Job Summary
- Technical Skill:
- DevSecOps ,
- Python ,
- IDS ,
- System Administration ,
- Linux ,
- VPN ,
- PowerShell ,
- Splunk ,
- Firewall ,
- Architecture ,
- Ansible ,
- IPS ,
- Flux ,
- Azure AD ,
- RBAC ,
- SIEM ,
- Kubernetes ,
- Bash ,
- Graylog ,
- SSO ,
- Terraform ,
- NIST CSF ,
- CIS ,
- KeyCloak ,
- ELK ,
- GitOps ,
- EDR ,
- DevSecOps ,
- IAM ,
- PAM ,
- ArgoCD ,
- Wazuh ,
- CKA
Job description
Overview of job
Introduction
Con Cung is the biggest omni-channel company for mom & baby with 600 retail stores in Vietnam in 2021 and plan to have 1,000 stores by 2023 with 1 billion USD revenue. Con Cung's annual growth rate is more than 70%. With the vision of providing good quality products for children, Con Cung is strongly investing into Product Research and Development in order to manufacture and provide products that are suitable to the local market in terms of pricing and quality. We also invest into technology in order to manage the network and online channel efficiently.
Con Cung Corporation also develops in-house cutting-edge automation and intelligence technologies. We are seeking for young, smart & dynamic talents to grow your career together with us.
Job Description
The company is seeking a SecOps Engineer to design, implement, and operate its core security infrastructure and network security, with particular emphasis on securing and hardening the Kubernetes/container platform. This role is both hands-on and strategic: building secure-by-design infrastructure from the ground up before expanding into SOC/DFIR capability as the security baseline matures. The engineer will combine deep systems/platform expertise with security engineering judgment to close foundational gaps.
Key Responsibilities
1. Security Architecture & Infrastructure
- Design and implement Identity & Access Management (IAM/SSO) architecture and Single Sign-On integration across internal applications.
- Design and implement Privileged Access Management (PAM) and Zero Trust Network Access (ZTNA) / identity-aware proxy solutions.
- Design and implement network security architecture, including segmentation, firewalls, VPN, and secure remote access.
- Build infrastructure using Infrastructure-as-Code (Terraform, Ansible) and version-controlled configuration where applicable.
2. Platform & Container Security
- Support the hardening of the company's Kubernetes platform: RBAC design, network policy, workload security baseline, secrets management.
- Contribute to the rollout of Policy-as-Code (e.g., Kyverno, OPA) for cluster governance.
- Collaborate with the current Cluster Admin to reduce single-point-of-failure risk and support knowledge transfer / documentation.
3. SOC Development & Operations
- Support the design, implementation, and day-to-day operation of the company's SOC capabilities (SIEM, EDR, log management, monitoring pipelines).
- Contribute to detection rule and alert logic development as SOC capability is built out.
4. Threat Detection, Response & DFIR
- Participate in security event investigation, containment, and remediation activities.
- Contribute to DFIR playbooks, escalation paths, and evidence-handling procedures.
5. Continuous Improvement & Collaboration
- Assist in tabletop exercises and simulations to validate incident response readiness.
- Collaborate with IT, InfraOps, AppSec, and Red Team functions to close security gaps.
- Document architecture decisions, runbooks, and lessons learned.
- Contribute to security policies, standards, and compliance initiatives (ISO 27001, etc.) incollaboration with the GRC team.
- Annual bonus: 2 - 3 months under minimum KPI requirement
- Fast promotion opportunities based on personal ability
- Work in a dynamic, open, creative environment
- Regular training, company team building, birthday bonus
Job Requirement
We are looking for a highly motivated person with:
- 2-3+ years of experience in security engineering, infrastructure/platform engineering, SRE, or DevSecOps.
- Hands-on production experience operating Kubernetes — RBAC design and troubleshooting, network policy, workload/container security fundamentals.
- Practical experience designing or implementing at least one of: IAM/SSO (e.g., Keycloak, Okta, Azure AD), PAM, ZTNA / identity-aware proxy, or network security architecture (firewall, segmentation, VPN).
- Strong Linux system administration and scripting/automation skills (Python, Bash, PowerShell, or similar).
- Familiarity with Infrastructure-as-Code and/or GitOps concepts (Terraform, Ansible, ArgoCD/Flux, or equivalent).
- A proactive attitude & the ability to think outside of the box.
- Works in an organized, structured manner; can-do attitude, gets things done.
- Excellent communication skills with diverse audiences.
- Strong critical thinking and analytical skills.
Nice-to-have:
- Experience with SIEM platforms (ELK Stack, Wazuh, Splunk, Graylog) or EDR tools.
- Foundation skills in log analysis, network traffic analysis, or malware analysis.
- Solid understanding of security frameworks (MITRE ATT&CK, NIST CSF, CIS Benchmarks).
- Foundation knowledge in AI integration for security operations.
- English communication.
- Relevant certifications: CKA/CKS, Security+, GCIA, GCIH, or equivalent.
Languages
-
English
Speaking: Intermediate - Reading: Intermediate - Writing: Intermediate
Technical Skill
- DevSecOps
- Python
- IDS
- System Administration
- Linux
- VPN
- PowerShell
- Splunk
- Firewall
- Architecture
- Ansible
- IPS
- Flux
- Azure AD
- RBAC
- SIEM
- Kubernetes
- Bash
- Graylog
- SSO
- Terraform
- NIST CSF
- CIS
- KeyCloak
- ELK
- GitOps
- EDR
- DevSecOps
- IAM
- PAM
- ArgoCD
- Wazuh
- CKA
COMPETENCES
- Proactive
- Organizational Skills
- Can-do attitude
- Communication Skills
- Analytic Skills
- Critical Thinking
BUSINESS PROFILE
Concung.com is a retail system of maternity and baby products.
Concung.com is a retail company with a turnover of VND1,500 billion by 2017 with 200 retail outlets. Concung.com's growth rate is 70 - 100% per year; and Concung.com has more than 500 retail outlets for moms and babies by 2020.
Concung.com builds a dynamic, young, creative and aggressive working environment. Each employee is a partner that is trusted by the company and creates the best conditions to show and develop his or her capacity. In addition to income, Concung.com applies a bonus share policy for important positions in the company.
Concung.com culture is young, open and simple.
Founded and run by young, in-depth technical experts in the field of science and technology, Concung.com uses technology, data and technology to operate the retail system effectively.