- No elements found. Consider changing the search query.
Experience:
3 years required
Skills:
Quality Assurance, Assurance
Job type:
Full-time
Salary:
฿25,000 - ฿35,000, negotiable
- ควบคุมการจัดเก็บ การแจกจ่าย การแก้ไข และการยกเลิกเอกสารในระบบ Document Control.
- จัดทำ ทบทวน และควบคุมเอกสารในระบบบริหารคุณภาพ เช่น SOP, WI, แบบฟอร์ม และบันทึกคุณภาพ ให้เป็นไปตามข้อกำหนดของบริษัทและมาตรฐานที่เกี่ยวข้อง.
- ติดตาม ตรวจสอบ และประเมินการปฏิบัติงานให้เป็นไปตามนโยบาย ขั้นตอนการทำงาน และข้อกำหนดด้านคุณภาพ.
- วางแผนและดำเนินการตรวจติดตามคุณภาพภายใน.
- จัดทำ รวบรวม และวิเคราะห์ข้อมูลด้านคุณภาพ พร้อมจัดทำรายงานผลการดำเนินงาน.
- ประสานงานกับหน่วยงานต่าง ๆ เพื่อพัฒนาและปรับปรุงกระบวนการทำงานให้มีประสิทธิภาพและสอดคล้องกับมาตรฐานคุณภาพ.
- ไม่จำกัดเพศ.
- อายุไม่เกิน 40 ปี.
- สำเร็จการศึกษาระดับปริญญาตรี สาขาวิทยาศาสตร์, เทคโนโลยีการแพทย์, ชีววิทยา, เทคโนโลยีชีวภาพ, เคมี, เภสัชศาสตร์, วิศวกรรมศาสตร์ หรือสาขาอื่นที่เกี่ยวข้อง.
- มีประสบการณ์ด้านการประกันคุณภาพ / การควบคุมคุณภาพ หรือระบบบริหารคุณภาพ (QMS) อย่างน้อย 1 - 3 ปี (หากเป็นผู้สำเร็จการศึกษาใหม่และมีประสบการณ์ฝึกงานด้าน QA สามารถพิจารณาได้).
- มีความรู้เกี่ยวกับมาตรฐานและระบบคุณภาพ เช่น ISO 9001, ISO 13485.
- มีความรู้ด้านการจัดทำและควบคุมเอกสารคุณภาพ.
- มีทักษะการใช้ Microsoft Office โดยเฉพาะ Excel, Word และ PowerPoint.
Skills:
ISO 27001, Compliance
Job type:
Full-time
Salary:
negotiable
- IT Governance: สอบทานโครงสร้างการบริหารจัดการ การจัดทำและบังคับใช้นโยบายความมั่นคงปลอดภัยสารสนเทศ และความสอดคล้องกับทิศทางธุรกิจ.
- IT Infrastructure: ตรวจสอบความปลอดภัยของระบบเครือข่าย ระบบเซิร์ฟเวอร์ ระบบคลาวด์ การบริหารจัดการฐานข้อมูล รวมถึงความพร้อมของแผนรองรับการดำเนินธุรกิจต่อเนื่อง (BCP) และแผนฟื้นฟูระบบจากภัยพิบัติ (DRP).
- IT Application: ตรวจสอบการบริหารจัดการสิทธิ์การเข้าถึงระบบงาน (Access Control), ความปลอดภัยของระบบสารสนเทศ และการควบคุมความถูกต้องในการประมวลผลข้อมูลที่สำคัญตามมาตรฐานค ...
- วิเคราะห์และรายงานผลข้อตรวจพบ โดยแปลงประเด็นความเสี่ยงเชิงเทคนิคให้สะท้อนถึงผลกระทบต่อการดำเนินธุรกิจ พร้อมข้อเสนอแนะที่สามารถนำไปปฏิบัติได้จริง.
- ติดตามผลความคืบหน้าในการปรับปรุงแก้ไขตามข้อเสนอแนะร่วมกับหน่วยงานที่เกี่ยวข้องอย่างต่อเนื่อง.
- การให้คำปรึกษาและวางมาตรการควบคุมเชิงป้องกัน (IT Advisory & Preventive Controls).
- ร่วมประเมินความเสี่ยงและให้ข้อเสนอแนะด้านการควบคุมภายในเชิงป้องกัน (Preventive Recommendations) แก่โครงการพัฒนาระบบหรือโครงการริเริ่มใหม่ตั้งแต่ระยะเริ่มต้น (Pre-implementation Review) โดยไม่กระทบต่อความเป็นอิสระในการตรวจสอบ.
- สอบทานและให้ข้อเสนอแนะในการปรับปรุงขั้นตอนการปฏิบัติงาน และนโยบายด้านเทคโนโลยีสารสนเทศ เพื่อเพิ่มประสิทธิภาพการทำงานและสอดคล้องกับมาตรฐานความปลอดภัย.
- ประสานงานกับหน่วยงานเจ้าของระบบงาน เพื่อส่งเสริมความตระหนักรู้ด้านความเสี่ยงและการควบคุมภายในเชิงรุก.
- สำเร็จการศึกษาระดับปริญญาตรีขึ้นไป สาขาเทคโนโลยีสารสนเทศ วิทยาการคอมพิวเตอร์ ระบบสารสนเทศเพื่อการจัดการ (MIS) บัญชีระบบสารสนเทศ หรือสาขาอื่นที่เกี่ยวข้อง.
- มีประสบการณ์การทำงานตรงด้านการตรวจสอบระบบสารสนเทศ (IT Audit) การกำกับดูแลด้านไอที (IT Compliance) หรือที่ปรึกษาด้านความเสี่ยงไอที (IT Advisory) ไม่น้อยกว่า 5 ปี.
- มีประสบการณ์ในการนำมาตรฐาน ISO 27001 มาใช้ในการตรวจประเมินหรือวางระบบการควบคุมภายในองค์กร.
- มีประสบการณ์ในการร่วมประเมินความเสี่ยงหรือสอบทานโครงการพัฒนาระบบงานใหม่.
- มีความรู้ความเข้าใจในโครงสร้างสถาปัตยกรรมระบบ (Network, Cloud, Database) สิทธิ์การเข้าใช้งานระบบ และกระบวนการ BCP/DRP.
- มีทักษะการสื่อสาร การนำเสนอ และการเจรจาต่อรองที่ดี สามารถอธิบายประเด็นเชิงเทคนิคให้ผู้บริหารและผู้ปฏิบัติงานสายธุรกิจเข้าใจได้อย่างชัดเจน.
- มีทัศนคติในการทำงานเชิงร่วมมือ (Collaborative mindset) เพื่อสนับสนุนการดำเนินงานของธุรกิจควบคู่กับการกำกับความเสี่ยง.
- ได้รับการรับรองคุณวุฒิวิชาชีพ เช่น CISA, ISO 27001 Lead Auditor / Implementer หรือ CRISC.
Skills:
ISO 27001, ISO 14001, ISO 9001
Job type:
Full-time
Salary:
negotiable
- IATF 16949 Auditor.
- ISO 27001, ISO 14064 or Sustainability Standards (Carbon Footprint or RSPO) at client's organizations.
- Conduct 3rd Party Certification Audits for IATF 16949, ISO 9001, ISO 14001, ISO 45001, ISO 50001.
- Prepare audit plans and audit reports in accordance with Certification Body procedures.
- Identify audit findings and communicate them professionally to clients.
- Evaluate corrective actions and verify effectiveness.
- Complete audit documentation within the required timeline.
- Maintain impartiality and comply with Certification Body requirements.
- Travel to client sites throughout Thailand when required.
- Bachelor's Degree or higher in Engineering, Science or related fields.
- (for ISO9001, ISO14001, ISO 45001, ISO 27001, ISO 14064). At least 2 years full time of professional experience in manufacturing, QA, Engineering.
- (for IATF 16949 auditor) At least 4 years full time of professional experience (including 2 years dedicated to Quality Assurance and/or Quality Management activities) in automotive industry within the past 12 years.
- Having IRCA registered Lead Assessor training certificate - preferable.
- Qualified as an auditor from CB - preferable.
- Able to travel within Asia and up-country.
- Medical Insurance.
- Annual Leave: 15 - 20 days.
- Medical Insurance IPD/OPD.
- Accident Insurance.
- Provident fund.
- Hybrid work.
- Dental care.
- Commission (for Sales).
- Travel expenses.
- All applicants shall have good command of read, written and spoken English and computer literacy.
- We offer attractive salary commensurate with experience and abilities, career development opportunities and generous fringe benefits such as health, life and accident insurance, annual bonus and provident fund to the successful candidate.
