- No elements found. Consider changing the search query.
Experience:
5 years required
Skills:
Network Infrastructure, Software Development, Architecture, Automation, Kubernetes, ISO 27001, English
Job type:
Full-time
Salary:
negotiable
- opportunities with innovative digital services.
- We are blessed to be operating in ASEAN, where we.
- are able to help one of the world.
- s.
- largest populations of underbanked, the people from some of the poorest.
- provinces who are disregarded by traditional banks.
- So many.
- lives are waiting for our help.
- In 2017, we served over 30 million customers.
- in 6 countries.
- Thailand,.
- Cambodia, Myanmar, Vietnam, Indonesia, Philippines., and processed over 4.
- 5 billion USD.
- This makes us by far the largest fintech company.
- in SE Asia, and growing quickly.
- As a member of our esteemed Engineering team,.
- you will be helping to bring this vision to reality by leveraging the most.
- modern cloud.
- native.
- technologies.
- At Ascend, you will be.
- part of a team who are directly responsible for improving the lives of millions.
- Provide security consultation in a.
- project.
- based environment as.
- well as assisting operational of IT Security components with functional.
- security requirements.
- Track and manage to resolution the.
- closure of security risks including review plans and monitor progress or.
- remedial actions.
- Conduct and perform advanced vulnerability and.
- penetration testing.
- assessments.
- that also require in.
- depth.
- analysis of IT controls applied to network infrastructure, visualized servers,.
- databases, web applications and interfaces and supporting software.
- infrastructure.
- document.
- management, reporting.
- Analysis of technical requirements.
- to design and deliver both Infrastructure and IT Security solutions and.
- Assessment.
- Consults with IT and business.
- leaders to analyses IT security service needs to determine scope and priorities.
- of projects, and to discuss system requirements.
- Provides technical guidance on all.
- systems in place to all levels of Information Technology staff.
- Maintain infrastructure,.
- Application and security architecture documentation and provide support to.
- projects involving enterprise wide applications and supporting hardware.
- Develop security automation.
- test.
- in CI.
- CD pipeline on a Kubernetes based platform, both.
- on premises and on a multi.
- cloud.
- infrastructure.
- AWS and GCP.
- Essential Skills & Prerequisites.
- A positive, can.
- do attitude, who naturally.
- expresses a high degree of empathy to others.
- Bachelor or Master.
- s degree in Computer.
- Engineering, MIS, IT or related field.
- At least 4.
- 5 year experiences in computer security area.
- Have a foundation in good information.
- security practices.
- Functional knowledge of networks,.
- products, Or Software Development Life Cycle.
- Knowledge of E2E security design.
- including network, platform and application.
- Experience in system and.
- applications security management and control.
- Experience in facilitating.
- information security risk assessments.
- Technical writing, documentation.
- development, process mapping, and visual communication skills.
- Professional certificates related.
- to work.
- e.
- g.
- CISSP, CISM, CEH, Sec.
- ISO 27001, PCI DSS or similar general security certification.
- is desirable.
- Good command of English.
Experience:
5 years required
Skills:
Risk Management, ISO 27001
Job type:
Full-time
Salary:
negotiable
- การวางแผนกลยุทธ์ด้านความปลอดภัยทางไซเบอร์.
- พัฒนา นโยบาย, มาตรฐาน, และแนวทางปฏิบัติ ด้านความปลอดภัยสารสนเทศ.
- กำหนดแนวทางปฏิบัติให้สอดคล้องกับกฎหมายและมาตรฐานสากล.
- จัดทำโปรแกรมฝึกอบรมความปลอดภัยทางไซเบอร์ ให้พนักงาน.
- การบริหารความเสี่ยงด้านความปลอดภัยทางไซเบอร์.
- วิเคราะห์ ความเสี่ยงทางไซเบอร์ (Cyber Risk Assessment).
- กำกับดูแลแนว นโยบาย, มาตรฐาน, และแนวทางปฏิบัติทางปฏิบัติให้สอดคล้องกับกฎหมายและมาตรฐานสากลและเป็นตามกฎระเบียบของบริษัท อาทิเช่น นโยบายสารสนเทศ, ISO 27001, PDPA, NIST และนโยบายด้านความปลอดภัยทางไซเบอร์อื่น ๆ ที่บริษัทได้นำมาใช้ภายในบริษัท.
- การปฏิบัติการด้านความปลอดภัยและการตอบสนองต่อเหตุการณ์.
- วิเคราะห์ ความเสี่ยงทางไซเบอร์ (Cyber Risk Assessment).
- บริหารจัดการ เหตุการณ์ด้านความปลอดภัยทางไซเบอร์ (Incident Response) อาทิเช่น การโจมตีจากแฮกเกอร์, Ransomware, Data Breach,etc.
- การตรวจจับและป้องกันภัยคุกคามทางไซเบอร์.
- บริหารจัดการกำกับดูแลและควบคุม Firewall, IDS/IPS, SIEM, Endpoint Security เพื่อตรวจสอบภัยคุกคาม.
- วิเคราะห์และบริหารจัดการ ภัยคุกคามทางไซเบอร์แบบเชิงรุก.
- ตรวจสอบและนำเทคโนโลยีใหม่ ๆ มาใช้เพื่อเพิ่มความปลอดภัย.
- ตรวจสอบและประเมินความเสี่ยงของ Third-Party Vendors ที่เกี่ยวข้องกับข้อมูลบริษัท.
