Concung.com

801 Nguyen Van Linh, TP Hồ Chí Minh

Quy mô công ty : 100-499

Xem thêm

Tóm lược

100-499

Product

Việt Nam

GRC Engineer

Concung.com

Quận 7, TP Hồ Chí Minh

  • English
  • Có kinh nghiêm (Nhân viên)
  • Toàn thời gian
  • Thỏa Thuận
  • Ngày Đăng:20/12/2025
  • 1

Mô tả công việc

Tóm tắt công việc

Introduction

Con Cung is the biggest omni-channel company for mom & baby with 600 retail stores in Vietnam in 2021 and plan to have 1,000 stores by 2023 with 1 billion USD revenue. Con Cung's annual growth rate is more than 70%. With the vision of providing good quality products for children, Con Cung is strongly investing into Product Research and Development in order to manufacture and provide products that are suitable to the local market in terms of pricing and quality. We also invest into technology in order to manage the network and online channel efficiently.

Con Cung Corporation also develops in-house cutting-edge automation and intelligence technologies. We are seeking for young, smart & dynamic talents to grow your career together with us.

Job Description

The company is seeking a GRC Engineer to build and formalize its Governance, Risk, and Compliance. This role will be responsible for designing security policies, managing risk assessments, driving compliance initiatives (ISO 27001, SOC 2 Type II), and strengthening privacy and physical security processes. The engineer will work closely with technical and business teams to ensure security requirements are embedded across all operations.

Key Responsibilities

1.  Risk Assessment & Management

  • Lead periodic information security risk assessments across systems, infrastructure, and business processes.
  • Maintain the company’s risk register and ensure timely remediation and risk treatment planning.
  • Collaborate with engineering, product, and business units to ensure risks are understood, prioritized, and addressed.
  • Develop metrics and dashboards for continuous monitoring of security risks.

2.  Security Awareness & Training

  • Design and deliver security awareness programs, including phishing simulations, annual training, and role-based education.
  • Evaluate training effectiveness and recommend improvements to strengthen security culture.
  • Work with HR to integrate security training into onboarding and staff development.

3.  Security Policy & Procedure Development

  • Develop, maintain, and improve security policies, standards, and procedures across all departments.
  • Ensure policies align with industry frameworks (NIST, ISO 27001) and regulatory requirements.
  • Support the rollout and enforcement of policies across teams and business units.

4.  Physical Security

  • Collaborate with facilities and operations teams to assess physical security across stores, warehouses, and offices.
  • Conduct risk assessments related to access control, surveillance, and asset protection.
  • Develop physical security guidelines and coordinate periodic audits.

5.  Data Protection & Privacy

  • Support the implementation and operation of data protection and privacy programs.
  • Assist in identifying and managing personal data risks, data flows, and data handling procedures.
  • Collaborate with legal and IT teams to support compliance with privacy regulations.
  • Participate in incident management related to data breaches and privacy risks.

6.  Certification & Compliance (ISO 27001, SOC 2 Type II)

  • Contribute to the preparation, implementation, and maintenance of certification projects (e.g., ISO 27001, SOC 2 Type II).
  • Competitive package.
  • 13th month salary and performance bonus (2-4 month salary)
  • Working in a dynamic, open and creative environment
  • Fast promotion opportunities based on personal ability
  • Team-Building, Year End Party and many internal events

About Concung.com 

  • Working time: 8:30 - 17:30 Monday - Friday 
  • Working place: 14th Floor, Phu My Hung Tower, Tan Phu Ward, Dist. 7, HCMC 
  • The Journey of 10 years:

Yêu cầu công việc

  • 1–3+ years of experience in governance, risk management, compliance, or cybersecurity.
  • Strong understanding of information security fundamentals, risk assessment methodologies, and compliance frameworks.
  • Experience with ISO 27001, SOC 2, or similar compliance programs.
  • Ability to write clear policies and communicate security concepts to both technical and non- technical audiences.
  • Good analytical, documentation, and project management skills.
  • Organized, detail-oriented working style with a proactive attitude.
  • Experience in privacy programs (GDPR, local privacy laws).
  • Familiarity with business continuity planning, vendor risk management, or audit processes.
  • English communication.
  • Relevant certifications: ISO 27001 Lead Implementer/Lead Auditor, CRISC, CISA, Security+, or equivalent.

Ngôn ngữ

  • English

    Nói: Intermediate - Đọc: Intermediate - Viết: Intermediate

Yêu cầu kỹ thuật

  • Information Security
  • Cyber Security
  • ISO
  • CISA
  • SoC
  • CRISC

NĂNG LỰC

  • Risk Management
  • Analytic Skills
  • Documentation
  • Communication Skills
  • Project Management
  • Management Skills
  • Planning Skills
  • Proactive
  • Organizational Skills
  • Detail oriented

Thông tin doanh nghiệp

Concung.com is a retail system of maternity and baby products.

Concung.com is a retail company with a turnover of VND1,500 billion by 2017 with 200 retail outlets. Concung.com's growth rate is 70 - 100% per year; and Concung.com has more than 500 retail outlets for moms and babies by 2020.

Concung.com builds a dynamic, young, creative and aggressive working environment. Each employee is a partner that is trusted by the company and creates the best conditions to show and develop his or her capacity. In addition to income, Concung.com applies a bonus share policy for important positions in the company.

Concung.com culture is young, open and simple.

Founded and run by young, in-depth technical experts in the field of science and technology, Concung.com uses technology, data and technology to operate the retail system effectively.