Experience:
2 years required
Skills:
Leadership Skill, ISO 27001, English, Thai
Job type:
Full-time
Salary:
negotiable
Job Summary The Cyber Security Manager will oversee the security of the organization's digital infrastructure and information systems. This role is responsible for developing, implementing, and maintaining security strategies, policies, and procedures to protect data and systems from cyber threats, including data breaches, hacking, malware, and other risks. The Cyber Security Manager will lead a team of cybersecurity professionals both inhouse and outsourced as well as work closely with IT and other departments, and stay up-to-date with industry best practices and compliance requir ...
Skills:
ISO 27001, Automation, Python
Job type:
Full-time
Salary:
negotiable
- Red Team: Provide security consultation on new Core Bank and its architecture e.g. application, container and DepSecOps.
- Blue Team: To provide security design, consulting, implement security tool and support cyber security operations on IT environment.
- For Red Team.
- Security Consultation: 1) Provide expert advice on security architecture for applications, cloud (e.g. AWS, Azure, OCP), and on-premises infrastructure. 2) Ensure alignment between business requirements and security controls. 3) Ensure the solution complies with internal policies and external standards (e.g. ISO 27001, NIST CSF, PDPA, BOT, PCI-DSS, etc.) 4) Develop and maintain security documentation (e.g. Security standard, Security requirements, Security hardening guides).
- Security Assessment: 1) Assess security scope including estimate required efforts for IT project 2) Conduct and coordinate penetration testing, vulnerability assessments, web application scans, and related activities 3) Provide practical recommendations for IT & BU 4) Maintain and follow up the findings.
- For Blue Team.
- SOC and Threat Management 1) Monitor, investigate, and respond to security alerts, incidents, and anomalies. 2) Administer and maintain cybersecurity tools, including AV/EDR, Network APT, SOC, SIEM, SOAR, TIP, Email Security, ASM, and Anti-DDoS solutions. 3) Conduct continuous threat intelligence monitoring and provide proactive responses to emerging threats and evolving attack trends. 4) Recommend and implement technical improvements to strengthen security posture based on the changing threat landscape. 5) Monitor, analyze, and escalate critical vulnerabilities; track normal vulnerabilities in alignment with the patch management plan..
- SOC Enhancement: 1) Develop and maintain SOC use cases, incident categories, dashboard and standardized reporting templates. 2) Maintain and update the SOC asset inventory and asset lookup tables. 3) Design, implement, and enhance automated playbooks to improve incident response efficiency..
- Operational Support: Provide daily support for key cyber operations, including: 1) SOC monitoring and incident response 2) Threat intelligence collection, analysis, and management 3) Brand protection and incident response 4) Vulnerability management (critical and normal) 5) Attack Surface Management (ASM) monitoring and remediation.
- Apply now if you have these advantages.
- For Red Team.
- Minimum of 3-8 years of experience in Information Security design, consulting and assessment (Banking Financial industries are advantage).
- Experience with Security architecture design and consulting.
- Experience with Security assessment e.g. penetration tests, source code review, VA scan, DAST.
- Experience with Security consulting on DevSecOps, Cloud environment e.g. AWS, Azure is advantage.
- Relevant local and international security standards and best practices such as OWASP, NIST, ISO 27001, CIS Controls, SOC 2, PCI-DSS, and PDPA (Thailand).
- For Blue Team.
- Minimum of 10 years of experiences in Information Security design, Cyber Security Operation, Consulting and assessment (Banking /Financial industries are advantage).
- Experience with Security architecture design and consulting.
- Experience with Security tool e.g. EDR, ATP, WAF, IPS/IDS, Deception, TI/TIP, Anti DDoS.
- Experience with Security operation related to security event monitoring, incident response, root cause analysis, malware analysis, security monitoring use case development.
- Experience with Threat Intelligent management e.g. response to threat intelligent alert, threat hunting, perform proactive incident response against cyber attack event.
- Experience with Security Automation e.g. Design and development security automation playbook.
- Experience with Cloud Environment e.g. Google Cloud, AWS, Microsoft Azure.
- Hands on experience with computer programming languages and/or scripting languages such as Python, Java, Shell for automation.
- Relevant local and international security standards and best practices such as OWASP, NIST, ISO 27001, CIS Controls, SOC 2, PCI-DSS, BOT-CRAF, NCSA and PDPA (Thailand).
- Why join Krungsri?.
- As a part of MUFG (Mitsubishi UFJ Financial Group), we a truly a global bank with networks all over the world.
- We offer a striking work-life balance culture with hybrid work policies (3 days in office per week).
- Unbelievable benefits such as attractive bonuses, employee loan with special rates and many more.
- Apply now before this role is close. **.
- FB: Krungsri Career(http://bit.ly/FacebookKrungsriCareer [link removed]).
- LINE: Krungsri Career (http://bit.ly/LineKrungsriCareer [link removed]).
- Talent Acquisition Department.
- Bank of Ayudhya Public Company Limited.
- 1222 Rama III Rd., Bangpongpang, Yannawa, Bangkok 10120.
- สอบถามข้อมูลเพิ่มเติม: Talent Acquisition Center 0-2-----000.
- หมายเหตุ ธนาคารมีความจำเป็นและจะมีขั้นตอนการตรวจสอบข้อมูลส่วนบุคคลเกี่ยวกับประวัติอาชญากรรมของผู้สมัคร ก่อนที่ผู้สมัครจะได้รับการพิจารณาเข้าร่วมงานกับธนาคารกรุงศรีฯ.
- Remark: The bank needs to and will have a process for verifying personal information related to the criminal history of applicants before they are considered for employment with the bank.
- Applicants can read the Personal Data Protection Announcement of the Bank's Human Resources Function by typing the link from the image that stated below.
- EN (https://krungsri.com/b/privacynoticeen).
- ผู้สมัครสามารถอ่านประกาศการคุ้มครองข้อมูลส่วนบุคคลส่วนงานทรัพยากรบุคคลของธนาคารได้โดยการพิมพ์ลิงค์จากรูปภาพที่ปรากฎด้านล่าง.
- ภาษาไทย (https://krungsri.com/b/privacynoticeth).
Experience:
5 years required
Skills:
Risk Management, ISO 27001
Job type:
Full-time
Salary:
negotiable
- Oversee and be responsible for creating, reviewing, updating, and maintaining documents related to the organization's management system standards, such as ISO/IEC 27701, ISO/IEC 27001, or other relevant future standards.
- Manage and organize documents (including ROPA, DPIA, LIA, and other related documents) systematically and ensure they are traceable and auditable.
- Coordinate with relevant departments to prepare for internal and external audits and follow up on closing any observations or gaps identified.
- Participate in and support the review of internal policies and processes to ensure alignment with relevant standards and best practices.
- Coordinate with technology, data, and other support departments to ensure compliance with applicable standards.
- Regulatory Compliance.
- Monitor, track, execute, coordinate, and advise to ensure the company's operations comply with laws, regulations, and business standards.
- Manage and coordinate requirements from ETDA, NCSA, or other relevant regulatory bodies, including related conditions and practices such as Terms of Use / Terms & Conditions, digital platform requirements, cybersecurity best practices, and others.
- Support the review, update, and preparation of documents, such as Terms of Use and Privacy Notices.
- Monitor incidents related to personal data or legal/regulatory matters and support response processes if needed, including supporting the Data Protection Officer (DPO) in tasks such as recording and storing data subject requests, preparing DPO appointment announcements, and other relevant documents.
- Provide guidance to employees and stakeholders on compliance with personal data protection laws or other relevant regulations, including conducting annual training on data protection, information security, and legal compliance.
- Customer Questionnaire & Documentation.
- Responsible for responding to customer questionnaires, forms, assessments, and documents acknowledging policies related to legal compliance, data security standards, and company policies.
- Coordinate with relevant departments to ensure accurate responses.
- Maintain completed questionnaires as evidence for future audits.
- Risk Management.
- Participate in and support risk identification, risk assessment, and monitoring of controls according to the Enterprise Risk Management (ERM) framework or other organizational standards, including preparing documents and related risk management activities.
- Coordinate and gather information from various departments to identify and assess risks according to the ERM framework.
- General and Internal Coordination.
- Maintain complete, accurate, and easily retrievable documents.
- Coordinate with internal company departments, external parties, and relevant government agencies.
- Help improve work processes to ensure efficiency, transparency, and auditability.
- Perform other duties as assigned.
- Bachelor's degree or higher.
- 5 - 7 years of work experience, with experience in Compliance, Risk, and Data Governance. Experience in relevant ISO Standards is a plus.
- English proficiency sufficient for work purposes.
- Ability to work effectively in a team.
- Understanding of or interest in data, technology, or digital systems.
- Proficiency in basic computer applications such as Microsoft Office, PowerPoint, and Excel.
- Analytical thinking, planning, problem-solving, coordination skills, and attention to detail.
