Cyber Security Specialist (Red and Blue Team)
atBank of Ayudhya PCL (Krungsri)Role overview
Red Team: Provide security consultation on new Core Bank and its architecture e.g. application, container and DepSecOps
Blue Team: To provide security design, consulting, implement security tool and support cyber security operations on IT environment
What you'll do
For Red Team
Security Consultation:
1) Provide expert advice on security architecture for applications, cloud (e.g. AWS, Azure, OCP), and on-premises infrastructure.
2) Ensure alignment between business requirements and security controls.
3) Ensure the solution complies with internal policies and external standards (e.g. ISO 27001, NIST CSF, PDPA, BOT, PCI-DSS, etc.)
4) Develop and maintain security documentation (e.g. Security standard, Security requirements, Security hardening guides)Security Assessment:
1) Assess security scope including estimate required efforts for IT project
2) Conduct and coordinate penetration testing, vulnerability assessments, web application scans, and related activities
3) Provide practical recommendations for IT & BU
4) Maintain and follow up the findings
For Blue Team
SOC and Threat Management
1) Monitor, investigate, and respond to security alerts, incidents, and anomalies.
2) Administer and maintain cybersecurity tools, including AV/EDR, Network APT, SOC, SIEM, SOAR, TIP, Email Security, ASM, and Anti-DDoS solutions.
3) Conduct continuous threat intelligence monitoring and provide proactive responses to emerging threats and evolving attack trends.
4) Recommend and implement technical improvements to strengthen security posture based on the changing threat landscape.
5) Monitor, analyze, and escalate critical vulnerabilities; track normal vulnerabilities in alignment with the patch management plan.SOC Enhancement:
1) Develop and maintain SOC use cases, incident categories, dashboard and standardized reporting templates.
2) Maintain and update the SOC asset inventory and asset lookup tables.
3) Design, implement, and enhance automated playbooks to improve incident response efficiency.Operational Support:
Provide daily support for key cyber operations, including:
1) SOC monitoring and incident response
2) Threat intelligence collection, analysis, and management
3) Brand protection and incident response
4) Vulnerability management (critical and normal)
5) Attack Surface Management (ASM) monitoring and remediation
Apply now if you have these advantages
For Red Team
- Minimum of 3-8 years of experience in Information Security design, consulting and assessment (Banking Financial industries are advantage)
- Experience with Security architecture design and consulting
- Experience with Security assessment e.g. penetration tests, source code review, VA scan, DAST
- Experience with Security consulting on DevSecOps, Cloud environment e.g. AWS, Azure is advantage
- Relevant local and international security standards and best practices such as OWASP, NIST, ISO 27001, CIS Controls, SOC 2, PCI-DSS, and PDPA (Thailand)
For Blue Team
- Minimum of 10 years of experiences in Information Security design, Cyber Security Operation, Consulting and assessment (Banking /Financial industries are advantage)
- Experience with Security architecture design and consulting
- Experience with Security tool e.g. EDR, ATP, WAF, IPS/IDS, Deception, TI/TIP, Anti DDoS
- Experience with Security operation related to security event monitoring, incident response, root cause analysis, malware analysis, security monitoring use case development
- Experience with Threat Intelligent management e.g. response to threat intelligent alert, threat hunting, perform proactive incident response against cyber attack event
- Experience with Security Automation e.g. Design and development security automation playbook
- Experience with Cloud Environment e.g. Google Cloud, AWS, Microsoft Azure
- Hands on experience with computer programming languages and/or scripting languages such as Python, Java, Shell for automation.
Relevant local and international security standards and best practices such as OWASP, NIST, ISO 27001, CIS Controls, SOC 2, PCI-DSS, BOT-CRAF, NCSA and PDPA (Thailand)
Why join Krungsri?
- As a part of MUFG (Mitsubishi UFJ Financial Group), we a truly a global bank with networks all over the world.
- We offer a striking work-life balance culture with hybrid work policies (3 days in office per week).
- Unbelievable benefits such as attractive bonuses, employee loan with special rates and many more.
** Apply now before this role is close. **
Stay connected with KRUNGRI CAREER at:
- FB: Krungsri Career(http://bit.ly/FacebookKrungsriCareer [link removed])
- LINE: Krungsri Career (http://bit.ly/LineKrungsriCareer [link removed])
Talent Acquisition Department
Bank of Ayudhya Public Company Limited
1222 Rama III Rd., Bangpongpang, Yannawa, Bangkok 10120
สอบถามข้อมูลเพิ่มเติม : Talent Acquisition Center 0-2•••-•000
หมายเหตุ ธนาคารมีความจำเป็นและจะมีขั้นตอนการตรวจสอบข้อมูลส่วนบุคคลเกี่ยวกับประวัติอาชญากรรมของผู้สมัคร ก่อนที่ผู้สมัครจะได้รับการพิจารณาเข้าร่วมงานกับธนาคารกรุงศรีฯ
Remark: The bank needs to and will have a process for verifying personal information related to the criminal history of applicants before they are considered for employment with the bank.
Applicants can read the Personal Data Protection Announcement of the Bank's Human Resources Function by typing the link from the image that stated below.
EN (https://krungsri.com/b/privacynoticeen)
ผู้สมัครสามารถอ่านประกาศการคุ้มครองข้อมูลส่วนบุคคลส่วนงานทรัพยากรบุคคลของธนาคารได้โดยการพิมพ์ลิงค์จากรูปภาพที่ปรากฎด้านล่าง
ภาษาไทย (https://krungsri.com/b/privacynoticeth)
Experience required
- any or no experience
Salary
- Negotiable
Job function
- Security
Job type
- Full-time
Company overview
Bank of Ayudhya Public Company Limited, commonly known as Krungsri, is the fifth-largest bank in Thailand in terms of assets, loans, and deposits. Established on January 27, 1945, Krungsri offers a comprehensive range of banking and financial services to both individua ...
Why join us: Joining Krungsri means becoming part of a leading financial institution with a rich history and a strong commitment to innovation and excellence. As a member of the MUFG network, employees have access to international expertise and opportunities for global collaboration.&nbs ...
Benefits
- Professional development
- Social Security
- Annual bonus
- Corporate Social Responsibility Initiatives
- Dental Insurance
- Health Insurance
- Learning & Development Opportunities
- Life Insurance
- Performance bonus
- Transport Allowance

