Join an International Fintech Leader ( Branch office in Vietnam) Are you a highly skilled Information Security professional looking to make a significant impact within a leading international fintech group?Our client, a respected international group headquartered in Belgium and a key player in the fintech industry, is expanding its operations and seeking a dedicated Information Security Officer to be based right here in Vietnam. Aurify works closely with this client, providing essential IT services and fostering a strong partnership.In this pivotal role, you will be the driving force behind the Information Security Strategy and Operations for the group. We are looking for a candidate with proven, hands-on expertise in:Information Security Management Systems (ISMS)Business Continuity PlanningComprehensive Risk ManagementCompliance FrameworksYou will have the unique opportunity to champion strategic security initiatives, directly supporting the international organization's growth while helping to cultivate a world-class security culture from our Vietnam hub. Elevate your career by joining a global-standard company where your expertise in information security is valued and essential! What you’ll be doing Maintain and continuously improve ISMS processesDraft, formalize, and validate security procedures and governance documentationSupport BCP, DRP and crisis management readinessAssess the current information security operations and programs and define a further enhanced group information security program, policies and operating model aligned with our business objectivesPropose solutions for information security issues and challengesInteract and inform management, compliance, legal, sales, development-and delivery teams and (security) operation teams by embodying a clear information security strategy and its operational requirements and policiesCollaborate closely with key stakeholders, including senior leadership or CISO‑level roles.Support internal and external audits, compliance reporting (planning, evidence collection, gap analysis, and remediation followup, etc.).Follow-up on pentests and risk analysesFollow-up on information security initiatives/projects.Enhance the information security awareness and culture within the organisation Support incident follow-up and integrate lessons learned into the ISMSManage and support GRC tool.Manage and maintain the risk register and exception register