- Eager to learn with a proactive, can-do attitude and willingness to take action.
- Logical thinking and business sense: able to see the organizational picture, connect requirements, regulations, and standards, and assess the business impact appropriately.
- Self-motivated, with a willingness to develop professionally and grow within the organization.
Skills:
Risk Management, Automation, ISO 27001, Assurance, Python
Job type:
Full-time
Salary:
negotiable
- การบริหารจัดการบัญชีผู้ใช้และสิทธิ์การเข้าถึง (Identity & Access Management Administration).
- จัดการ Account Lifecycle Management (Provisioning, Deprovisioning, Account Recertification) สำหรับพนักงาน ผู้ใช้งานภายนอก และบัญชี Service Accounts.
- บริหารจัดการ Role-Based Access Control (RBAC) และ Least Privilege Access.
- ตรวจสอบและบังคับใช้ Multi-Factor Authentication (MFA), Single Sign-On (SSO) และ Password Policy.
- การเฝ้าระวังและตรวจสอบกิจกรรมการเข้าถึง (Access Monitoring & Auditing).
- เฝ้าระวังและวิเคราะห์ Access Logs และ Authentication Events เพื่อระบุความผิดปกติหรือพฤติกรรมที่เสี่ยงต่อความปลอดภัย.
- จัดทำ Identity & Access Review (IAR) ตามข้อกำหนดด้าน Compliance เช่น ISO 27001.
- วิเคราะห์และจัดทำรายงาน Access Certification และ Privileged Access Management (PAM) Review.
- การรักษาความปลอดภัยของบัญชีผู้ใช้และการเข้าถึง (Identity Security & Risk Management).
- ป้องกันและตรวจจับ Identity Threats เช่น Account Takeover (ATO), Credential Stuffing, และ Insider Threats.
- บริหารจัดการ Privileged Access Management (PAM) เช่น CyberArk, BeyondTrust, Delinea, PAM360.
- บังคับใช้ Zero Trust Security และ Identity Threat Detection & Response (ITDR).
- การจัดการและบูรณาการระบบ IAM (IAM Systems & Integration).
- ดูแลและปรับแต่งระบบ IAM Solutions เช่น Microsoft Entra ID (Azure AD), Okta, Ping Identity, One Identity, ForgeRock.
- บูรณาการระบบ IAM กับ Cloud (Azure AD), On-Premise AD, HR Systems และ Business Applications.
- พัฒนา IAM Automation & Workflows ด้วย API และ Scripting เช่น PowerShell, Python.
- การวิเคราะห์ช่องโหว่และเสริมสร้างความมั่นคงปลอดภัย (IAM Security Assessment & Hardening).
- ตรวจสอบ IAM Misconfigurations และ Excessive Permissions เพื่อลดความเสี่ยง.
- ทำ Privilege Escalation Testing และ Identity Threat Hunting เพื่อตรวจจับบัญชีที่อาจถูกแทรกแซง.
- บังคับใช้แนวทาง Just-In-Time Access (JIT) และ Passwordless Authentication.
- การปฏิบัติตามข้อกำหนดและมาตรฐานด้านความปลอดภัย (IAM Compliance & Governance).
- ดูแลให้ IAM Policies & Procedures สอดคล้องกับมาตรฐาน เช่น ISO 27001, NIST 800-53, CIS Controls.
- จัดทำเอกสาร IAM Risk Assessment และ Audit Report สำหรับทีมบริหารและหน่วยงานกำกับดูแล.
- ประสานงานกับทีม Security Engineer, SOC และ Risk Management เพื่อปรับปรุงการจัดการสิทธิ์ให้ปลอดภัยยิ่งขึ้น.
- การพัฒนาและฝึกอบรมทีมงานเกี่ยวกับ IAM (IAM Awareness & Training).
- อบรมพนักงานเกี่ยวกับ Identity Hygiene และ Access Security Best Practices.
- พัฒนา IAM Playbook และ Incident Response Procedures สำหรับการบริหารจัดการบัญชีผู้ใช้ที่ถูกบุกรุก.
- สนับสนุนและให้คำแนะนำด้าน IAM แก่ทีม IT, HR, และผู้ใช้งานทั่วไป.
- อื่น ๆ.
- ดูแล ควบคุม และป้องกันภัยคุมคามต่าง ๆ ทางด้านเทคโนโลยีและไซเบอร์ ให้เป็นไปตามมาตรฐานสำหรับความมั่นคงปลอดภัยของระบบเทคโนโลยีสารสนเทศ.
- จัดทำเอกสารสำหรับบันทึกปัญหา วิธีการแก้ไข รวมทั้งสาเหตุที่เกิดขึ้น เพื่อเก็บเป็นประวัติและแนวปฏิบัติในอนาคต.
- จัดทำรายงานข้อมูลความมั่นคงสารสนเทศ นำเสนอต่อผู้บังคับบัญชา.
- ร่วมในการวางแผนศึกษา/ปรับปรุงระบบ ในการนำเสนอเทคโนโลยีใหม่ ๆ เพื่อให้ระบบของโรงพยาบาลมีความมั่นคง ปลอดภัยที่เหมาะสม.
- ปฏิบัติตามนโยบาย ระเบียบ ข้อกำหนดของหน่วยงานให้เป็นไปตามมาตรฐาน ISO27001 และ JCI.
- ปริญญาตรีหรือปริญญาโท สาขาวิทยาศาสตร์หรือวิศวกรรมศาสตร์คอมพิวเตอร์, Information Security, Cyber Security and Information Assurance.
Skills:
ISO 27001
Job type:
Full-time
Salary:
฿45,000 - ฿60,000, negotiable
- ศึกษา วิเคราะห์ และจัดทำ IT Policy และแนวปฏิบัติด้านความมั่นคงปลอดภัยสารสนเทศขององค์กร ให้ครอบคลุมการใช้งานระบบ IT อย่างปลอดภัย สอดคล้องกับมาตรฐานสากล และสนับสนุนนโยบายระดับองค์กร.
- ควบคุมและกำกับดูแลการปฏิบัติตามกฎหมายด้านข้อมูลส่วนบุคคล (PDPA, GDPR) โดยทำหน้าที่เป็นผู้นำในการประสานงานและให้คำปรึกษาแก่หน่วยงานต่าง ๆ ภายในองค์กร.
- เป็นผู้รับผิดชอบหลักในการดำเนินการระบบ ISO/IEC 27001 ตั้งแต่การวางแผน ประเมินช่องว่าง (Gap Analysis) จัดทำเอกสาร จัดเตรียมการตรวจประเมิน และติดตามการแก้ไขข้อเสนอแนะจากผ ...
- บริหารจัดการภัยคุกคามไซเบอร์อย่างรอบด้าน โดยวิเคราะห์ความเสี่ยง ตอบสนองต่อเหตุการณ์ และกำหนดแนวทางป้องกันเชิงรุกเพื่อปกป้องระบบและข้อมูลสำคัญขององค์กร.
- ควบคุมและวางแผนการประเมินช่องโหว่ (VA) และการทดสอบเจาะระบบ (Pen Test) โดยร่วมมือกับผู้เชี่ยวชาญภายนอก และวิเคราะห์ผลเพื่อนำไปสู่การปรับปรุงระบบ.
- บริหารการตรวจสอบและติดตามระบบและเครือข่ายด้านความปลอดภัย (Security Monitoring) โดยใช้เครื่องมือเช่น SIEM, IDS และระบบแจ้งเตือน เพื่อตรวจจับเหตุผิดปกติอย่างทันท่วงที.
- วางแผนและดำเนินการจัดทำแผนรับมือเหตุการณ์ (Cybersecurity Incident Response Plan) และกำกับการซ้อมแผนร่วมกับทีมที่เกี่ยวข้องอย่างเป็นระบบและต่อเนื่อง.
- ออกแบบและขับเคลื่อนโครงการสร้างความตระหนักรู้ด้าน Cybersecurity ให้ครอบคลุมทุกระดับพนักงาน พร้อมจัดกิจกรรม/อบรมที่เหมาะสมในแต่ละช่วงเวลา.
- ควบคุมและตรวจสอบการบริหารสิทธิ์การเข้าถึงข้อมูล (Access Control) ให้เป็นไปตามหลัก Least Privilege และ Zero Trust.
- ประสานงานกับหน่วยงานกำกับดูแลและภายนอก เช่น ThaiCERT, PDPC และ ETDA รวมถึงรายงานเหตุการณ์ที่เกี่ยวข้องให้ครบถ้วน ถูกต้อง และทันเวลา.
- จัดทำรายงานสรุปผลการดำเนินงานด้านความปลอดภัยสารสนเทศ เพื่อสนับสนุนการวางกลยุทธ์ของผู้บริหารและการตัดสินใจในระดับนโยบาย.
