Responsibility

  • Provide consultancy advice to business and project teams to ensure security standards and requirements are considered and implemented.
  • Perform deep dive reviews focused on Cybersecurity Risk, Technology Risk, and Emerging Risk.
  • Effective management of all technology risk and cybersecurity framework including technology policies and standards based on the Group's risk appetite.
  • Closely monitor technology and cyber related KPIs, KRIs, KCIs and drive remediation actions as Group perspective.
  • Timely update on all material technology risk and cybersecurity topics including a set of risk indicators to the relevant Group Risk Committees and forums.
  • Oversight the result of control testing from subsidiaries to ensure Cybersecurity and technology controls meet internal and external compliance requirements.
  • Conduct technology risk assessments: Identify and evaluate potential risks Management with the organization's technology systems, infrastructure, and processes. Assess the adequacy of controls, identify vulnerabilities, and recommend risk mitigation strategies.
  • Develop and implement risk management strategies: Collaborate with stakeholders to develop comprehensive risk management strategies that align with business objectives and regulatory requirements. Implement controls and procedures to mitigate identified risks effectively.
  • Monitor technology risk exposure: Continuously monitor technology systems, networks, and processes to identify emerging risks, vulnerabilities, and trends. Stay up-to-date with industry developments, emerging technologies, and regulatory changes to proactively address potential risks.
  • Perform risk analysis and reporting: Analyze risk assessment findings, internal control evaluations, and audit reports to identify trends, root causes, and areas of improvement. Prepare detailed reports on risk exposure, mitigation strategies, and recommendations for management and relevant stakeholders.
  • Collaborate with cross-functional teams: Work closely with IT teams, compliance officers, cybersecurity professionals, and other stakeholders to develop and implement risk management frameworks, policies, and procedures. Provide guidance and recommendations on technology-related risk management activities.
  • Conduct technology risk training and awareness programs: Develop and deliver training programs to educate employees on technology risk management best practices, policies, and procedures. Raise awareness about emerging threats and provide guidance on incident response protocols.
  • Assist in incident response and recovery: Support the organization in managing technology-related incidents, including data breaches, system failures, and cybersecurity threats. Coordinate response efforts, assist in recovery measures, and contribute to post-incident reviews and lessons learned.
  • Stay updated on industry standards and regulations: Keep abreast of industry trends, emerging technologies, and regulatory requirements related to technology risk management. Provide recommendations on incorporating best practices into the organization's risk management framework.


Qualification

  • Minimum of 5 years' experience in Technology and Cyber Risk.
  • Bachelor's degree or above in related discipline.
  • Working experience or familiar in a group public company.
  • Understanding of regulatory requirements such as BOT, OIC, and SEC; industry standards such as COBIT, NIST, ISO27001, ITIL, and PCIDSS.
  • Experience in one or more emerging technologies such as Artificial Intelligence, Machine Learning, Distributed Ledger Technology, Robotic Process Automation, Cloud computing.
  • Excellent communication and relationship building skills; proven ability to influence senior management.
  • Good command of written and spoken in English is preferable.
āļ›āļĢāļ°āļŠāļšāļāļēāļĢāļ“āđŒāļ—āļĩāđˆāļˆāļģāđ€āļ›āđ‡āļ™
  • āđ„āļĄāđˆāļĢāļ°āļšāļļāļ›āļĢāļ°āļŠāļšāļāļēāļĢāļ“āđŒāļ‚āļąāđ‰āļ™āļ•āđˆāļģ
āđ€āļ‡āļīāļ™āđ€āļ”āļ·āļ­āļ™
  • āļŠāļēāļĄāļēāļĢāļ–āļ•āđˆāļ­āļĢāļ­āļ‡āđ„āļ”āđ‰
āļŠāļēāļĒāļ‡āļēāļ™
  • āđ„āļ­āļ—āļĩ / āđ€āļ‚āļĩāļĒāļ™āđ‚āļ›āļĢāđāļāļĢāļĄ
  • āļ™āļąāļāļ§āļīāđ€āļ„āļĢāļēāļ°āļŦāđŒ
āļ›āļĢāļ°āđ€āļ āļ—āļ‡āļēāļ™
  • āļ‡āļēāļ™āļ›āļĢāļ°āļˆāļģ

