Lead - Cloud Security Engineer

Find out how well you fit this job.

Job updated 3 days ago
The employer was active about 9 hours ago

Job Description

MoMo processes billions of transactions each year for more than tens of millions of users across payments, lending, insurance, and investment products — all running on a multi-cloud platform spanning AWS, GCP, Azure, FPT Cloud, and VNG Cloud.

As a Cloud Security Engineer, you will be the dedicated security practitioner who hardens our cloud and container estate end-to-end: from workload identity and network segmentation in Kubernetes, to supply-chain integrity in CI/CD, to runtime threat detection in production. You will work closely with platform, DevOps, data, and AI engineering teams to harden security by design — embedding guardrails directly into Terraform modules, Helm charts, and deployment pipelines so that secure-by-default is the easy path, not the slow one.



Mô tả công việc

▸  Harden Kubernetes — enforce workload identity, network policies, Pod Security Standards, RBAC, and admission control (OPA / Kyverno) across production and staging clusters.

▸  Secure the software supply chain — implement container image scanning, signing (cosign / Notation), SBOM generation, secret scanning, and automated security gates in CI/CD pipelines.

▸  Own cloud IAM & secrets management — design and enforce least-privilege IAM across AWS, GCP, FPT Cloud, and VNG Cloud; manage secrets at scale with HashiCorp Vault / SOPS including automated rotation and periodic access reviews.

▸  Isolate multi-tenant workloads — architect security boundaries for user-run Jupyter notebooks, Apache Spark jobs, and GPU workloads that execute arbitrary code on shared infrastructure.

▸  Shift security left — codify secure-by-default Terraform modules, Helm charts, and pipeline templates so engineering squads get guardrails instead of gates.

▸  Build detection & response — deploy and tune runtime threat detection (Falco / Tetragon), cloud-native posture management (GCP SCC), centralize audit logs to SIEM, and author incident runbooks.

▸  Govern AI & data access — protect the LLM gateway and feature stores, define access policies for AI model endpoints, and support PCI-DSS Level 1 and BSP / SBV regulatory compliance.



Yêu cầu công việc

▸  Harden Kubernetes — enforce workload identity, network policies, Pod Security Standards, RBAC, and admission control (OPA / Kyverno) across production and staging clusters.

▸  Secure the software supply chain — implement container image scanning, signing (cosign / Notation), SBOM generation, secret scanning, and automated security gates in CI/CD pipelines.

▸  Own cloud IAM & secrets management — design and enforce least-privilege IAM across AWS, GCP, FPT Cloud, and VNG Cloud; manage secrets at scale with HashiCorp Vault / SOPS including automated rotation and periodic access reviews.

▸  Isolate multi-tenant workloads — architect security boundaries for user-run Jupyter notebooks, Apache Spark jobs, and GPU workloads that execute arbitrary code on shared infrastructure.

▸  Shift security left — codify secure-by-default Terraform modules, Helm charts, and pipeline templates so engineering squads get guardrails instead of gates.

▸  Build detection & response — deploy and tune runtime threat detection (Falco / Tetragon), cloud-native posture management (GCP SCC), centralize audit logs to SIEM, and author incident runbooks.

▸  Govern AI & data access — protect the LLM gateway and feature stores, define access policies for AI model endpoints, and support PCI-DSS Level 1 and BSP / SBV regulatory compliance.


Nice to have:

▸  Experience with financial-services or fintech security requirements (PCI-DSS, data residency, fraud controls).

▸  Familiarity with AI/ML platform security — model serving, feature stores, prompt-injection defenses, data access governance.

▸  Relevant certifications: CKS, CCSP, GCP Professional Cloud Security Engineer, or AWS Security Specialty.

▸  Exposure to runtime observability stacks (Falco, Tetragon, eBPF-based tooling) or CSPM/CNAPP platforms.


View all jobs

Find out how well you fit this job.

View all jobs

Find out how well you fit this job.

Find out how well you fit this job.

1
No requirement for relevant working experience
Personal Invitation Link
This is your personal referral link for job invitation. You'll receive an email notification when someone applied for the position via your job link.
Share this job

About us

MoMo is one of the fastest-growing fintech companies in Vietnam, with nearly 2,000 employees dedicated to advancing financial inclusion for the Vietnamese people.

Founded in 2007, MoMo now has over 31 million users, 50,000 domestic partners, 140,000 payment acceptance points nationwide, and partnerships with 70 banks and international card organizations. With a diverse ecosystem and cutting-edge technology, MoMo enables users to spend, manage finances, invest, access credit, and run their businesses more easily and efficiently.

Working at MoMo means joining a team that constantly innovates and pioneers the use of technology, especially AI, to bring millions of Vietnamese people a flexible and proactive financial life.

We are proud to be among the Top 28 Best Workplaces in Vietnam (2023 survey).