- ติดตามและประเมินเทคโนโลยี แนวโน้มภัยคุกคาม และเครื่องมือด้าน Cybersecurity ใหม่ ๆ เพื่อนำมาเสนอแนะและปรับใช้ในการพัฒนาระบบขององค์กรให้ทันสมัยและปลอดภัยยิ่งขึ้น.
- วุฒิการศึกษา ปริญญาตรีหรือสูงกว่า ในสาขาวิทยาการคอมพิวเตอร์, วิศวกรรมคอมพิวเตอร์, เทคโนโลยีสารสนเทศ หรือสาขาอื่นที่เกี่ยวข้องกับระบบสารสนเทศและความมั่นคงปลอดภัยไซเบอร์ มีประสบการณ์ทำงานในด้านที่เกี่ยวข้องกับความมั่นคงปลอดภัยสารสนเทศ (Cybersecurity), การกำกับดูแลข้อมูลส่วนบุคคล (PDPA), การตรวจสอบระบบสารสนเทศ (IT Security / IT Audit), หรือการบริหารจัดการข้อมูล (Data Governance) อย่างน้อย 3 - 5 ปี.
- ความรู้ ทักษะ และสมรรถนะที่จำเป็นในงานแบบบรรยายลักษณะงาน (Job Description).
- มีความรู้เชิงลึกด้านความมั่นคงปลอดภัยสารสนเทศ (Information Security) โดยเข้าใจหลักการพื้นฐาน เช่น ความลับ (Confidentiality), ความถูกต้องครบถ้วน (Integrity), และความพร้อมใช้งาน (Availability) รวมถึงหลักการของ Zero Trust และ Defense in Depth.
- มีความสามารถในการวิเคราะห์และประเมินความเสี่ยงด้านไซเบอร์ (Cyber Risk Assessment) โดยสามารถระบุช่องโหว่ ภัยคุกคาม และผลกระทบ พร้อมจัดทำแผนบริหารความเสี่ยง และข้อเสนอแนะแนวทางควบคุมที่เหมาะสม.
- มีความรู้และความเข้าใจในกฎหมาย ข้อบังคับ และมาตรฐานที่เกี่ยวข้อง เช่น พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล (PDPA), GDPR, พ.ร.บ.คอมพิวเตอร์, ISO/IEC 27001 และสามารถประยุกต์ใช้ในบริบทขององค์กรได้อย่างถูกต้อง.
- มีทักษะในการเขียนและพัฒนาเอกสารด้านความมั่นคงปลอดภัย เช่น นโยบาย (Policy), แนวปฏิบัติ (Standard), ขั้นตอนปฏิบัติงาน (Procedure) และคู่มือการใช้งาน (Guideline) ที่ชัดเจน และสามารถนำไปใช้งานจริงได้.
- มีประสบการณ์ในการติดตาม ตรวจสอบ และตอบสนองต่อเหตุการณ์ด้านความปลอดภัยไซเบอร์ (Security Incident Monitoring & Response) โดยใช้เครื่องมือ SIEM, IDS/IPS, Antivirus, Log Management และระบบแจ้งเตือนอัตโนมัติ.
- มีความสามารถในการดำเนินการหรือประสานการทดสอบความปลอดภัยระบบ (Security Testing) ทั้งด้าน Vulnerability Assessment (VA) และ Penetration Testing (PT) พร้อมวิเคราะห์ผลและวางแผนแก้ไขอย่างเป็นระบบ.
- มีทักษะในการจัดทำแผนฝึกอบรมและกิจกรรมส่งเสริมความตระหนักรู้ด้าน Cybersecurity สำหรับพนักงานทุกระดับ เพื่อสร้างวัฒนธรรมองค์กรที่ใส่ใจด้านความปลอดภัยสารสนเทศ.
- เชี่ยวชาญการใช้งานและบริหารจัดการเครื่องมือด้าน IT Security เช่น Firewall, Endpoint Detection & Response (EDR), Data Loss Prevention (DLP), Access Control System, SIEM และระบบจัดการบัญชีผู้ใช้ (IAM).
- มีความสามารถในการวิเคราะห์ข้อมูลทางเทคนิคเชิงลึก (Technical Analysis) และสามารถสื่อสารหรือถ่ายทอดข้อมูลเชิงเทคนิคให้แก่ผู้บริหารหรือผู้ไม่มีพื้นฐานด้าน IT เข้าใจได้อย่างมีประสิทธิภาพ.
- มีทัศนคติที่ดีในการทำงานเชิงรุก ร่วมมือกับทีมงานและหน่วยงานอื่นได้ดี มีความคล่องตัวในการเรียนรู้เทคโนโลยีใหม่ ๆ และสามารถปรับตัวเข้ากับความเปลี่ยนแปลงในโลกไซเบอร์ได้อย่างรวดเร็ว.
Skills:
Automation, ISO 27001
Job type:
Full-time
Salary:
negotiable
- You lead the day-to-day operations of the IT Service Desk, ensuring incidents and requests meet SLA targets.
- You manage a small but effective customer focused team, reporting to the IT Operations Manager.
- You act as the escalation point for complex or high-impact incidents.
- You monitor ticket queues, prioritisation, and workload distribution.
- You coach and develop your team, running performance reviews and 1-on-1s.
- You drive a customer-first mindset across all support activities.
- You track and improve key KPIs: FCR, MTTR, CSAT, backlog and SLA compliance.
- You identify recurring issues and contribute to problem management and process improvement.
- You introduce and stimulate the use of automation, self-service and AI tools.
- You maintain and improve the knowledge base and documentation quality.
- You collaborate with IT teams (security, applications, infrastructure) and manage stakeholder expectations.
- You ensure compliance with SHEQ standards, IT policies and security requirements (e.g. ISO 27001).
- You deliver clear reporting and insights on service performance.
- About You.
- You are a.
- hands-on leader who enjoys structure, service quality and continuous improvement. You step in where needed, but you also step back to develop your team. You make decisions based on data, and you bring clarity in fast-moving environments.
- You combine.
- technical understanding.
- people leadership., and a.
- drive to optimise processes., including the use of AI and automation.
- Experience leading or mentoring an IT Service Desk or support team.
- Strong understanding of incident management, SLA tracking and IT support processes.
- Experience with ticketing systems and service management tools.
- Ability to analyse KPIs (FCR, MTTR, CSAT) and drive improvements.
- Strong communication skills in an international environment.
- A structured, proactive and solution-oriented mindset.
- Commitment to safety, compliance and IT security standards.
- Knowledge of ITIL principles or service management frameworks.
- Experience with automation, self-service platforms or AI-driven support tools.
- Experience in a global or 24/5 support environment.
- Exposure to ISO standards or audit environments.
- You Give Some, You Get Some.
- We offer you a role where you truly own your scope and shape the future of IT support within a global organization.
- Market conform salary according to the seniority in the position.
- A leadership role with real impact in a global IT environment.
- Opportunities to introduce innovation (AI, automation, service optimization).
- A strong focus on development, ownership and autonomy.
- A team where safety, precision and collaboration come first.
- The chance to grow within a global, family-owned company active in over 65 countries.
- Ready to lead, improve and inspire?.
- Join Team Blue and Own Your Future.
Experience:
5 years required
Skills:
Project Management, Internal Audit, ISO 27001, English, Thai
Job type:
Full-time
Salary:
negotiable
- Manage the end-to-end evidence collection process for ISO 27001, PDPA, and PCI-DSS - define evidence requirements, assign collection tasks to control owners, validate completeness, and organise evidence repositories.
- Coordinate internal and external audit schedules - manage logistics, prepare control owners for audit interviews, ensure evidence packages are ready, and track audit finding responses.
- Track and drive remediation of audit findings and compliance gaps - maintain a remed ...
- Conduct control validation testing - verify that documented controls are operating effectively through sample testing, walkthroughs, and evidence review.
- Produce and maintain the compliance dashboard - real-time view of compliance status across frameworks, evidence collection progress, remediation pipeline, and upcoming audit milestones.
- Manage the security exception register - track approved exceptions, monitor expiration dates, ensure risk acceptance documentation is complete, and trigger renewal reviews.
- Support vendor compliance assessments - collect and review vendor security questionnaires, track vendor compliance gaps, and maintain the vendor risk register.
- Coordinate with IT and business teams on control implementation - translate compliance requirements into operational tasks and track implementation progress.
- Maintain compliance documentation - audit reports, finding responses, remediation evidence, exception approvals, and compliance correspondence with regulators and auditors.
- Manage the end-to-end evidence collection process for ISO 27001, PDPA, and PCI-DSS - define evidence requirements, assign collection tasks to control owners, validate completeness, and organise evidence repositories.
