en
Candidates

Together, we’ll map out career-defining, life-changing pathways to achieve your career ambitions. Browse our range of services, advice, and resources.

Learn more
About Robert Walters Vietnam

Since our establishment in 2011, our belief remains the same: Building strong relationships with people is vital in a successful partnership.

Learn more

Work for us

Our people are the difference. Hear stories from our people to learn more about a career at Robert Walters Vietnam.

Learn more

Senior Security GRC Program Manager

Save job

We are seeking an experienced Senior Security GRC Program Manager to establish and scale enterprise security, compliance, risk, and privacy programs. You will own ISO 27001 & SOC 2 certifications end-to-end, manage automated GRC platforms (Vanta/Drata), lead technology risk frameworks, and partner with cross-functional leadership to embed robust security controls across the organization.

We are seeking a Senior Security Governance, Risk & Compliance (GRC) Program Manager to lead and develop enterprise security, compliance, risk, and privacy programs across a fast-growing technology organization.

This role requires a blend of strategic governance design and hands-on execution. You will establish scalable governance frameworks, maintain continuous audit readiness, manage vendor risk, and partner with cross-functional stakeholders to ensure security controls are embedded into business and technology operations.

Key Responsibilities

Security Governance & Compliance
• Own and maintain the Information Security Management System (ISMS).
• Directly own and manage end-to-end certification and compliance programs, including ISO 27001 and SOC 2 (Type I & Type II).
• Manage compliance automation platforms such as Vanta, Drata, or equivalent tools.
• Coordinate external auditors, manage evidence collection, and drive continuous audit readiness.

Technology Risk Management
• Establish and maintain enterprise technology risk management frameworks and risk registers.
• Conduct risk assessments covering cloud environments, applications, infrastructure, third parties, and AI/ML technologies.
• Develop governance reporting, risk metrics, KRIs, and executive dashboards.

Security Assurance & Operations Governance
• Design and oversee control testing, vulnerability management SLAs, and penetration testing coordination.
• Monitor remediation activities arising from audits, assessments, and internal reviews.
• Partner with Engineering and Product teams to embed security requirements into tech delivery lifecycles.

Vendor & Customer Security Assurance
• Build and maintain Third-Party Risk Management (TPRM) frameworks and conduct vendor due diligence.
• Handle complex customer security reviews, security questionnaires, and trust documentation.

Privacy & Security Awareness
• Operationalize privacy requirements (data mapping, retention, DPIA, cross-border data governance).
• Govern security awareness training programs and access review controls.

Qualifications

Required:
• 8+ years of hands-on experience in Security Governance, Technology Risk Management, GRC, and Security Compliance.
• Demonstrated track record as the DIRECT OWNER of ISO 27001 and SOC 2 (Type I & II) audits from preparation through to issuance.
• Hands-on experience operating compliance automation platforms (Vanta, Drata, or equivalent).
• Proven expertise in establishing Risk Registers, KRIs, Vendor Risk Management frameworks, and answering Customer Security Reviews.
• Strong working knowledge of security frameworks: ISO 27001, SOC 2, NIST CSF, and CIS Controls.
• Outstanding stakeholder management and communication skills.

Preferred:
• Experience in SaaS, fintech, or modern cloud-native environments.
• Exposure to GDPR, HIPAA, PCI-DSS, or AI Governance frameworks.
• Relevant certifications: CISSP, CISM, CRISC, CIPM, or ISO 27001 Lead Implementer/Auditor.

Due to the high volume of applications we are experiencing, our team will only be in touch with you if your application is shortlisted.

Contract Type: Perm

Specialism: Tech & Transformation

Focus: Security

Industry: Technology

Salary: Negotiable

Workplace Type: Hybrid

Experience Level: Mid Management

Location: Ho Chi Minh City

Job Reference: W6AJ0Q-FE53CC60

Date posted: 19 August 2026

Consultant: An Tran