Ho Chi Minh City · Full-time (Posted 15 hours ago)
MoMo processes billions of transactions each year for more than tens of millions of users across payments, lending, insurance, and investment products — all running on a multi-cloud platform spanning AWS, GCP, Azure, FPT Cloud, and VNG Cloud.
As a Cloud Security Engineer, you will be the dedicated security practitioner who hardens our cloud and container estate end-to-end: from workload identity and network segmentation in Kubernetes, to supply-chain integrity in CI/CD, to runtime threat detection in production. You will work closely with platform, DevOps, data, and AI engineering teams to harden security by design — embedding guardrails directly into Terraform modules, Helm charts, and deployment pipelines so that secure-by-default is the easy path, not the slow one.
Harden Kubernetes — enforce workload identity, network policies, Pod Security Standards, RBAC, and admission control (OPA / Kyverno) across production and staging clusters.
Secure the software supply chain — implement container image scanning, signing (cosign / Notation), SBOM generation, secret scanning, and automated security gates in CI/CD pipelines.
Own cloud IAM & secrets management — design and enforce least-privilege IAM across AWS, GCP, FPT Cloud, and VNG Cloud; manage secrets at scale with HashiCorp Vault / SOPS including automated rotation and periodic access reviews.
Isolate multi-tenant workloads — architect security boundaries for user-run Jupyter notebooks, Apache Spark jobs, and GPU workloads that execute arbitrary code on shared infrastructure.
Shift security left — codify secure-by-default Terraform modules, Helm charts, and pipeline templates so engineering squads get guardrails instead of gates.
Build detection & response — deploy and tune runtime threat detection (Falco / Tetragon), cloud-native posture management (GCP SCC), centralize audit logs to SIEM, and author incident runbooks.
Govern AI & data access — protect the LLM gateway and feature stores, define access policies for AI model endpoints, and support PCI-DSS Level 1 and BSP / SBV regulatory compliance.
Harden Kubernetes — enforce workload identity, network policies, Pod Security Standards, RBAC, and admission control (OPA / Kyverno) across production and staging clusters.
Secure the software supply chain — implement container image scanning, signing (cosign / Notation), SBOM generation, secret scanning, and automated security gates in CI/CD pipelines.
Own cloud IAM & secrets management — design and enforce least-privilege IAM across AWS, GCP, FPT Cloud, and VNG Cloud; manage secrets at scale with HashiCorp Vault / SOPS including automated rotation and periodic access reviews.
Isolate multi-tenant workloads — architect security boundaries for user-run Jupyter notebooks, Apache Spark jobs, and GPU workloads that execute arbitrary code on shared infrastructure.
Shift security left — codify secure-by-default Terraform modules, Helm charts, and pipeline templates so engineering squads get guardrails instead of gates.
Build detection & response — deploy and tune runtime threat detection (Falco / Tetragon), cloud-native posture management (GCP SCC), centralize audit logs to SIEM, and author incident runbooks.
Govern AI & data access — protect the LLM gateway and feature stores, define access policies for AI model endpoints, and support PCI-DSS Level 1 and BSP / SBV regulatory compliance.
Nice to have:
Experience with financial-services or fintech security requirements (PCI-DSS, data residency, fraud controls).
Familiarity with AI/ML platform security — model serving, feature stores, prompt-injection defenses, data access governance.
Relevant certifications: CKS, CCSP, GCP Professional Cloud Security Engineer, or AWS Security Specialty.
Exposure to runtime observability stacks (Falco, Tetragon, eBPF-based tooling) or CSPM/CNAPP platforms.
Ho Chi Minh City, Ha Noi, Da Nang
1000+
Founded 2007
Startup
Founded in Vietnam
How We Work
MoMo offers core working time of 09:00 AM to 06:00 PM.
Remote Work
Currently, MoMo doesn't offer remote working, all employee must come to office.
Vacation & PTO
No work on weekends, national holidays, and company holidays at the end of the year.
Our hiring process are as below:
1. Application Screening (English CV is required)
Fill out the application form with your latest resume and academic transcript
2. Online Test
A technical online test about practical skills and cultural-fit will be sent to provided email. Be yourself and let your passion for technology truly shine!
3. Interview
Be confident to answer quick-check questions about your resume and fundamental knowledge. Your professional skills and positive attitude always make a great impression. Get your well-deserved offer and explore the exciting journey of a MoMoer.
Vietnam's leading dynamic Fintech environment is ready to welcome you to join us. As a MoMoer, you will get:
At MoMo, we promote the spirit of working together, supporting, and collaborating to achieve the greatest outcomes in work. New and innovative ideas from MoMoers will always be advocated and advanced to realize as long as they’re potential. Innovation has always been a vital aspect of MoMoers' DNA.
1. Team Work
2. Constant Learning
3. Innovations
4. Exellent on Execution
MoMo (M_Service)
Saigon Technology
Money Forward
Get Latest Jobs
Join our newsletter to get the latest news and updates in your inbox. 🤟
VietnamDevs is a job board for software engineer to find the best tech jobs at the modern companies in Vietnam.
© 2026 VietnamDevs. All rights reserved