- Coordinate internal and external audit schedules - manage logistics, prepare control owners for audit interviews, ensure evidence packages are ready, and track audit finding responses.
- Track and drive remediation of audit findings and compliance gaps - maintain a remediation tracker with owners, deadlines, and status; escalate overdue items; validate closure evidence.
- Conduct control validation testing - verify that documented controls are operating effectively through sample testing, walkthroughs, and evidence review.
- Produce and maintain the compliance dashboard - real-time view of compliance status across frameworks, evidence collection progress, remediation pipeline, and upcoming audit milestones.
- Manage the security exception register - track approved exceptions, monitor expiration dates, ensure risk acceptance documentation is complete, and trigger renewal reviews.
- Support vendor compliance assessments - collect and review vendor security questionnaires, track vendor compliance gaps, and maintain the vendor risk register.
- Coordinate with IT and business teams on control implementation - translate compliance requirements into operational tasks and track implementation progress.
- Maintain compliance documentation - audit reports, finding responses, remediation evidence, exception approvals, and compliance correspondence with regulators and auditors.
- Technical Requirements.
- Compliance frameworks: ISO 27001 (control mapping), PDPA requirements, PCI-DSS basics.
- Evidence management: Document management systems, evidence repositories, audit trail maintenance.
- Tracking and reporting: Project management tools, compliance dashboards, Excel/Google Sheets for tracker management.
- Control testing: Basic understanding of IT controls - access management, change management, logging, backup - to validate evidence.
- Must-have Requirements.
- These are non-negotiable. If you do not meet all of these, this role is not the right fit.
- 4+ years in information security, IT audit, or compliance operations.
- Hands-on experience with audit evidence management - you've collected, organised, and presented evidence to external auditors.
- Working knowledge of ISO 27001 controls and audit processes - you understand what auditors look for and how to prepare for assessments.
- Strong project management and tracking skills - ability to manage multiple concurrent compliance workstreams with different deadlines.
- Excellent attention to detail and organisational skills - you can manage hundreds of evidence items across multiple frameworks without dropping anything.
- Fluent in Thai; reading English proficiency for compliance frameworks and documentation.
- Nice-to-have.
- ISO 27001 Internal Auditor certification or equivalent.
- Experience with PDPA compliance operations or PCI-DSS evidence management.
- Familiarity with GRC tools (ServiceNow GRC, OneTrust, or similar) for automating evidence collection and tracking.
- Background in IT audit (Big Four or internal audit function) - understanding audit methodology and expectations.
- Experience building compliance dashboards or automated reporting.
Skills:
ISO 27001
Job type:
Full-time
Salary:
negotiable
- Establish and maintain IT Security Policy and IT Procedure in comply with the regulations requirements from regulators such as SEC, BOT, PDPA.
- Coordinate with IT Process Control to prepare Paper for Supporting External or Internal IT Audit include Tracking and Follow up Issue.
- Coordinate with IT Security Team for Tracking and Follow up Issue from Source Code Scan, Security Patch Update, Pentest and VA (vulnerability assessment) and Cyber Attack.
- Provide IT Security Awareness Program to the employee include Cyber-Drill Program.
- Prepare Management Monthly Report such as IT Loss, IT Risk Appetite, IT Incident and Summary IT Audit Issue.
- Male/Female, Bachelor or higher degree in Information Technology, Computer Science or related field, Ages not over 35 years.
- Good Knowledge of Software/System Development Life Cycle (SDLC), User Access Management, Incident Management, Change Management, IT Asset Management, IT Operation Control management, Business Continuity.
- Management and IT Service Management.
- 5 years' Experience in field relate IT Audit, IT Risk, IT Compliance, or IT Process Control.
- Self-motivated, ambitious and quickly absorb.
- Problem solver, Strong analytical and organizational skills.
- Work independently and effectively as part of a team.
- Handling multiple tasks and responsibilities in a dynamic environment.
- Excellent verbal and written communication skills.
- Specific knowledge and skill / ความรู้เฉพาะตำแหน่ง.
- IT quality standards such as Capability Maturity Model (CMM/CMMI), ISO27001, COBIT, ITIL, ISO22301.
- Good Knowledge of the IT regulations requirements from SEC (nor por.3).
Experience:
3 years required
Skills:
Analytical Thinking, Risk Management, Accounting, ISO 27001, Assurance
Job type:
Full-time
Salary:
negotiable
- Conduct digital audits and assess effectiveness of controls to support business processes in fast growing digital financial services.
- Prepare findings and recommendation reports to management and concerned parties for improving both financial and operational controls.
- Stay up to date with related regulatory requirements, guidelines, and best practices, and apply data analytics and other audit techniques to move toward real time assurance.
- Bachelor's degree or higher in IT, Computer Science, Engineering, Data Science, Statistics, Auditing, Accounting, Finance, Economics, or a related field.
- At least three years of relevant experience in Digital/IT Audit, Internal or External Audit, Technology Risk, Cybersecurity, Data Analytics, or Consulting, preferably in financial services or a regulated industry.
- Good understanding of digital financial services, technology-enabled processes, and related risks and controls.
- Strong digital and data literacy, analytical thinking, problem-solving, communication, and report-writing skills, with the ability to translate technical issues into business and risk implications.
- Ability to work independently and across multidisciplinary teams, adapt to emerging technologies and regulatory changes, and demonstrate professional curiosity, sound judgment, and a growth mindset.
- Specific knowledge and skill / ความรู้เฉพาะตำแหน่ง.
- Knowledge of IT governance, technology risk, cybersecurity, data privacy, operational resilience, relevant regulations, and frameworks such as COBIT, ITIL, NIST, and ISO 27001.
- Understanding digital financial services and emerging technologies, including mobile banking, digital platforms, APIs, cloud, digital identity/biometrics, blockchain/digital assets, and AI/GenAI.
- Knowledge of cloud and third-party risk management, including shared responsibility models, data and access security, service resilience, SLA monitoring, concentration risk, and exit strategies.
- Understanding of digital fraud and regulatory Shared Responsibility requirements, including account takeover, mule accounts, transaction monitoring, customer notification, and incident response.
- Apply now ".
Experience:
5 years required
Skills:
Risk Management, ISO 27001
Job type:
Full-time
Salary:
negotiable
- การวางแผนกลยุทธ์ด้านความปลอดภัยทางไซเบอร์.
- พัฒนา นโยบาย, มาตรฐาน, และแนวทางปฏิบัติ ด้านความปลอดภัยสารสนเทศ.
- กำหนดแนวทางปฏิบัติให้สอดคล้องกับกฎหมายและมาตรฐานสากล.
- จัดทำโปรแกรมฝึกอบรมความปลอดภัยทางไซเบอร์ ให้พนักงาน.
- การบริหารความเสี่ยงด้านความปลอดภัยทางไซเบอร์.
- วิเคราะห์ ความเสี่ยงทางไซเบอร์ (Cyber Risk Assessment).
- กำกับดูแลแนว นโยบาย, มาตรฐาน, และแนวทางปฏิบัติทางปฏิบัติให้สอดคล้องกับกฎหมายและมาตรฐานสากลและเป็นตามกฎระเบียบของบริษัท อาทิเช่น นโยบายสารสนเทศ, ISO 27001, PDPA, NIST และนโยบายด้านความปลอดภัยทางไซเบอร์อื่น ๆ ที่บริษัทได้นำมาใช้ภายในบริษัท.
- การปฏิบัติการด้านความปลอดภัยและการตอบสนองต่อเหตุการณ์.
- วิเคราะห์ ความเสี่ยงทางไซเบอร์ (Cyber Risk Assessment).
- บริหารจัดการ เหตุการณ์ด้านความปลอดภัยทางไซเบอร์ (Incident Response) อาทิเช่น การโจมตีจากแฮกเกอร์, Ransomware, Data Breach,etc.
- การตรวจจับและป้องกันภัยคุกคามทางไซเบอร์.
- บริหารจัดการกำกับดูแลและควบคุม Firewall, IDS/IPS, SIEM, Endpoint Security เพื่อตรวจสอบภัยคุกคาม.
- วิเคราะห์และบริหารจัดการ ภัยคุกคามทางไซเบอร์แบบเชิงรุก.
- ตรวจสอบและนำเทคโนโลยีใหม่ ๆ มาใช้เพื่อเพิ่มความปลอดภัย.
- ตรวจสอบและประเมินความเสี่ยงของ Third-Party Vendors ที่เกี่ยวข้องกับข้อมูลบริษัท.
- การสนับสนุนกิจกรรมด้านความปลอดภัยทางไซเบอร์.
- รับผิดชอบ, ติดตาม และแก้ไขปัญหาที่เกี่ยวข้องกับระบบ Cyber Security.