- การสนับสนุนกิจกรรมด้านความปลอดภัยทางไซเบอร์.
- รับผิดชอบ, ติดตาม และแก้ไขปัญหาที่เกี่ยวข้องกับระบบ Cyber Security.
- กำกับดูแลการป้องกันต่างๆ ตามที่ได้รับมอบหมาย เช่น update Cyber Security.
- สนับสนุน, จัดทำเอกสารประกอบ และดูแลรักษาระบบ Cyber Security.
- กำกับดูแลการจัดทำข้อมูล Cyber Security ที่ได้รับมอบหมาย.
- กำกับดูแลดำเนินการบริหารจัดการทะเบียนความเสี่ยงต่าง ๆามที่ได้รับการอนุมัติ.
- กำกับดูแลการรวบรวมและจัดทำข้อมูลรายงาน Risk Management.
- กำหนดแนวทางพัฒนาทักษะของทีมงานด้าน Cyber Security.
- วางแผนการลงทุนในระบบฐานข้อมูลให้รองรับต่อเหตุการการโจมตีทาง Cyber Security โดยตัดสินใจจากข้อมูลเกี่ยวกับข้อมูล และผลวิเคราะห์แนวโน้มของข้อมูล.
- บริหารโครงการติดตั้งระบบด้าน Cyber Security.
- มอบหมายงาน ติดตามงาน ทบทวน และประเมินผลงานของทีมงาน.
- จัดทำรายงานกิจกรรม และความคืบหน้าของโครงการต่างๆ ที่ทีมงาน.
- Educations Background(การศึกษา).
- ปริญญาตรีทางวิศวกรรม หรือ วิทยาศาสตร์ สาขาคอมพิวเตอร์ หรือเทียบเท่า.
- Professional Experiences(ประสบการณ์การทำงาน).
- มีประสบการณ์ทำงานอย่างน้อย 10 ปี.
- มีประสบการณ์มากกว่า 6 ปีในงานดูแล Cyber Security.
- มีประสบการณ์ในการบริหาร / บังคับบัญชาทีมงาน.
- มีความรู้ด้านระบบ Cyber Security ดังต่อไปนี้.
- o ความรู้ทางเทคนิค (Technical Knowledge) Network Security, Endpoint Security & Malware Protection, Cloud Security, Application Security และ Incident Response เป็นต้น.
- o ความรู้ด้านกฎหมายและมาตรฐานความปลอดภัย GDPR, PDPA, ISO/IEC 27001 หรือ NIST.
- o ทักษะการบริหารจัดการ (Management Skills) Risk Management, Communication & Training หรือ Policy Development.
- o ความรู้เกี่ยวกับแนวโน้มภัยคุกคามและเทคโนโลยีใหม่ Cyber Threats และ Zero-Day Attacks ความเข้าใจ AI และ Machine Learning ใน Cyber Security, Threat Intelligence Tools เช่น MITRE ATT&CK, Cyber Threat Feeds.
- HUMAN RELATIONS SKILLS (คุณลักษณะที่จำเป็น).
- ทักษะด้านมนุษยสัมพันธ์ที่จำเป็นต่อการปฏิบัติงาน.
- ทักษะในการทำงานเป็นทีม.
- ทำงานร่วมกับผู้อื่นได้อย่างมีประสิทธิภาพ และ ให้ความร่วมมือกับทีมงานทุกฝ่าย.
- มีมนุษยสัมพันธ์ที่ดี และ มุ่งเน้นการให้บริการที่เป็นมิตรและสร้างสรรค์.
- ทักษะการสื่อสารและการประสานงาน.
- สามารถ อธิบายเรื่องเทคนิคที่ซับซ้อนให้เข้าใจง่าย สำหรับผู้ใช้ที่ไม่มีพื้นฐานด้าน IT.
- มีความสามารถในการ ประสานงานทั้งภายในและภายนอกองค์กร อย่างมีประสิทธิภาพ.
- แจ้งข้อมูลเกี่ยวกับ ปัญหาของระบบกลางหรือปัญหาทางเทคนิค ที่อาจส่งผลกระทบต่อผู้ใช้.
- ให้ข้อมูลอัปเดตเกี่ยวกับ สถานะของปัญหาที่กำลังดำเนินการแก้ไข.
- การจัดการข้อร้องเรียนและการควบคุมอารมณ์.
- สามารถ รับมือกับข้อร้องเรียนของผู้ใช้ ได้อย่างเป็นมืออาชีพ.
- มีความสามารถในการจัดการกับ พฤติกรรมเชิงลบหรือพฤติกรรมก้าวร้าวของผู้ใช้บริการ.
- DESCISION MAKING RESPONSIBILITY (ความรับผิดชอบในการตัดสินใจ).
- การวิเคราะห์และการตัดสินใจในการแก้ไขปัญหา.
- ศึกษา, วิเคราะห์, และตรวจสอบปัญหาด้าน Cyber Security ในระบบที่รับผิดชอบ.
- ตัดสินใจเกี่ยวกับการ แก้ไขปัญหาด้านเทคนิค อย่างรวดเร็วและมีประสิทธิภาพ.
- สามารถตัดสินใจ แก้ไขปัญหาพื้นฐานในระบบที่รับผิดชอบได้ด้วยตนเอง.
