āļāļĢāļ°āļāļēāļĻāļāļēāļāļāļĩāđāļŦāļĄāļāļāļēāļĒāļļāđāļĨāđāļ§
Lead Cyber Security (Key & Vault Management Specialist)
āļāļĩāđāļāļāļēāļāļēāļĢāļāļĢāļļāļāļĻāļĢāļĩāļāļĒāļļāļāļĒāļē āļāļģāļāļąāļ (āļĄāļŦāļēāļāļ)Scope Overview
Implement, and operate enterprise-grade cryptographic key management and secrets management solutions within a banking environment. The role will be responsible for ensuring secure key lifecycle management, HSM operations, vault administration, and compliance with regulatory and security standards.
Hands-on experience with Thales Luna HSM is highly preferred.
What you'll do
Cryptographic Key Management
- Manage end-to-end cryptographic key lifecycle (generation, distribution, rotation, backup, archival, destruction).
- Administer and operate Hardware Security Modules (HSMs), preferably Thales Luna HSM.
- Define and enforce key management policies and procedures aligned with banking regulations and industry standards (e.g., PCI DSS, ISO 27001).
- Support encryption key integration across banking applications, core systems, payment systems, and digital channels.
- Conduct key ceremonies and maintain audit logs.
Vault & Secrets Management
- Administer enterprise vault platforms (e.g., HashiCorp Vault or similar).
- Manage secrets lifecycle (API keys, certificates, tokens, database credentials).
- Configure access control policies, role-based access, and segregation of duties.
- Integrate vault solutions with applications, DevOps pipelines, and cloud/on-prem infrastructure.
- Monitor vault security posture and perform regular health checks.
Security & Compliance
- Ensure compliance with regulatory requirements (BOT, PCI DSS, SWIFT CSP, etc.).
- Perform risk assessments related to cryptographic controls.
- Support audit activities and provide evidence for internal/external auditors.
- Participate in incident response related to key compromise or vault breaches.
Architecture & Improvement
- Contribute to cryptographic architecture design and secure key management framework.
- Support post-quantum cryptography transition planning (if applicable).
- Recommend best practices and continuous improvements for key and secrets management.
Apply now if you have these advantages
- Bachelorâs degree or higher in computer science/ data science or any related field.
Minimum of 3-7 years of experience in Information Security or Cryptography (Banking Financial industries are advantage)
· 3â7+ years of experience in Information Security or Cryptography.
· Hands-on experience with HSM (Thales Luna preferred).
· Experience in Vault or Secrets Management platforms (e.g., HashiCorp Vault).
· Experience in banking or financial services environment is highly preferred.- Strong understanding of cryptographic principles (PKI, symmetric/asymmetric encryption, TLS, key wrapping, key derivation).
- Experience with key lifecycle management processes.
- Knowledge of PKI, certificate management, and CA integration.
- Familiarity with PCI DSS encryption requirements.
- Scripting skills (e.g., Bash, Python, PowerShell) are a plus
Why join Krungsri?
- As a part of MUFG (Mitsubishi UFJ Financial Group), we a truly a global bank with networks all over the world.
- We offer a striking work-life balance culture with hybrid work policies (3 days in office per week).
- Unbelievable benefits such as attractive bonuses, employee loan with special rates and many more.
** Apply now before this role is close. **
Stay connected with KRUNGRI CAREER at:
- FB: Krungsri Career(http://bit.ly/FacebookKrungsriCareer [link removed])
- LINE: Krungsri Career (http://bit.ly/LineKrungsriCareer [link removed])
Talent Acquisition Department
Bank of Ayudhya Public Company Limited
1222 Rama III Rd., Bangpongpang, Yannawa, Bangkok 10120
āļŦāļĄāļēāļĒāđāļŦāļāļļ āļāļāļēāļāļēāļĢāļĄāļĩāļāļ§āļēāļĄāļāļģāđāļāđāļāđāļĨāļ°āļāļ°āļĄāļĩāļāļąāđāļāļāļāļāļāļēāļĢāļāļĢāļ§āļāļŠāļāļāļāđāļāļĄāļđāļĨāļŠāđāļ§āļāļāļļāļāļāļĨāđāļāļĩāđāļĒāļ§āļāļąāļāļāļĢāļ°āļ§āļąāļāļīāļāļēāļāļāļēāļāļĢāļĢāļĄāļāļāļāļāļđāđāļŠāļĄāļąāļāļĢ āļāđāļāļāļāļĩāđāļāļđāđāļŠāļĄāļąāļāļĢāļāļ°āđāļāđāļĢāļąāļāļāļēāļĢāļāļīāļāļēāļĢāļāļēāđāļāđāļēāļĢāđāļ§āļĄāļāļēāļāļāļąāļāļāļāļēāļāļēāļĢāļāļĢāļļāļāļĻāļĢāļĩāļŊ
Remark: The bank needs to and will have a process for verifying personal information related to the criminal history of applicants before they are considered for employment with the bank.
Applicants can read the Personal Data Protection Announcement of the Bank's Human Resources Function by typing the link from the image that stated below.