āđ€āļāļĩāđˆāļĒāļ§āļāļąāļšāļšāļĢāļīāļĐāļąāļ—

āļˆāļģāļ™āļ§āļ™āļžāļ™āļąāļāļ‡āļēāļ™:100-500 āļ„āļ™
āļ›āļĢāļ°āđ€āļ āļ—āļšāļĢāļīāļĐāļąāļ—:āļāļēāļĢāđ€āļ‡āļīāļ™āđāļĨāļ°āļāļēāļĢāļ˜āļ™āļēāļ„āļēāļĢ
āļ—āļĩāđˆāļ•āļąāđ‰āļ‡āļšāļĢāļīāļĐāļąāļ—:āļāļĢāļļāļ‡āđ€āļ—āļž
āđ€āļ§āđ‡āļšāđ„āļ‹āļ•āđŒ:www.scbx.com
āļāđˆāļ­āļ•āļąāđ‰āļ‡āđ€āļĄāļ·āđˆāļ­āļ›āļĩ:1906

SCBX āđ€āļ›āđ‡āļ™āļĒāļēāļ™āđāļĄāđˆāļ‚āļ­āļ‡āļāļĨāļļāđˆāļĄāļ˜āļļāļĢāļāļīāļˆāđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩāļ—āļēāļ‡āļāļēāļĢāđ€āļ‡āļīāļ™ āđ‚āļ”āļĒāļĄāļĩ āļ˜āļ™āļēāļ„āļēāļĢāđ„āļ—āļĒāļžāļēāļ“āļīāļŠāļĒāđŒ āļšāļĢāļīāļĐāļąāļ— āđ€āļ­āļŠāļ‹āļĩāļšāļĩ āđ€āļ—āđ‡āļ™āđ€āļ­āļāļ‹āđŒ āļˆāļģāļāļąāļ” āļšāļĢāļīāļĐāļąāļ— āļ„āļēāļĢāđŒāļ” āđ€āļ­āļāļ‹āđŒ āļˆāļģāļāļąāļ” āļšāļĢāļīāļĐāļąāļ—āļŦāļĨāļąāļāļ—āļĢāļąāļžāļĒāđŒ āļ­āļīāļ™āđ‚āļ™āđ€āļ§āļŠāļ—āđŒ āđ€āļ­āļāļ‹āđŒ āļˆāļģāļāļąāļ”āļšāļĢāļīāļĐāļąāļ— āđ€āļžāļ­āļĢāđŒāđ€āļžāļīāļĨ āđ€āļ§āļ™āđ€āļˆāļ­āļĢāđŒāļŠ āļˆāļģāļāļąāļ” āđāļĨāļ°āļšāļĢāļīāļĐāļąāļ—āļ­āļ·āđˆāļ™āđ† āļĄāļĩāļĒāļļāļ—āļ˜āļĻāļēāļŠāļ•āļĢāđŒāļĄāļļāđˆāļ‡āļŠāļđāđˆāļāļēāļĢāđ€āļ›āđ‡āļ™āļāļĨāļļāđˆāļĄāļšāļĢāļīāļĐāļąāļ—āđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩāļ—āļēāļ‡āļāļēāļĢāđ€āļ‡āļīāļ™āļĢāļ°āļ”āļąāļšāļ āļđāļĄāļī ...

āļ­āđˆāļēāļ™āļ•āđˆāļ­

āļĢāđˆāļ§āļĄāļ‡āļēāļ™āļāļąāļšāđ€āļĢāļē:

āļ—āļĩāđˆ SCB X āļ„āļļāļ“āļˆāļ°āđ„āļ”āđ‰āđ€āļ›āđ‡āļ™āļŠāđˆāļ§āļ™āļŦāļ™āļķāđˆāļ‡āļ‚āļ­āļ‡āļ­āļ‡āļ„āđŒāļāļĢāļ—āļĩāđˆāļāđ‰āļēāļ§āļĨāđ‰āļģāļŠāļđāđˆāļ­āļ™āļēāļ„āļ• āļžāļĢāđ‰āļ­āļĄāļžāļĨāļīāļāđ‚āļ‰āļĄāļ§āļ‡āļāļēāļĢāļāļēāļĢāđ€āļ‡āļīāļ™āđāļšāļšāļ”āļąāđ‰āļ‡āđ€āļ”āļīāļĄāļœāđˆāļēāļ™āļ™āļ§āļąāļ•āļāļĢāļĢāļĄāđāļĨāļ°āđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩ āđ€āļĢāļēāļĄāļĩāļŠāļ āļēāļžāđāļ§āļ”āļĨāđ‰āļ­āļĄāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ—āđ‰āļēāļ—āļēāļĒāđāļĨāļ°āđ€āļ›āļīāļ”āļāļ§āđ‰āļēāļ‡āļŠāļģāļŦāļĢāļąāļšāđ„āļ­āđ€āļ”āļĩāļĒāđƒāļŦāļĄāđˆ āđ† āđāļĨāļ°āđƒāļŦāđ‰āđ‚āļ­āļāļēāļŠāļ„āļļāļ“āđ„āļ”āđ‰āļ—āļģāļ‡āļēāļ™āļĢāđˆāļ§āļĄāļāļąāļšāļ—āļĩāļĄāļ—āļĩāđˆāļĄāļĩāļ„āļ§āļēāļĄāđ€āļŠāļĩāđˆāļĒāļ§āļŠāļēāļāļŦāļĨāļēāļāļŦāļĨāļēāļĒ