- การออกแบบระบบและแนวทางการรักษาความปลอดภัย.
- มีความสามารถในการ ออกแบบระบบ Cyber Security เพื่อป้องกันภัยคุกคามทางไซเบอร์.
- ตัดสินใจเกี่ยวกับการเลือก เครื่องมือและเทคโนโลยี ที่เหมาะสมเพื่อเสริมสร้างความปลอดภัยในองค์กร.
- การให้คำแนะนำและการประเมินผลกระทบ.
- ให้คำแนะนำเกี่ยวกับ ผลกระทบด้านความปลอดภัยทางไซเบอร์ ต่อระบบและการดำเนินธุรกิจ.
- ตัดสินใจในเรื่อง การจัดการความเสี่ยงทางไซเบอร์ และการลงทุนในเทคโนโลยีความปลอดภัย.
Experience:
8 years required
Skills:
SAP
Job type:
Full-time
Salary:
negotiable
- Develop and implement comprehensive SAP data management strategies and policies that align with organisational objectives and industry best practices.
- Oversee the design, implementation, and maintenance of SAP security frameworks, including access controls, encryption, and authentication protocols.
- Lead data governance initiatives to ensure data quality, integrity, and compliance across all SAP systems and processes.
- Manage and supervise a team of data and security professionals, providing mentoring, coaching, and professional development opportunities.
- Conduct regular security audits and risk assessments to identify vulnerabilities and recommend remediation strategies.
- Ensure compliance with relevant data protection regulations, industry standards, and internal policies.
- Collaborate with business units to understand data requirements and design solutions that balance security with operational efficiency.
- Monitor SAP system performance and data security metrics, reporting on key performance indicators to senior management.
- Lead incident response and data breach management protocols, ensuring timely and effective resolution.
- Stay current with emerging technologies, security threats, and industry trends, recommending strategic investments and upgrades.
- What we're looking for.
- Bachelor's degree in Computer Science, Information Technology, Business Administration, or a related field.
- Minimum of 10 years of professional experience in SAP systems management, with at least 5 years in a senior management or leadership capacity.
- Extensive knowledge of SAP data architecture, data warehousing, and enterprise data management solutions.
- Advanced expertise in SAP security, including user access management, system security, encryption, and compliance controls.
- Strong understanding of data protection regulations such as GDPR, PDPA, or equivalent regional data privacy laws.
- Proven experience managing large, complex SAP implementations or upgrades in multi-site environments.
- Demonstrated ability to lead, mentor, and develop technical teams.
- Excellent project management skills with the ability to manage multiple initiatives simultaneously.
- Strong analytical and problem-solving capabilities with a strategic mindset.
- Excellent communication skills with the ability to present complex technical concepts to non-technical stakeholders.
- Professional certification in SAP security, data management, or related fields (such as SAP Certified Associate, CISSP, or equivalent) is highly desirable.
- Experience with cloud-based SAP solutions and hybrid environments is advantageous.
- Apply now.
- If you are an experienced SAP professional with a passion for data security and management, and you meet the qualifications outlined above, we would like to hear from you. Please submit your CV, a cover letter detailing your relevant experience, and any supporting documents to our Human Resources team. Join SVI Public Company Limited and make a significant impact on our data and security operations.
Skills:
Project Management, Risk Management, Automation
Job type:
Full-time
Salary:
negotiable
- This role is responsible for driving moderately complex activities to ensure the security and integrity of an organization's systems, processes, and data.
- The role involves gathering evidence, analyzing data, and collaborating with various teams to mitigate risks and ensure compliance.
- The role identifies security risks and priorities related to organizational functions and establishes long-term security goals.
- Delivers tactical security support to specific divisional/regional operations, manages one or more security programs focused on an aspect of security fundamental to organizational security strategy.
- Provides guidance and support to site and subsidiary security operations, ensuring organizational standard are implemented.
- Assesses security exposures and implements programs to address them, influencing stakeholders and clients as required.
- Conducts and supports investigations within the region or elsewhere as requested by Global Security Management.
- Provides support as directed in areas of executive protection, crisis management, site security, brand security, etc.
- Provides training and awareness programs for employees and stakeholders on security best practices.
- Develops and maintains security data to enable trending and return on investment analysis, maintains incident reporting database and measures.
- Assesses and monitors the security practices of third-party vendors providing services to the organization.
- Develops and implements security policies, procedures, and controls for organizational systems; maintains liaison with government, industry, and intelligence professionals.
- Education & Experience Recommended.
- Four-year or Graduate Degree in Criminal Justice, Security Management, Law Enforcement, or any other related discipline or commensurate work experience or demonstrated competence.
- Typically has 7-10 years of work experience, preferably in law enforcement, military, intelligence, specialized security systems, or a related field.
- Preferred Certifications.
- Certified Protection Professional (CPP).
- Certified Information Systems Security Professional (CISSP).
- Industry Certifications (CISM, CISA or similar).
- Knowledge & Skills.
- Access Controls.
- Alarm Devices.
- Asset Protection.
- Automation.
- Crisis Management.
- Evidence Preservation.
- Exception Reporting.
- Incident Response.
- Information Privacy.
- Law Enforcement.
- Loss Prevention.
- Physical Security.
- Physical Security Operations.
- Project Management.
- Risk Analysis.
- Risk Management.
- Security Information And Event Management (SIEM).
- Security Management.
- Security Systems.