EN (https://krungsri.com/b/privacynoticeen)
āļāļđāđāļŠāļĄāļąāļāļĢāļŠāļēāļĄāļēāļĢāļāļāđāļēāļāļāļĢāļ°āļāļēāļĻāļāļēāļĢāļāļļāđāļĄāļāļĢāļāļāļāđāļāļĄāļđāļĨāļŠāđāļ§āļāļāļļāļāļāļĨāļŠāđāļ§āļāļāļēāļāļāļĢāļąāļāļĒāļēāļāļĢāļāļļāļāļāļĨāļāļāļāļāļāļēāļāļēāļĢāđāļāđāđāļāļĒāļāļēāļĢāļāļīāļĄāļāđāļĨāļīāļāļāđāļāļēāļāļĢāļđāļāļ āļēāļāļāļĩāđāļāļĢāļēāļāļāļāđāļēāļāļĨāđāļēāļ
āļ āļēāļĐāļēāđāļāļĒ (https://krungsri.com/b/privacynoticeth)
āļāļĢāļ°āļŠāļāļāļēāļĢāļāđāļāļĩāđāļāļģāđāļāđāļ
- āđāļĄāđāļĢāļ°āļāļļāļāļĢāļ°āļŠāļāļāļēāļĢāļāđāļāļąāđāļāļāđāļģ
āđāļāļīāļāđāļāļ·āļāļ
- āļŠāļēāļĄāļēāļĢāļāļāđāļāļĢāļāļāđāļāđ
āļŠāļēāļĒāļāļēāļ
- āļāļ§āļēāļĄāļāļĨāļāļāļ āļąāļĒ
āļāļĢāļ°āđāļ āļāļāļēāļ
- āļāļēāļāļāļĢāļ°āļāļģ
āđāļāļĩāđāļĒāļ§āļāļąāļāļāļĢāļīāļĐāļąāļ
āļāļāļēāļāļēāļĢāļāļĢāļļāļāļĻāļĢāļĩāļāļĒāļļāļāļĒāļē āļāļģāļāļąāļ (āļĄāļŦāļēāļāļ) āļŦāļĢāļ·āļāļāļĩāđāļĢāļđāđāļāļąāļāļāļąāļāđāļāļāļ·āđāļ "āļāļĢāļļāļāļĻāļĢāļĩ" āđāļāđāļāļāļāļēāļāļēāļĢāļāļĩāđāđāļŦāļāđāđāļāđāļāļāļąāļāļāļąāļāļŦāđāļēāđāļāļāļĢāļ°āđāļāļĻāđāļāļĒāđāļāļāđāļēāļāļŠāļīāļāļāļĢāļąāļāļĒāđ āđāļāļīāļāđāļŦāđāļŠāļīāļāđāļāļ·āđāļ āđāļĨāļ°āđāļāļīāļāļāļēāļ āļāđāļāļāļąāđāļāđāļĄāļ·āđāļāļ§āļąāļāļāļĩāđ 27 āļĄāļāļĢāļēāļāļĄ āļ.āļĻ. 2488 āļāļāļēāļāļēāļĢāļāļĢāļļāļāļĻāļĢāļĩāđāļŦāđāļāļĢāļīāļāļēāļĢāļāļēāļāļāļēāļĢāđāļāļīāļāđāļĨāļ°āļāļēāļĢāļāļāļēāļāļēāļĢāļāļĩāđāļāļĢāļāļ§āļ ...
āļĢāđāļ§āļĄāļāļēāļāļāļąāļāđāļĢāļē: Joining Krungsri means becoming part of a leading financial institution with a rich history and a strong commitment to innovation and excellence. As a member of the MUFG network, employees have access to international expertise and opportunities for global collaboration.&nbs ...
āļŠāļ§āļąāļŠāļāļīāļāļēāļĢ
- āļāļēāļĢāļāļąāļāļāļēāđāļāļ·āđāļāļāļ§āļēāļĄāđāļāđāļāļĄāļ·āļāļāļēāļāļĩāļ
- āļāļĢāļ°āļāļąāļāļŠāļąāļāļāļĄ
- āđāļāļāļąāļŠāļāļķāđāļāļāļĒāļđāđāļāļąāļāļāļĨāļāļĢāļ°āļāļāļāļāļēāļĢ
- āđāļāļĢāļāļāļēāļĢāļŠāđāļāđāļŠāļĢāļīāļĄāļāļļāļāļ āļēāļāļāļĩāļ§āļīāļ
- āļāļĢāļ°āļāļąāļāļāļąāļāļāļāļĢāļĢāļĄ
- āļāļĢāļ°āļāļąāļāļŠāļļāļāļ āļēāļ
- āđāļāļāļēāļŠāđāļāļāļēāļĢāđāļĢāļĩāļĒāļāļĢāļđāđāđāļĨāļ°āļāļąāļāļāļē
- āļāļĢāļ°āļāļąāļāļāļĩāļ§āļīāļ
- āđāļāļāļąāļŠāļāļķāđāļāļāļĒāļđāđāļāļąāļāļāļĨāļāļēāļ
- āļāđāļēāđāļāļīāļāļāļēāļ

