Cyber Security Specialist (Red and Blue Team)
ที่ธนาคารกรุงศรีอยุธยา จำกัด (มหาชน)Role overview
Red Team: Provide security consultation on new Core Bank and its architecture e.g. application, container and DepSecOps
Blue Team: To provide security design, consulting, implement security tool and support cyber security operations on IT environment
What you'll do
For Red Team
Security Consultation:
1) Provide expert advice on security architecture for applications, cloud (e.g. AWS, Azure, OCP), and on-premises infrastructure.
2) Ensure alignment between business requirements and security controls.
3) Ensure the solution complies with internal policies and external standards (e.g. ISO 27001, NIST CSF, PDPA, BOT, PCI-DSS, etc.)
4) Develop and maintain security documentation (e.g. Security standard, Security requirements, Security hardening guides)Security Assessment:
1) Assess security scope including estimate required efforts for IT project
2) Conduct and coordinate penetration testing, vulnerability assessments, web application scans, and related activities
3) Provide practical recommendations for IT & BU
4) Maintain and follow up the findings
For Blue Team
SOC and Threat Management
1) Monitor, investigate, and respond to security alerts, incidents, and anomalies.
2) Administer and maintain cybersecurity tools, including AV/EDR, Network APT, SOC, SIEM, SOAR, TIP, Email Security, ASM, and Anti-DDoS solutions.
3) Conduct continuous threat intelligence monitoring and provide proactive responses to emerging threats and evolving attack trends.
4) Recommend and implement technical improvements to strengthen security posture based on the changing threat landscape.
5) Monitor, analyze, and escalate critical vulnerabilities; track normal vulnerabilities in alignment with the patch management plan.SOC Enhancement:
1) Develop and maintain SOC use cases, incident categories, dashboard and standardized reporting templates.
2) Maintain and update the SOC asset inventory and asset lookup tables.
3) Design, implement, and enhance automated playbooks to improve incident response efficiency.Operational Support:
Provide daily support for key cyber operations, including:
1) SOC monitoring and incident response
2) Threat intelligence collection, analysis, and management
3) Brand protection and incident response
4) Vulnerability management (critical and normal)
5) Attack Surface Management (ASM) monitoring and remediation
Apply now if you have these advantages
For Red Team
- Minimum of 3-8 years of experience in Information Security design, consulting and assessment (Banking Financial industries are advantage)
- Experience with Security architecture design and consulting
- Experience with Security assessment e.g. penetration tests, source code review, VA scan, DAST
- Experience with Security consulting on DevSecOps, Cloud environment e.g. AWS, Azure is advantage
- Relevant local and international security standards and best practices such as OWASP, NIST, ISO 27001, CIS Controls, SOC 2, PCI-DSS, and PDPA (Thailand)
For Blue Team
- Minimum of 10 years of experiences in Information Security design, Cyber Security Operation, Consulting and assessment (Banking /Financial industries are advantage)
- Experience with Security architecture design and consulting
- Experience with Security tool e.g. EDR, ATP, WAF, IPS/IDS, Deception, TI/TIP, Anti DDoS
- Experience with Security operation related to security event monitoring, incident response, root cause analysis, malware analysis, security monitoring use case development
- Experience with Threat Intelligent management e.g. response to threat intelligent alert, threat hunting, perform proactive incident response against cyber attack event
- Experience with Security Automation e.g. Design and development security automation playbook
- Experience with Cloud Environment e.g. Google Cloud, AWS, Microsoft Azure
- Hands on experience with computer programming languages and/or scripting languages such as Python, Java, Shell for automation.
Relevant local and international security standards and best practices such as OWASP, NIST, ISO 27001, CIS Controls, SOC 2, PCI-DSS, BOT-CRAF, NCSA and PDPA (Thailand)
Why join Krungsri?
- As a part of MUFG (Mitsubishi UFJ Financial Group), we a truly a global bank with networks all over the world.
- We offer a striking work-life balance culture with hybrid work policies (3 days in office per week).
- Unbelievable benefits such as attractive bonuses, employee loan with special rates and many more.
** Apply now before this role is close. **
Stay connected with KRUNGRI CAREER at:
- FB: Krungsri Career(http://bit.ly/FacebookKrungsriCareer [link removed])
- LINE: Krungsri Career (http://bit.ly/LineKrungsriCareer [link removed])
Talent Acquisition Department
Bank of Ayudhya Public Company Limited
1222 Rama III Rd., Bangpongpang, Yannawa, Bangkok 10120
สอบถามข้อมูลเพิ่มเติม : Talent Acquisition Center 0-2•••-•000
หมายเหตุ ธนาคารมีความจำเป็นและจะมีขั้นตอนการตรวจสอบข้อมูลส่วนบุคคลเกี่ยวกับประวัติอาชญากรรมของผู้สมัคร ก่อนที่ผู้สมัครจะได้รับการพิจารณาเข้าร่วมงานกับธนาคารกรุงศรีฯ
Remark: The bank needs to and will have a process for verifying personal information related to the criminal history of applicants before they are considered for employment with the bank.
Applicants can read the Personal Data Protection Announcement of the Bank's Human Resources Function by typing the link from the image that stated below.
EN (https://krungsri.com/b/privacynoticeen)
ผู้สมัครสามารถอ่านประกาศการคุ้มครองข้อมูลส่วนบุคคลส่วนงานทรัพยากรบุคคลของธนาคารได้โดยการพิมพ์ลิงค์จากรูปภาพที่ปรากฎด้านล่าง
ภาษาไทย (https://krungsri.com/b/privacynoticeth)
ประสบการณ์ที่จำเป็น
- ไม่ระบุประสบการณ์ขั้นต่ำ
เงินเดือน
- สามารถต่อรองได้
สายงาน
- ความปลอดภัย
ประเภทงาน
- งานประจำ
เกี่ยวกับบริษัท
ธนาคารกรุงศรีอยุธยา จำกัด (มหาชน) หรือที่รู้จักกันในชื่อ "กรุงศรี" เป็นธนาคารที่ใหญ่เป็นอันดับห้าในประเทศไทยในด้านสินทรัพย์ เงินให้สินเชื่อ และเงินฝาก ก่อตั้งเมื่อวันที่ 27 มกราคม พ.ศ. 2488 ธนาคารกรุงศรีให้บริการทางการเงินและการธนาคารที่ครบวง ...
ร่วมงานกับเรา: Joining Krungsri means becoming part of a leading financial institution with a rich history and a strong commitment to innovation and excellence. As a member of the MUFG network, employees have access to international expertise and opportunities for global collaboration.&nbs ...
สวัสดิการ
- การพัฒนาเพื่อความเป็นมืออาชีพ
- ประกันสังคม
- โบนัสขึ้นอยู่กับผลประกอบการ
- โครงการส่งเสริมคุณภาพชีวิต
- ประกันทันตกรรม
- ประกันสุขภาพ
- โอกาสในการเรียนรู้และพัฒนา
- ประกันชีวิต
- โบนัสขึ้นอยู่กับผลงาน
- ค่าเดินทาง