- Vulnerability.
- Cross-Org Skills.
- Effective Communication.
- Results Orientation.
- Learning Agility.
- Digital Fluency.
- Customer Centricity.
- Impact & Scope.
- Impacts function and leads and/or provides expertise to functional project teams and may participate in cross-functional initiatives.
- Complexity.
- Works on complex problems where analysis of situations or data requires an in-depth evaluation of multiple factors.
- Disclaimer.
- This job description describes the general nature and level of work performed in this role. It is not intended to be an exhaustive list of all duties, skills, responsibilities, knowledge, etc. These may be subject to change and additional functions may be assigned as needed by management.
- LiPost.
- Job -.
- Supply Chain & Operations.
- Schedule -.
- Full time.
- Shift -.
- No shift premium (Thailand).
- Travel -.
- 25%.
- Relocation -.
- NoEqual Opportunity Employer (EEO) -.
- HP, Inc. provides equal employment opportunity to all employees and prospective employees, without regard to race, color, religion, sex, national origin, ancestry, citizenship, sexual orientation, age, disability, or status as a protected veteran, marital status, familial status, physical or mental disability, medical condition, pregnancy, genetic predisposition or carrier status, uniformed service status, political affiliation or any other characteristic protected by applicable national, federal, state, and local law(s).
- Please be assured that you will not be subject to any adverse treatment if you choose to disclose the information requested. This information is provided voluntarily. The information obtained will be kept in strict confidence.
- For more information, review HP's EEO Policy or read about your rights as an applicant under the law here: "Know Your Rights: Workplace Discrimination is Illegal".
Skills:
Project Management, Cloud Computing, Web Services, Procurement
Job type:
Full-time
Salary:
negotiable
AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we're the people who keep the cloud running. We support all AWS data centers and all of the servers, storage, networking, power, and cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most challenging problems, with thousands of variables impacting the supply chain and we're looking for talented people who want to help. You'll join a diverse team of software, hardware, and network engineers, su ...
Experience:
5 years required
Skills:
Procurement, Recruitment, Negotiation, English, Thai
Job type:
Full-time
Salary:
฿80,000 - ฿120,000, negotiable
- Mind Edge Recruitment is hiring on behalf of our client, a leading Thai security innovation and technology company providing integrated solutions across cybersecurity, physical security, privacy and data protection, and public safety.
- Work Location: Lat Phrao 18, Bangkok.
- Working Days: Monday-Friday.
- Working Hours: 9:00 AM-6:00 PM.
- Salary and Allowances.
- Base salary.
- Car and travel allowance: THB 6,500 per month.
- Mobile phone allowance: THB 1,000 per month.
- Attractive commission scheme, subject to agreement.
- Drive enterprise technology sales, build pipelines, and close high-value cybersecurity and security solution deals with private and public organizations.
- Define Ideal Customer Profiles (ICP) and develop B2B market penetration strategies targeting large enterprises, critical infrastructure, regulated industries, government agencies, and Smart City projects.
- Proactively acquire new accounts and establish executive-level relationships with CEOs, CIOs, CTOs, CISOs, DPOs, CSOs, Heads of Risk and Compliance, and Procurement leaders.
- Generate new business opportunities independently without relying solely on inbound leads.
- Translate cybersecurity, privacy and PDPA, data protection, and physical security risks into practical business solutions that improve efficiency, reduce risks, and deliver measurable value.
- Manage complex enterprise sales cycles involving multiple stakeholders, technical evaluations and POCs, security reviews, RFPs/TORs, legal and DPA reviews, and procurement processes.
- Prepare business cases, proposals, solution presentations, and commercial offers tailored to clients' requirements.
- Manage pricing, discounts, gross margins, payment terms, cash flow, and contractual risks to ensure profitable and deliverable deals.
- Build and maintain a healthy sales pipeline and prepare accurate sales forecasts through CRM systems.
- Apply structured sales methodologies such as MEDDPICC, SPICED, or equivalent frameworks to qualify and manage opportunities.
- Develop co-selling partnerships with System Integrators, telecommunications companies, cloud providers, and consulting partners while maintaining account ownership and transparent deal registration.
- Work closely with technical, project, and customer success teams to ensure effective handover, solution adoption, client satisfaction, and contract renewal.
- Manage one existing team member and support future team expansion while remaining actively involved in individual sales activities.
- Sell solutions to both private- and public-sector clients, with a primary focus on private enterprises.
- Bachelor's degree in Information Technology, Computer Science, Engineering, Business Administration, Marketing, or a related field.
- At least 5 years of experience in enterprise software, cybersecurity, IT infrastructure, SaaS, physical security, PSIM, or complex technology solution sales.
- Proven record of consistently achieving or exceeding sales targets.
- Able to clearly demonstrate previous sales performance, including sales quota, actual sales, attainment percentage, average deal size, and sales cycle.
- Proven ability to build a sales pipeline from the ground up and independently close deals valued from several million to tens of millions of Thai baht.
- Strong understanding of enterprise security technology, such as Security Operations, Governance, Privacy and Data Protection, Cloud or Network Security, or Physical Security Integration.
- Ability to communicate business value effectively with C-level executives and discuss solution requirements with technical teams.
- Experience managing complex sales cycles involving multiple decision-makers, POCs, RFPs/TORs, legal reviews, and procurement.
