Cybersecurity Lead Auditor
NewKey Responsibilities
- Plan and conduct on-site information security audits at Vietnam-based supplier factories, covering network and system controls, endpoint and device management, access and account governance, physical security, and data protection practices.
- Manage the complete audit cycle independently: pre-audit preparation and factory briefing, meeting, on-site inspection and evidence collection, and post-audit deliverable submission.
- Produce all audit deliverables in English within agreed timelines: Audit Report (with findings and control references), Meeting Minutes (MoM), and daily Activity Reports.
- Apply the client's proprietary security standard consistently and accurately, mapping field observations to specific control requirements with clear supporting evidence.
- Communicate professionally and constructively with factory throughout the audit, maintaining objectivity and factual accuracy in all findings.
- Escalate significant findings to the project lead promptly and in accordance with programme protocols.
- Maintain complete, auditable records of all audit activity in the designated project management system.
- Contribute to team quality reviews.
Qualifications & Experience Required
- Minimum 4 years of professional experience in information security auditing, IT compliance, or supply chain security assessment.
- Demonstrated experience conducting independent on-site audits at manufacturing or technology facilities.
- Working knowledge of core information security controls: network segmentation and access control, endpoint security and MDM, account lifecycle management, logging and audit trails, and data protection.
- Experience working within a structured audit methodology — planning, evidence collection, finding documentation, and reporting — with accountability for output quality.
- Trilingual proficiency: Mandarin Chinese (optional), Vietnamese, and English.
- Bachelor's degree or above in Information Security, Computer Science, Engineering, or a related field.
Preferred
- Professional certification: CISSP, or equivalent.
- Experience auditing within the electronics manufacturing or technology supply chain sector.
- Familiarity with proprietary client-specific security frameworks (in addition to standard frameworks such as ISO 27001).
Benefits:
- Working in a dynamic, friendly, and international environment
- 15 days of annual leave, 15 days of paid sick leave, plus Christmas leave
- 13th-month salary and performance-based bonus aligned with individual and business results
- Full social insurance, health insurance, and unemployment insurance based on full basic salary in accordance with Vietnamese Labor Law
- Comprehensive insurance benefits package, including: 24/7 Accident insurance and Health care insurance
- Annual health check
- Free parking
- Regular staff engagement activities, including team-building events and company trips
- Participate in the company’s training programs, LinkedIn Learning license holder with fees supported by company according to policy