP — on both commercial and open-source platforms
  • In-depth Linux knowledge (RedHat, CentOS, Debian); experience managing patches/upgrades on servers, workstations, and network hardware
  • Familiarity with web technologies (web apps, web services, SOA) and related protocols; AWS/cloud (PaaS) security

Compliance & Governance

  • Experience with PCI DSS/SOX audit processes; able to write SOPs and BCP plans
  • Familiar with ITIL/ITSM; able to work well under pressure

Technical Skills

  • Scripting proficiency: Bash, Python, or PowerShell

Certifications (Preferred)

  • CEH, CISSP, CSP, CCNP Security, or equivalent

AI Integration (Claude-Powered)

  • Hands-on experience with LLM APIs, especially Claude API, for automation/analysis workflows
  • Prompt engineering skills for structured security tasks (log summarization, alert triage, threat narratives)
  • Experience with SIEM/SOAR query languages (SPL, KQL, AQL); strong Python for parsing log formats (CEF, LEEF, JSON, syslog) and managing context/token budgets
  • Understanding of RAG patterns and human-in-the-loop validation workflows

Digital Forensics

  • Hands-on with forensics tools (Autopsy, Volatility, FTK, Wireshark); experience with MITRE ATT&CK
  • Knowledge of malware analysis (static/dynamic); GCFE/GCFA/GREM a plus