- Familiarity with sales qualification frameworks such as MEDDPICC, SPICED, or equivalent is preferred.
- Good commercial understanding of pricing, gross margins, cash flow, payment terms, contracts, and collection.
- Excellent presentation, communication, and negotiation skills in Thai.
- Good command of English for meetings, documentation, and coordination with international partners or vendors.
- Must own a car, hold a valid driving licence, and be available to visit clients in Bangkok and upcountry locations.
- Preferred Qualifications.
- Experience selling multi-module platforms or executing land-and-expand strategies across enterprise accounts.
- Established professional network among CISOs, CIOs, DPOs, CSOs, critical infrastructure, Smart City, Command Center, or Public Safety organizations.
- Understanding of enterprise and government procurement processes, including TORs, RFPs, and working with System Integrators or telecommunications partners.
- Experience selling recurring SaaS, Managed Security Services, Managed Services, or subscription-based solutions.
- Experience managing customer retention, renewal, account expansion, or Net Revenue Retention.
- Social Security.
- Group Insurance.
- Annual Leave.
- Public Holidays and Weekly Days Off.
- Free Lunch.
- Complimentary Snacks, Tea, and Coffee.
- Monthly Team Activities.
- Performance-based Annual Bonus.
- Car and Travel Allowance.
- Mobile Phone Allowance.
- Commission Scheme.
- Why Join Our Client?.
- Sell integrated cybersecurity and security technology solutions to major enterprise customers.
- Take ownership of high-value deals from pipeline creation through closing and renewal.
- Join a growing business with the opportunity to develop and expand the sales team.
Skills:
Risk Management, Recruitment, English, Thai, Laos
Job type:
Full-time
Salary:
฿60,000 - ฿80,000, negotiable
- VFS (THAILAND) LTD. is seeking an experienced and strategic.
- Senior Manager - Corporate Security.
- to join our Bangkok office on a full-time basis. This is a pivotal leadership position within our security and risk management division, responsible for overseeing all aspects of corporate security operations and ensuring the protection of our assets, personnel and facilities. You will handle Thailand,Myanmar,Laos & Cambodia and play a critical role in safeguarding our business operations across all locations.
- Developing and implementing comprehensive corporate security policies, procedures and protocols to protect company assets, personnel and facilities.
- Overseeing the management and supervision of security personnel, including recruitment, training, performance management and team development.
- Conducting regular security audits and risk assessments to identify vulnerabilities and recommend appropriate mitigation strategies.
- Managing security incident response procedures and conducting investigations into security breaches or suspected violations.
- Liaising with external security agencies, law enforcement and government authorities to ensure compliance with local security regulations and standards.
- Developing and maintaining security infrastructure, including access control systems, surveillance systems and alarm systems.
- Preparing detailed security reports and presenting findings and recommendations to management.
- Managing the corporate security budget and ensuring cost-effective deployment of resources.
- Staying current with evolving security threats, best practices and emerging technologies in the security industry.
- Co-ordinating with other departments to integrate security requirements into business operations and continuity planning.
- What we're looking for.
- Maximum 10 years of professional experience in corporate security management or a related security field.
- Proven track record of successfully leading and managing security teams in a corporate or commercial environment.
- Comprehensive knowledge of security best practices, protocols and regulatory compliance requirements in Thailand.
- Strong background in risk assessment, threat analysis and security system design and implementation.
- Proficiency in security technologies and systems, including CCTV, access control and alarm monitoring systems.
- Professional certifications in security management (such as CPP, PSP or equivalent) are highly desirable.
- Fluency in English and Thai is mandatory; additional languages are advantageous.
- What we offer.
- Comprehensive group health insurance and provident funds contribution from employer.
- Professional development and training opportunities to enhance your security expertise and leadership skills.
- Opportunities for career progression within our growing organisation.
- A collaborative workplace culture that values innovation and continuous improvement.
- Apply now.
- If you are an experienced security professional ready to take on this senior management challenge, we would like to hear from you. Please submit your CV, a cover letter highlighting your relevant experience and any professional certifications to our recruitment team. We look forward to considering your application for the position of Senior Manager - Corporate Security at VFS (THAILAND) LTD.
Skills:
Financial Analysis, Cloud Computing, Web Services
Job type:
Full-time
Salary:
negotiable
AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we're the people who keep the cloud running. We support all AWS data centers and all of the servers, storage, networking, power, and cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most challenging problems, with thousands of variables impacting the supply chain and we're looking for talented people who want to help. You'll join a diverse team of software, hardware, and network engineers, su ...
Skills:
Computer Security, Risk Management
Job type:
Full-time
Salary:
negotiable
ซื้อประกันภัยออนไลน์กับเออร์โกประกันภัย (ERGO Insurance) ประกันภัยรถยนต์ชั้น 1, 2+, 3+ ประกันสุขภาพ และประกันอุบัติเหตุ คุ้มครองครอบคลุม บริการรวดเร็ว 24 ชม.
Experience:
5 years required
Skills:
Kubernetes, Docker, Kafka
Job type:
Full-time
Salary:
฿50,000 - ฿70,000, negotiable
- As Head of Platform & Security, you will lead and shape the strategic direction of our platform, building, scaling, and running a world-class cloud infrastructure. You will own the full platform engineering function, bring modern engineering, CD, developer experience and autonomy to all, and you become a strong and vocal leader for all our engineering teams.