āđ€āļĢāļēāļŠāđˆāļ‡āđ€āļŠāļĢāļīāļĄāļ§āļąāļ’āļ™āļ˜āļĢāļĢāļĄāļ­āļ‡āļ„āđŒāļāļĢāļ—āļĩāđˆāđƒāļŦāđ‰āļ„ ...

āļ­āđˆāļēāļ™āļ•āđˆāļ­

āļŠāļģāļ™āļąāļāļ‡āļēāļ™āđƒāļŦāļāđˆ: 9 āļ–āļ™āļ™āļĢāļąāļŠāļ”āļēāļ āļīāđ€āļĐāļ āđ€āļ‚āļ•āļˆāļ•āļļāļˆāļąāļāļĢ āļāļĢāļļāļ‡āđ€āļ—āļžāļŊ 10900
Display map

āļŠāļ§āļąāļŠāļ”āļīāļāļēāļĢ

  • āļ—āļģāļ‡āļēāļ™āļ™āļ­āļāļŠāļ–āļēāļ™āļ—āļĩāđˆ
  • āđ‚āļšāļ™āļąāļŠāļœāļąāļ™āđāļ›āļĢ
  • āļāļēāļĢāļ—āļģāļ‡āļēāļ™āđāļšāļšāđ„āļŪāļšāļĢāļīāļ”
āļ—āļĩāđˆ WorkVenture āđ€āļĢāļēāđƒāļŦāđ‰āļĄāļđāļĨāđ€āļŠāļīāļ‡āđ€āļāļĩāđˆāļĒāļ§āļāļąāļšāļšāļĢāļīāļĐāļąāļ— SCB X PCL āđ‚āļ”āļĒāļĄāļĩāļ‚āđ‰āļ­āļĄāļđāļĨāļ—āļĩāđˆāđ€āļāļĩāđˆāļĒāļ§āļ‚āđ‰āļ­āļ‡ āļ•āļąāđ‰āļ‡āđāļ•āđˆāļ āļēāļžāļšāļĢāļĢāļĒāļēāļāļēāļĻāļāļēāļĢāļ—āļģāļ‡āļēāļ™ āļĢāļđāļ›āļ–āđˆāļēāļĒāļ‚āļ­āļ‡āļ—āļĩāļĄāļ‡āļēāļ™ āđ„āļ›āļˆāļ™āļ–āļķāļ‡āļĢāļĩāļ§āļīāļ§āđ€āļŠāļīāļ‡āļĨāļķāļāļ‚āļ­āļ‡āļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ™āļąāđˆāļ™ āļ‹āļķāđˆāļ‡āļ‚āđ‰āļ­āļĄāļđāļĨāļ—āļļāļāļ­āļĒāđˆāļēāļ‡āļšāļ™āļŦāļ™āđ‰āļēāļ‚āļ­āļ‡āļšāļĢāļīāļĐāļąāļ— SCB X PCL āļĄāļĩāļžāļ™āļąāļāļ‡āļēāļ™āļ—āļĩāđˆāļāļģāļĨāļąāļ‡āļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļšāļĢāļīāļĐāļąāļ— SCB X PCL āļŦāļĢāļ·āļ­āđ€āļ„āļĒāļ—āļģāļ‡āļēāļ™āļ—āļĩāđˆāļ™āļąāđˆāļ™āļˆāļĢāļīāļ‡āđ† āđ€āļ›āđ‡āļ™āļ„āļ™āđƒāļŦāđ‰āļ‚āđ‰āļ­āļĄāļđāļĨāļˆāļĢāļīāļ‡āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļ™āļąāļ™āļĒāļēāļ‡āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āļ™āļīāļ›āļ›āļ­āļ™ āđāļžāđ‡āļ„āđ€āļāļˆāļˆāļīāđ‰āļ‡āļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ āđ‚āļžāļĨāļ›āđ‰āļēāļŠāļĄāļąāļ„āļĢāļ‡āļēāļ™ WV