- กำกับดูแลการป้องกันต่างๆ ตามที่ได้รับมอบหมาย เช่น update Cyber Security.
- สนับสนุน, จัดทำเอกสารประกอบ และดูแลรักษาระบบ Cyber Security.
- กำกับดูแลการจัดทำข้อมูล Cyber Security ที่ได้รับมอบหมาย.
- กำกับดูแลดำเนินการบริหารจัดการทะเบียนความเสี่ยงต่าง ๆามที่ได้รับการอนุมัติ.
- กำกับดูแลการรวบรวมและจัดทำข้อมูลรายงาน Risk Management.
- กำหนดแนวทางพัฒนาทักษะของทีมงานด้าน Cyber Security.
- วางแผนการลงทุนในระบบฐานข้อมูลให้รองรับต่อเหตุการการโจมตีทาง Cyber Security โดยตัดสินใจจากข้อมูลเกี่ยวกับข้อมูล และผลวิเคราะห์แนวโน้มของข้อมูล.
- บริหารโครงการติดตั้งระบบด้าน Cyber Security.
- มอบหมายงาน ติดตามงาน ทบทวน และประเมินผลงานของทีมงาน.
- จัดทำรายงานกิจกรรม และความคืบหน้าของโครงการต่างๆ ที่ทีมงาน.
- Educations Background(การศึกษา).
- ปริญญาตรีทางวิศวกรรม หรือ วิทยาศาสตร์ สาขาคอมพิวเตอร์ หรือเทียบเท่า.
- Professional Experiences(ประสบการณ์การทำงาน).
- มีประสบการณ์ทำงานอย่างน้อย 10 ปี.
- มีประสบการณ์มากกว่า 6 ปีในงานดูแล Cyber Security.
- มีประสบการณ์ในการบริหาร / บังคับบัญชาทีมงาน.
- มีความรู้ด้านระบบ Cyber Security ดังต่อไปนี้.
- o ความรู้ทางเทคนิค (Technical Knowledge) Network Security, Endpoint Security & Malware Protection, Cloud Security, Application Security และ Incident Response เป็นต้น.
- o ความรู้ด้านกฎหมายและมาตรฐานความปลอดภัย GDPR, PDPA, ISO/IEC 27001 หรือ NIST.
- o ทักษะการบริหารจัดการ (Management Skills) Risk Management, Communication & Training หรือ Policy Development.
- o ความรู้เกี่ยวกับแนวโน้มภัยคุกคามและเทคโนโลยีใหม่ Cyber Threats และ Zero-Day Attacks ความเข้าใจ AI และ Machine Learning ใน Cyber Security, Threat Intelligence Tools เช่น MITRE ATT&CK, Cyber Threat Feeds.
- Human Relations Skills (คุณลักษณะที่จำเป็น).
- ทักษะด้านมนุษยสัมพันธ์ที่จำเป็นต่อการปฏิบัติงาน.
- ทักษะในการทำงานเป็นทีม.
- ทำงานร่วมกับผู้อื่นได้อย่างมีประสิทธิภาพ และ ให้ความร่วมมือกับทีมงานทุกฝ่าย.
- มีมนุษยสัมพันธ์ที่ดี และ มุ่งเน้นการให้บริการที่เป็นมิตรและสร้างสรรค์.
- ทักษะการสื่อสารและการประสานงาน.
- สามารถ อธิบายเรื่องเทคนิคที่ซับซ้อนให้เข้าใจง่าย สำหรับผู้ใช้ที่ไม่มีพื้นฐานด้าน IT.
- มีความสามารถในการ ประสานงานทั้งภายในและภายนอกองค์กร อย่างมีประสิทธิภาพ.
- แจ้งข้อมูลเกี่ยวกับ ปัญหาของระบบกลางหรือปัญหาทางเทคนิค ที่อาจส่งผลกระทบต่อผู้ใช้.
- ให้ข้อมูลอัปเดตเกี่ยวกับ สถานะของปัญหาที่กำลังดำเนินการแก้ไข.
- การจัดการข้อร้องเรียนและการควบคุมอารมณ์.
- สามารถ รับมือกับข้อร้องเรียนของผู้ใช้ ได้อย่างเป็นมืออาชีพ.
- มีความสามารถในการจัดการกับ พฤติกรรมเชิงลบหรือพฤติกรรมก้าวร้าวของผู้ใช้บริการ.
- Descision Making Responsibility (ความรับผิดชอบในการตัดสินใจ).
- การวิเคราะห์และการตัดสินใจในการแก้ไขปัญหา.
- ศึกษา, วิเคราะห์, และตรวจสอบปัญหาด้าน Cyber Security ในระบบที่รับผิดชอบ.
- ตัดสินใจเกี่ยวกับการ แก้ไขปัญหาด้านเทคนิค อย่างรวดเร็วและมีประสิทธิภาพ.
- สามารถตัดสินใจ แก้ไขปัญหาพื้นฐานในระบบที่รับผิดชอบได้ด้วยตนเอง.
- การออกแบบระบบและแนวทางการรักษาความปลอดภัย.
- มีความสามารถในการ ออกแบบระบบ Cyber Security เพื่อป้องกันภัยคุกคามทางไซเบอร์.
- ตัดสินใจเกี่ยวกับการเลือก เครื่องมือและเทคโนโลยี ที่เหมาะสมเพื่อเสริมสร้างความปลอดภัยในองค์กร.
- การให้คำแนะนำและการประเมินผลกระทบ.
- ให้คำแนะนำเกี่ยวกับ ผลกระทบด้านความปลอดภัยทางไซเบอร์ ต่อระบบและการดำเนินธุรกิจ.
- ตัดสินใจในเรื่อง การจัดการความเสี่ยงทางไซเบอร์ และการลงทุนในเทคโนโลยีความปลอดภัย.
Experience:
3 years required
Skills:
Risk Management, Procurement, Recruitment, ISO 27001, English, Thai
Job type:
Full-time
Salary:
negotiable
- Drive end-to-end sales cycle for cybersecurity solutions (SIEM, incident response, threat intelligence, governance & compliance, cloud security) to banking clients.
- Develop and execute account plans targeting C-level stakeholders (CISO, CRO, CFO) and key decision makers in banking institutions.
- Conduct discovery workshops and assessments to understand security posture, regulatory requirements (Basel III, PCI-DSS, GDPR, STR), and organizational risk profile.
- Collaborate with presales architects and solution consultants to design tailored cybersecurity roadmaps addressing compliance, operational risk, and cyber resilience.
- Build and present business cases, ROI models, and executive briefings articulating security maturity improvements and risk mitigation value.
- Lead RFP/RFI responses and competitive evaluations against solutions from Accenture, DXC, Infosys, TCS, and Deloitte.
- Establish and nurture relationships with bank security teams, procurement, and governance bodies to expand share of wallet.
- Achieve and exceed sales targets, quota, and pipeline coverage metrics; forecast accurately and report on pipeline health.
- Serve as product evangelist and thought leader, attending banking industry events and building brand presence in the APAC financial services market.
- 7+ years of direct sales experience selling cybersecurity, security services, or risk management solutions.
- 3+ years of proven success in Banking, Financial Services, or highly regulated industry verticals (insurance, healthcare, government).
- Demonstrated ability to close enterprise deals ($500K - $5M+ ACV) with complex stakeholder environments and long sales cycles.
- Deep working knowledge of cybersecurity frameworks, risk management, and threat landscape (NIST, ISO 27001, COBIT, threat intelligence, incident response).
- Understanding of banking regulatory requirements: Basel III, PCI-DSS, GDPR, STR, AML, and audit/compliance frameworks.
- Strong knowledge of core cybersecurity solution categories: SIEM, firewalls, endpoint detection & response (EDR), identity & access management (IAM), data loss prevention (DLP), and cloud security.
- Excellent consultative selling skills; ability to translate security challenges into business outcomes and quantifiable ROI.
- Proven track record of pipeline generation, forecasting accuracy, and consistent quota attainment.
- Ability to influence and build consensus across technical and business stakeholders at all levels.
- Strong communication skills (presentation, written, and interpersonal) in English; Thai language is a plus.
- On-site Working.
- About NTT DATA.
- NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.
- Equal Opportunity Employer.
- NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
- Third parties fraudulently posing as NTT DATA recruiters.
- NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters - whether in writing or by phone - in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @ nttdata.com email address. If you suspect any fraudulent activity, please _contact us_.
Experience:
1 year required
Skills:
Software Development, Project Management, Risk Management, ISO 27001, English
Job type:
Full-time
Salary:
negotiable
- Responsible for supporting the development, implementation, and continuous improvement of IT governance frameworks to ensure alignment with business strategy, risk management, and regulatory compliance. The position works closely with cross-functional teams and senior stakeholders to strengthen IT controls, compliance, performance monitoring, and governance best practices across the organization.