- You will own the security function. Your team will actively follow security best practices and topics, and own the security backlog for our organization. You will be su ...
- Lead and grow a high-performing Platform & Security team, setting the vision, culture, and technical direction.
- Own the design, delivery, and evolution of highly available, flexible, secure and cheap infrastructure at scale.
- Enable great developer experience, leveraging trunk-based and continuous delivery pipeline to enable product engineering teams autonomy.
- Leverage extensive automation to embed standards, security and operational excellence into every stage of the development lifecycle.
- Drive a DevSecOps culture where reliability, availability, security are shared responsibilities for all team members.
- Stay actively engaged with security topics day to day following the threat landscape, reviewing approaches, and remaining hands-on enough to guide the team and make sound technical decisions.
- Build and embed security fundamentals across The 1 Platform, developing and continuously improving generalisable approaches to authorization, authentication, abuse detection, abuse prevention, and auditing.
- Lead platform and product security incident response, ensuring timely detection, escalation, and resolution of security events.
- Oversee security auditing practices for platform infrastructure, ensuring compliance with internal policies and relevant regulatory requirements.
- Establish and govern reusable platform standards, golden paths, and self-service capabilities that accelerate product delivery.
- Define and own the platform and security roadmap, balancing short-term delivery needs with long-term scalability, reliability, security, and cost sustainability.
- Serve as the executive-level technical authority for cloud, Kubernetes, CD, security, and shared infrastructure services.
- Act as a trusted technical advisor and strategic partner to engineering, product, finance, compliance, and executive stakeholders.
- Proactively identify and mitigate scaling, reliability, security, and cost risks before they impact customers.
- Own and drive the organization's FinOps strategy, ensuring effective cloud cost governance and optimization across compute, storage, networking workloads.
- Establish cost visibility, attribution, and accountability frameworks across engineering teams.
- Recruit, develop, and retain senior platform and security engineering talent; build a coaching and mentorship culture within the team.
- Define and report on engineering, security, and operational metrics, communicating platform health, progress, and investment trade-offs to senior leadership.
- Watch your leadership impact a rapidly growing company and the lives of our customers.
- Deep expertise in AWS/GCP, CD Terraform, Docker, Kubernetes, Kafka, API gateways.
- Demonstrated experience leading and scaling platform, security, engineering teams.
- Enthusiast to collaborate with all engineers towards excellence as a team.
- Proven track record of securing cloud environments, API gateways, and platform services at scale, including abuse detection, penetration testing.
- Strong knowledge of network infrastructure and cloud security architecture.
- Treats git as the source of truth for everything infrastructure, configuration, and policy.
- Holds a BS/BA degree in computer science or a relevant field.
- Has at least 8 years of experience in platform, infrastructure, or DevSecOps/security engineering, with 3+ years in a senior leadership role.
- Strong command of computer science fundamentals and distributed systems principles.
- Passionate about reliability, performance, security, and building platforms that others love to use.
- An exceptional leader and communicator who can inspire engineers, influence executives, and build alignment across diverse stakeholders from design to compliance.
- Operates with high autonomy and sound judgment in ambiguous, fast-moving environments.
- Thinks at the system, organizational, and business-impact level not just at the component or team level.
- Brings a product mindset to platform engineering focused on developer experience, internal adoption, and measurable business outcomes.
Experience:
10 years required
Skills:
Architecture, Recruitment, Negotiation, Automation, English
Job type:
Full-time
Salary:
negotiable
- Our client is a rapidly growing, venture-backed B2B SaaS company headquartered in Bangkok, Thailand, serving thousands of businesses across more than 100 countries. They develop AI-powered software solutions that help organizations streamline critical business processes and are recognized as one of the leading technology companies in the region.
- With a highly international team and a strong engineering culture, the company values innovation, ownership, and collaboration. As they continue expanding globally, the ...
- About the Role.
- Reporting directly to the Chief Technology Officer (CTO), the Head of Security, Trust & Compliance will lead the organization's security, trust, and compliance initiatives. This strategic leadership role oversees Trust & Safety operations, security compliance, IT management, and enterprise security support throughout the customer lifecycle.
- Managing a team of three, you will serve as the primary bridge between security operations and engineering, driving automation projects, strengthening security processes, and ensuring the organization maintains a strong security posture while supporting business growth.
- Trust & Safety.
- Own the end-to-end account verification workflow (KYB) after subscription, ensuring legitimate use of the platform.
- Define and continuously improve fraud detection processes: fraudulent job postings and general abuse and misuse.
- Act as the project manager for fraud detection automation: define requirements, timelines, and deliverables in collaboration with the Engineering team.
- Establish and maintain Trust & Safety policies, escalation paths, and response playbooks.
- Security & Compliance.
- Own and drive SOC 2 Type 2 compliance, including audit preparation, evidence collection, control monitoring, and remediation tracking.
- Orchestrate the penetration testing program end-to-end: vendor selection, scoping, tooling setup, intake of findings into Jira, report negotiation, and remediation coordination with engineering teams.
- Orchestrate the bug bounty program: vendor management, triage workflow, severity assessment coordination, and remediation tracking.
- Own security incident response for non-product incidents (reported data breaches, unauthorized access, credential compromise). Product availability incidents remain with the Engineering Team.
- Proactively identify security risks across the organization and implement mitigation strategies that balance security with operational velocity.
- Sales Enablement.
