IT Security & Data Protection, Specialist

Ho Chi Minh City, VN-AIA Vietnam Until 9/16/2026 5+ years exp First posted July 18, 2026 Last posted July 18, 2026
Job description

At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone.

As pioneering innovators for over 100 years, we’re now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live Healthier, Longer, Better Lives.

To get there, we need people with tech/digital/analytics expertise and passion to help develop positive, sustainable change through digitally enhanced experiences that will impact the lives of millions of people and create a healthier future for everyone.

If you believe in developing a better tomorrow, read on. 

About the Role

Report to: Senior Manager, IT Security & Asset Management
Location: Hochiminh City
Function: Customer Office and Information Technology | Department: IT Security & Asset Management
Type: Individual Contributor

THE OPPORTUNITY: 

We are looking for an IT Security & Data Protection, Specialist with hands-on experience in implementing and managing enterprise-level security and compliance controls who are responsible for

  • Ensuring the organization’s data protection and IT security governance frameworks are effectively implemented, monitored, and continuously improved.

  • Embedding robust data protection controls, managing IT risk assessments, supporting audits, driving end-user awareness, and maintaining governance dashboards to ensure compliance and timely escalation of issues.

ROLES AND RESPONSIBILITIES:

Data Protection Controls (40%)

  • Design and Implementation: Lead the design and deployment of robust data protection controls in alignment with AIA Group’s data governance framework and applicable local regulations, including the Data Law and Personal Data Protection Law.

  • Ensure appropriate classification, handling, and protection of sensitive data across systems and services.

  • Collaborate with application, business and infrastructure teams to embed privacy-by-design principles.

  • Monitoring & Continuous Improvement: Continuously monitor data protection measures and drive enhancements based on evolving regulatory requirements, threat landscape, and internal audit findings.

IT Risk & Control Assessment (eGRC, MSII) (30%)

  • Lead and support IT risk assessments using enterprise governance platforms (e.g., eGRC, MSII).

  • Identify control gaps and recommend remediation plans to mitigate risks.

  • Risk Register Management: Maintain accurate and up-to-date risk registers, ensuring timely documentation, tracking, and reporting of risk mitigation activities to relevant governance bodies.

Audit Support (10%)

  • Coordinate with internal and external auditors to provide evidence and responses for IT security and data protection audits.

  • Track audit findings and ensure closure of remediation actions within agreed timelines.

SAF & GIS Dashboard Tracking & Escalation (10%)

  • Maintain and monitor Security Assurance Framework (SAF) and Governance Information System (GIS) dashboards.

  • Escalate critical issues and non-compliance to relevant stakeholders in a timely manner.

  • Provide regular reporting and insights to senior management.

End User Awareness (10%)

  • Develop and deliver security awareness campaigns and training programs tailored to different user groups.

  • Promote a culture of security and data protection across the organization.

JOB REQUIREMENTS:

  • B.A Degree or higher in Information Technology related field.;

  • 5 years of experiences of information security domain, especially hands on experience for data protection, IT audit, IT security governance;

  • Hands on experience in database query such as SQL, Python;

  • Familiarity with IT security requirement such as PCI DSS, GDPR, ISO 27001, NIST;

  • Security Certifications/licenses: CISA, CISM, CRISC, CISSP is a plus;

  • Good communication skills, especially in English to effectively work and negotiate with internal/external teams;

  • Work under high pressure, goal oriented, and inspired to perform without outside help.

Build a career with us as we help our customers and the community live Healthier, Longer, Better Lives.

You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.

About this role

Summary

Manage data protection controls, risk assessments, audit support, dashboards, and end-user awareness.

Job title

IT Security & Data Protection, Specialist

Experience level

5+ years

Minimum experience

5+ years exp

Industry

finance

Location requirements

Ho Chi Minh City; remote work not specified

Salary

Not specified

Management role

No

Skills & keywords

Required skills

SQLPythonPCI DSSGDPRISO 27001NIST

Preferred skills

CISACISMCRISCCISSPEnglish

Specializations

data protectionIT security governanceauditrisk assessmentcompliance
Locations

Structured locations inferred from the posting.

Ho Chi Minh City, Vietnam

Work arrangement unknown City