- IT Governance Framework Development.
- Provide advisory support for the development, implementation, and continuous improve ...
- Collaborate with senior executives to define IT policies, standards, and governance guidelines covering IT project management, resource allocation, and performance monitoring.
- Ensure the IT Governance Framework addresses critical IT operational areas, including information security, risk management, regulatory compliance, and audit processes.
- IT Risk Management and Compliance.
- Advise on regulatory and compliance requirements (e.g., GDPR, ISO 27001, SOX, HIPAA) and support the development of global compliance strategies.
- Design and enforce data protection and privacy policies to ensure compliance with international laws and industry standards.
- Provide strategic guidance on IT risk management, including identification of risks arising from IT systems, data management, and operations, and develop mitigation plans aligned with the enterprise risk management framework.
- IT Policies and Standards Implementation.
- Provide guidance on the development and implementation of IT operational policies and standards, such as information security policies, software development standards, and change management processes.
- Support the establishment of standardized IT project management practices to ensure consistent delivery, effective resource management, and accountability across all operating countries.
- Ensure the adoption of best practices for IT asset management, system maintenance, and vendor/service provider management.
- IT Audit and Control.
- Collaborate with internal and external auditors to prepare for IT audits and support the development of audit plans.
- Advise on the design and implementation of IT control systems to govern IT policies and standards, ensuring systems operate effectively and comply with regulatory requirements.
- Support the establishment of monitoring mechanisms for critical IT systems to ensure transparent tracking of data and system activities.
- IT Performance Monitoring and Accountability.
- Provide guidance on developing evaluation criteria and key performance indicators (KPIs) to assess the effectiveness of IT operations, systems, and projects across the organization.
- Support the implementation of accountability mechanisms for IT performance, such as project evaluations, lessons learned reviews, and system audits.
- Work with senior management to establish IT performance reporting that highlights achievements, issues, and improvement opportunities.
- Continuous Improvement of IT Governance.
- Advise on the continuous enhancement of the IT Governance Framework to respond to changes in business strategy, technology, and regulatory requirements.
- Conduct periodic assessments of governance practices, IT risk management strategies, and compliance efforts to identify gaps and improvement opportunities.
- Promote a culture of continuous learning and improvement within IT teams through training programs and governance awareness initiatives.
- Cross-Functional Collaboration.
- Work closely with IT teams, key stakeholders, and senior management to ensure IT governance aligns with organizational business goals and strategies.
- Collaborate with Information Security, Legal, and Audit teams to ensure IT governance is fully integrated with enterprise-level policies and compliance frameworks.
- Provide advisory support to project managers and business leaders on applying IT governance principles and compliance requirements in IT project planning and execution.
- Bachelor's or Master's degree in.
- Information Technology, Computer Science, Information Systems,.
- or a related field. (GPA: over 2.70 for Bachelor's degree and over 3.30 for Master's degree.).
- 1 - 5 years of experience in IT governance, IT Risk, Compliance, Audit, Cyber Security, or related areas.
- Knowledge of IT governance, risk, and compliance frameworks and standards, such as ISO/IEC 27001, ISO/IEC 20000, and related regulatory or industry compliance requirements.
- Knowledge in SDLC; IT processes and service management; network and infrastructure; cybersecurity; and cloud technologies.
- Good command of English in written and verbal (TOEIC Score > 550).
- Willing to work onsite at SCG Packaging PCL. (Bangsue, Bangkok).
Experience:
5 years required
Skills:
Network Infrastructure, Software Development, Architecture, Automation, Kubernetes, ISO 27001, English
Job type:
Full-time
Salary:
negotiable
- opportunities with innovative digital services.
- We are blessed to be operating in ASEAN, where we.
- are able to help one of the world.
- s.
- largest populations of underbanked, the people from some of the poorest.
- provinces who are disregarded by traditional banks.
- So many.
- lives are waiting for our help.
- In 2017, we served over 30 million customers.
- in 6 countries.
- Thailand,.
- Cambodia, Myanmar, Vietnam, Indonesia, Philippines., and processed over 4.
- 5 billion USD.
- This makes us by far the largest fintech company.
- in SE Asia, and growing quickly.
- As a member of our esteemed Engineering team,.
- you will be helping to bring this vision to reality by leveraging the most.
- modern cloud.
- native.
- technologies.
- At Ascend, you will be.
- part of a team who are directly responsible for improving the lives of millions.
- Provide security consultation in a.
- project.
- based environment as.
- well as assisting operational of IT Security components with functional.
- security requirements.
- Track and manage to resolution the.
- closure of security risks including review plans and monitor progress or.
- remedial actions.
- Conduct and perform advanced vulnerability and.
- penetration testing.
- assessments.
- that also require in.
- depth.
- analysis of IT controls applied to network infrastructure, visualized servers,.
- databases, web applications and interfaces and supporting software.
- infrastructure.
- document.
- management, reporting.
- Analysis of technical requirements.
- to design and deliver both Infrastructure and IT Security solutions and.
- Assessment.
- Consults with IT and business.
- leaders to analyses IT security service needs to determine scope and priorities.
- of projects, and to discuss system requirements.
- Provides technical guidance on all.
- systems in place to all levels of Information Technology staff.
- Maintain infrastructure,.
- Application and security architecture documentation and provide support to.
- projects involving enterprise wide applications and supporting hardware.
- Develop security automation.
- test.
- in CI.
- CD pipeline on a Kubernetes based platform, both.
- on premises and on a multi.
- cloud.
- infrastructure.
- AWS and GCP.
- Essential Skills & Prerequisites.
- A positive, can.
- do attitude, who naturally.
- expresses a high degree of empathy to others.
- Bachelor or Master.
- s degree in Computer.
- Engineering, MIS, IT or related field.
- At least 4.
- 5 year experiences in computer security area.
- Have a foundation in good information.
- security practices.
- Functional knowledge of networks,.
- products, Or Software Development Life Cycle.
- Knowledge of E2E security design.
- including network, platform and application.
- Experience in system and.
- applications security management and control.
- Experience in facilitating.
- information security risk assessments.
- Technical writing, documentation.
- development, process mapping, and visual communication skills.
- Professional certificates related.
- to work.
- e.
- g.
- CISSP, CISM, CEH, Sec.
- ISO 27001, PCI DSS or similar general security certification.
- is desirable.
- Good command of English.
Experience:
5 years required
Skills:
Business Development, Customer Relationship Management (CRM), Negotiation, English, Thai
Job type:
Full-time
Salary:
฿50,000 - ฿80,000, negotiable
- Serve as a consultative business partner, translating complex technology solutions into high-value business opportunities forB2B and B2Gsectors.
- Build, manage, and maintain strong long-term relationships with clients, partners, and key government stakeholders.
- Lead customer engagement activities to identify business needs, address pain points, and strengthen the opportunity pipeline.
- Analyze GovernmentTerms of Reference (TOR)and lead end-to-end proposal development to support competitive bidding and project success.
- Identify and develop strategic partnerships and collaboration opportunities, both locally and internationally.
- Drive the full business development cycle from opportunity identification and negotiation to successful project acquisition.
- Work closely with technical teams and external stakeholders to support the successful delivery of complex IT projects.
- Bachelor's degree or above in Engineering, Computer Science, Software, IT, or related technical disciplines.
- Minimum 5 yearsof proven experience inGovernment / Public Sectorbusiness development or ICT solution sales.
- Overseas experience or proven ability to work in international business environments and cross-border public sector projects is a strong advantage.
- Demonstrated success in partner development, stakeholder management, and winning large-scale projects.
- Excellent command of English, both spoken and written, for international coordination and executive-level presentations.
- Strong negotiation, communication, and stakeholder management skills.
- Strong analytical thinking, especially in interpreting complex technical requirements and Government TOR documents.
- Results-driven, resilient, and able to work effectively in a dynamic business environment.
- Preferred Qualifications.
- Strong understanding of B2G sales cycles, government bidding, and public procurement processes.
- Familiarity with Blockchain, Digital Identity (DID), Cybersecurity, or advanced software technology solutions.
- Ability to work effectively with cross-functional technical teams and senior-level stakeholders.
Experience:
2 years required
Skills:
Leadership Skill
Job type:
Full-time
Salary:
฿20,000+ , negotiable
- มีประสบการณ์ 2 - 5 ปี ด้าน Information Security, Compliance หรือ Cybersecurity.
- เข้าใจมาตรฐาน เช่น ISO 27001/27701/22301, NIST, PCI DSS หรือที่เกี่ยวข้อง.
- มีทักษะการสื่อสารดี (ไทย - อังกฤษ) สามารถนำประชุมและนำเสนอได้.
- มีความเป็นผู้นำ กล้าตัดสินใจ และสามารถดูแลโครงการได้.