- Directly answer complex or non-standard questions that require deep knowledge of Manatal's security posture.
- Lead the technical response for security questionnaires, RFIs and RFPs, acting as the subject matter expert to support enterprise sales cycles.
- IT Management.
- Manage the IT function (helpdesk, device management, access control, internal tooling).
- Define and oversee the lifecycle management of all company IT assets, ensuring hardware and software inventory is secure, tracked, and compliant.
- Ensure IT-related policies and operations align with SOC 2 and broader security requirements.
- Culture & Cross-Functional Collaboration.
- Partner with Engineering to scope and prioritize security and trust-related automation projects.
- Provide security input during product and architecture reviews when trust or compliance implications exist.
- Foster a culture of security awareness across all departments through training and clear policy definitions.
- Report on trust, security, and compliance posture to the CTO on a regular cadence.
- 6+ years of experience in information security, trust & safety, or GRC, with at least 2 years in a leadership role within a technology company.
- Hands-on experience owning a SOC 2 Type 2 program (audit preparation, evidence collection, remediation tracking).
- Experience managing external security vendors (penetration testing firms, auditors, or bug bounty platforms).
- Ability to define security and trust workflows and translate them into actionable projects for engineering teams.
- Strong understanding of cloud infrastructure security and web application security.
- People management experience.
- Excellent English communication skills, written and verbal. You will negotiate with vendors, write policies, and interface with clients.
- Technical fluency: you can read a vulnerability report, understand API-level risks, and write requirements that engineers can act on.
- Nice to Have.
- Experience with KYB/KYC processes.
- Familiarity with privacy regulations (GDPR, PDPA, CCPA).
- Professional certifications (CISM, CISSP, CISA).
- Familiarity with compliance automation tools (Vanta, Drata, or similar).
- Background in recruitment technology or HR tech.
- Language Proficiency.
- Fluent in English.
- Social Security.
- Comprehensive health insurance + Telemedicine service.
- 15 days of paid annual leaves (Pro-rated).
- 13 days of national holiday.
- 2 weeks/year to work from anywhere (After probation).
- Monthly new hire & birthday lunches.
- Personal development allowance.
- Working Conditions.
- Full-time position based in Bangkok, Thailand.
- On-site working environment with flexibility to collaborate across global time zones.
- Standard office hours with occasional flexibility depending on business needs.
- Opportunity to work alongside an international, high-performing technology team.
- Learn More About the Company.
- Please send your resume or enquiries to.
- [email protected].
- or connect with us on.
- LinkedIn.
Experience:
8 years required
Skills:
Enthusiastic, English
Job type:
Full-time
Salary:
negotiable
- Head of Security Advisory, is the managerial position that leads the team to continuously establish and enforce security baseline, security standard and security policy for the bank, to ensure that all stakeholders are continuously aware, prepared and having necessary security control in place for both existing and emerging technology component supporting the organization roadmap, organization security certification and regulatory security requirements.
- The unit also leads on security design, security assessment and approval of Data sha ...
- The unit lead on security assessment of the new Solution acquisition.
- Cybersecurity knowledge in Banking.
- Fast -Learner for new IT and security technology and practice.
- Comprehensive Security control & security organization assessment experience.
- Technology Security consultation skill.
- English skill / Security certification.
- We're committed to bringing passion and customer focus to the business.
- If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us.
Experience:
1 year required
Skills:
Leadership Skill
Job type:
Full-time
Salary:
negotiable
- Provide recommendations and participate in planning to ensure the security of customers, employees, buildings, and assets of the Siam Piwat Group and its affiliates, in accordance with overall policies.
- Participate in planning and provide guidance in supervising and overseeing the work of subcontractors to ensure they perform according to the work plan.
- Security Management: Develop and implement comprehensive security plans to protect the mall, its patrons, and employees.
- Safety Protocols: Participate in setting standards for security, traffic management, and the management of parking facilities within the shopping center.
- Crisis Response: Provide recommendations and participate in developing security standards to be prepared for various potential emergencies.
- Team Leadership: Supervise and mentor the security team, providing training and development opportunities to enhance their skills and performance.
- Surveillance and Monitoring: Oversee the operation of surveillance systems and ensure continuous monitoring of the premises.
- Incident Reporting: Manage the documentation and investigation of security incidents, accidents, and breaches, and implement corrective actions.
- Collaboration: Work closely with local law enforcement, emergency services, and other relevant agencies to coordinate security efforts and response plans.
- Budget Management: Prepare and manage the security departments budget, ensuring cost-effective use of resources.
- Customer Service: Maintain a visible presence within the mall, addressing security concerns of customers and staff promptly and professionally.
- Bachelors degree in Security Management, Criminal Justice, or a related field.
- Minimum of 15 years of experience in security management, with at least 10 years in a leadership role.
- Strong knowledge of safety regulations, crisis management, and emergency response protocols.
- Excellent leadership, communication, and interpersonal skills.
- Ability to remain calm and make quick decisions in high-pressure situations.
- Proficiency in security technology and surveillance systems.
- Candidates with experience in the.
- luxury shopping mall.
- or.
- luxury hotel industry.
- will be given special consideration.
- Has a background in the military will be given special consideration.
Skills:
SAP, Compliance, English
Job type:
Full-time
Salary:
negotiable
- Lead the SAP Basis and Security/Authorization workstream across SAP S/4HANA implementation and rollout programs.