- คิดเป็นระบบ วิเคราะห์ปัญหา และบริหารความเสี่ยงได้.
- บุคลิกดี มีความรับผิดชอบ อดทน เรียนรู้ไว และใส่ใจรายละเอียด (Double-check งาน).
- จบสาขา IT / Computer Science หรือที่เกี่ยวข้อง.
- พิจารณาเป็นพิเศษ:มี Certification เช่น ISO Lead Auditor, CISA, CISSP, CEH.
- Lead และบริหารโครงการตั้งแต่ต้นจนส่งมอบ (วางแผน Timeline, Scope, Resource).
- ให้คำปรึกษาลูกค้าด้าน GRC / IT Security / Compliance ตามมาตรฐานที่เกี่ยวข้อง.
- นำเสนอและดำเนินการประชุม พร้อมติดตาม Action และสรุปประเด็นสำคัญ.
- วิเคราะห์ปัญหา บริหารความเสี่ยง และปรับแผนงานให้เหมาะสม.
- ควบคุมคุณภาพงานและตรวจสอบ Deliverables ให้ตรงตามมาตรฐาน.
- ติดตามความคืบหน้าและรายงานสถานะโครงการต่อผู้เกี่ยวข้อง.
- ประสานงานทีม ลูกค้า และหน่วยงานต่าง ๆ ให้ทำงานได้อย่างราบรื่น.
- ส่งมอบโครงการให้ตรงเวลาและบรรลุเป้าหมายที่กำหนด.
- ประกันสังคม / ประกันสุขภาพ / ประกันอุบัติเหตุ / ตรวจสุขภาพประจำปี.
- วันหยุดตามประเพณี 16 - 18 วัน/ปี และสวัสดิการตามกฎหมาย.
- โบนัสและปรับเงินเดือนประจำปี.
- ค่าเดินทางเข้าพบลูกค้า.
- การอบรมและพัฒนาทักษะความรู้.
- อาหาร ขนม เครื่องดื่มสำหรับพนักงาน.
- สวัสดิการวันเกิด / งานเลี้ยงปีใหม่ / ชุดยูนิฟอร์ม.
- สถานที่ทำงาน: อาคารสินสาธรทาวเวอร์ ชั้น 2 และ 39 ถนนกรุงธนบุรี แขวงคลองต้นไทร เขตคลองสาน กรุงเทพฯ (ใกล้ BTS กรุงธนบุรี และ BTS วงเวียนใหญ่).
- รูปแบบการทำงาน: Onsite.
- เวลาทำงาน: วันจันทร์ - วันศุกร์ เวลา 09.00 - 18.00 น.
- วันหยุด: วันเสาร์ - วันอาทิตย์.
Skills:
Legal, Procurement
Job type:
Full-time
Salary:
negotiable
- กำหนดและกำกับดูแลนโยบายด้าน IT Governance, Cybersecurity, AI Governance.
- Ensure การปฏิบัติงานสอดคล้องกับมาตรฐาน เช่น ISO 27001, NIST, DJSI.
- ทำงานร่วมกับ Legal, HR และ Procurement เพื่อให้สอดคล้องกับข้อกำหนดกฎหมายและนโยบายองค์กร.
- Information Security & Quality System.
- บริหารจัดการ Information Security Management System (ISMS).
- กำหนด Framework ด้าน People, Process และ Technology.
- ติดตาม Performance, Compliance และ Continuous Improvement.
- วางแผน Quality System ระยะ 3 ปี (Surveillance & Recertification Audit).
- Policy & Risk Management.
- Review / Revamp Policy ให้สอดคล้องกับกฎหมาย (เช่น PDPA).
- ทำ Risk & Operational Review ครอบคลุมทุกหน่วยงาน.
- ดูแล Contract และ Internal Policies ให้ทันต่อ Regulatory Changes.
- Audit & Certification Management.
- บริหารจัดการ Internal & External Audit (เช่น BSI).
- เตรียมองค์กรสำหรับ ISO Certification และ Surveillance Audit.
- ทำงานร่วมกับ Committee และ Stakeholders ทุกฝ่าย.
- Strategic Planning & Execution.
- จัดทำแผนประจำปีเพื่อรองรับมาตรฐาน (ISO, NIST, DJSI).
- Ensure การดำเนินงานเป็นไปตาม Timeline (เช่น ต้องเสร็จภายในเดือนกรกฎาคมของทุกปี).
- เชื่อมโยงแผนงานกับ Business Impact และ Digital Strategy.
- Stakeholder & Committee Management.
- ทำงานร่วมกับผู้บริหารระดับสูงและคณะกรรมการบริษัท.
- เป็นตัวกลางระหว่าง D&T, Techno และหน่วยงานต่าง ๆ.
- สร้าง Alignment ทั่วทั้งองค์กรด้าน Security & Compliance.
- Required.
- ประสบการณ์ระดับ Senior / Executive ด้าน IT Governance / Cybersecurity / Risk / Compliance.
- มีประสบการณ์ตรงด้าน ISO 27001 / NIST / IT Governance Framework.
- มีความเข้าใจด้าน PDPA / Regulatory / Legal Compliance.
- มีประสบการณ์บริหารทีม และขับเคลื่อนองค์กรขนาดใหญ่.
- Preferred.
- มีประสบการณ์ดูแล Audit (Internal / External / Certification).
- เคยทำงานร่วมกับ Committee หรือ Board Level.
- เข้าใจด้าน Digital Transformation และ Enterprise IT.
- Contact Information:-.
- K. Nanchanok (Recruiter) Email: nanchanok.r@ thaibev.com.
- Company name: DIGITAL AND TECHNOLOGY SERVICES CO., LTD.
- Office Locattion: F.Y.I Center 2525 Rama IV Rd, Khlong Tan, Khlong Toei, Bangkok 10110.
- MRT QSNCC Station Exit 1.
Skills:
System Testing, DevOps, Software Development, English
Job type:
Full-time
Salary:
negotiable
- Ensure system reliability, scalability, and performance across development, testing, and production environments..
- Automate deployment, monitoring, and incident response to enhance operational efficiency..
- Support and optimize CI/CD pipelines to enable smooth and reliable application releases..
- Manage and maintain Dev, SIT, and UAT environments to ensure stability for development and QA activities..
- Assist with test data preparation and data provisioning to support QA and system testing..
- Implement monitoring, alerting, and observability tools for proactive issue detection and resolution..
- Collaborate with Development, Infrastructure, and QA teams to ensure systems meet Non-Functional Requirements (NFRs) such as performance, reliability, and availability..
- Support environment readiness and test data provisioning throughout testing cycles..
- Bachelor's degree or higher in Computer Science or related fields.
- 7 - 10+ years of experience in Site Reliability Engineering, DevOps, or Environment Management..
- Experience with CI/CD, DevSecOps, data provisioning..
- Familiar with DevOps / Software Development tools (Dynatrace, GitLab, Jenkins, SonarQube, Nexus).
- Strong expertise in system reliability, performance, and multi environment management (Dev/SIT/UAT)..
- Hands on experience with CI/CD pipelines and deployment automation..
- Knowledge of cybersecurity fundamentals and compliance frameworks (ISO 27001, ITIL, SOC, GDPR/PDPA)..
- Ability to support test data preparation and environment readiness..
- Strong problem solving and cross team collaboration skills..
- Good English Communication.
- Talent Acquisition Department.
- Bank of Ayudhya Public Company Limited.
- 1222 Rama III Rd., Bangpongpang, Yannawa, Bangkok 10120.
- Contact: Talent Acquisition Center: 0 2--- ---- #--183.
- FB: Krungsri Career.
- LINE: Krungsri Career.
- LINKEDIN: Krungsri.
- Applicants can read the Personal Data Protection Announcement of the Bank's Human Resources Function by typing the link from the image that stated below.
- EN (https://krungsri.com/b/privacynoticeen).
- ผู้สมัครสามารถอ่านประกาศการคุ้มครองข้อมูลส่วนบุคคลส่วนงานทรัพยากรบุคคลของธนาคารได้โดยการพิมพ์ลิงค์จากรูปภาพที่ปรากฎด้านล่าง.
- ภาษาไทย (https://krungsri.com/b/privacynoticeth).
- หมายเหตุ ธนาคารมีความจำเป็นและจะมีขั้นตอนการตรวจสอบข้อมูลส่วนบุคคลเกี่ยวกับประวัติอาชญากรรมของผู้สมัคร ก่อนที่ผู้สมัครจะได้รับการพิจารณาเข้าร่วมงานกับธนาคารกรุงศรีฯ.
- Remark: The bank needs to and will have a process for verifying personal information related to the criminal history of applicants before they are considered for employment with the bank.
- 1
- 2