- Manage environment readiness, transport strategy, release management, cutover planning, and production deployment activities.
- Oversee SAP Cloud ALM (CALM) activities, including deployment governance, monitoring, testing coordination, defect management, and release tracking.
- Lead security and authorization design, role management, user provisioning, access controls, authorization testing, and Segregation of Duties (SoD) compliance.
- Support deployment and integration activities across SAP S/4HANA, SAP MDG, SAP Group Reporting, SAP PaPM, SAP CPI, SAP BTP, and SAP Business Data Cloud (BDC).
- Plan and execute environment management, transport migrations, system refreshes, cutover activities, hypercare support, and production readiness assessments.
- Collaborate with Functional, Integration, Development, Data Migration, and Testing teams to ensure successful end-to-end solution deployment.
- Coordinate with SAP hosting providers, technical teams, and key stakeholders to resolve deployment issues and drive successful program delivery.
- Extensive experience in SAP Basis and SAP Security/Authorization, typically gained through 10+ years of relevant experience.
- Proven experience delivering at least three full-cycle SAP S/4HANA implementation or rollout programs.
- Hands-on experience with SAP S/4HANA Private Cloud and RISE with SAP environments.
- Strong knowledge of SAP Cloud ALM (CALM), transport management, release management, cutover planning, and environment governance.
- Deep understanding of SAP Security and Authorization concepts, role design, user administration, compliance controls, and SoD requirements.
- SAP S/4HANA, including Group Reporting.
- SAP Master Data Governance (MDG).
- SAP Profitability and Performance Management (PaPM).
- SAP CPI / SAP Integration Suite.
- SAP Business Technology Platform (BTP).
- SAP Business Data Cloud (BDC).
- Strong stakeholder management and leadership skills, including coordination across onshore and offshore teams.
- Strong communication skills in English and Thai, as the role requires regular collaboration with local and global stakeholders.
- Preferred Qualifications.
- Experience supporting transformation programs within FMCG, Consumer.
- Goods, Beverage, or Bottling industries.
- Experience managing enterprise-scale deployment, cutover, and hypercare activities in global SAP programs.
- SAP certifications related to Basis, Security, SAP S/4HANA, or SAP Cloud technologies.
- About Accenture.
- Accenture is a leading global professional services company that helps the world s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world s leaders in helping drive that change, with strong ecosystem relationships.
- We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360 value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360 value we create for our clients, each other, our shareholders, partners and communities.
- Visit us at www.accenture.com.
- Equal Employment Opportunity Statement.
- We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, military veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.
Skills:
Legal, Procurement
Job type:
Full-time
Salary:
negotiable
- กำหนดและกำกับดูแลนโยบายด้าน IT Governance, Cybersecurity, AI Governance.
- Ensure การปฏิบัติงานสอดคล้องกับมาตรฐาน เช่น ISO 27001, NIST, DJSI.
- ทำงานร่วมกับ Legal, HR และ Procurement เพื่อให้สอดคล้องกับข้อกำหนดกฎหมายและนโยบายองค์กร.
- Information Security & Quality Systemบริหารจัดการ Information Security Management System (ISMS).
- กำหนด Framework ด้าน People, Process และ Technology.
- ติดตาม Performance, Compliance และ Continuous Improvement.
- วางแผน Quality System ระยะ 3 ปี (Surveillance & Recertification Audit).
- Policy & Risk ManagementReview / Revamp Policy ให้สอดคล้องกับกฎหมาย (เช่น PDPA).
- ทำ Risk & Operational Review ครอบคลุมทุกหน่วยงาน.
- ดูแล Contract และ Internal Policies ให้ทันต่อ Regulatory Changes.
- Audit & Certification Managementบริหารจัดการ Internal & External Audit (เช่น BSI).
- เตรียมองค์กรสำหรับ ISO Certification และ Surveillance Audit.
- ทำงานร่วมกับ Committee และ Stakeholders ทุกฝ่าย.
- Strategic Planning & Executionจัดทำแผนประจำปีเพื่อรองรับมาตรฐาน (ISO, NIST, DJSI).
- Ensure การดำเนินงานเป็นไปตาม Timeline (เช่น ต้องเสร็จภายในเดือนกรกฎาคมของทุกปี).
- เชื่อมโยงแผนงานกับ Business Impact และ Digital Strategy.
- Stakeholder & Committee Managementทำงานร่วมกับผู้บริหารระดับสูงและคณะกรรมการบริษัท.
- เป็นตัวกลางระหว่าง D&T, Techno และหน่วยงานต่าง ๆ.
- สร้าง Alignment ทั่วทั้งองค์กรด้าน Security & Compliance.
- QualificationsRequiredประสบการณ์ระดับ Senior / Executive ด้าน IT Governance / Cybersecurity / Risk / Compliance.
- มีประสบการณ์ตรงด้าน ISO 27001 / NIST / IT Governance Framework.
- มีความเข้าใจด้าน PDPA / Regulatory / Legal Compliance.
- มีประสบการณ์บริหารทีม และขับเคลื่อนองค์กรขนาดใหญ่.
- Preferredมีประสบการณ์ดูแล Audit (Internal / External / Certification).
- เคยทำงานร่วมกับ Committee หรือ Board Level.
- เข้าใจด้าน Digital Transformation และ Enterprise IT.
- Contact Information:-.
- K. Nanchanok (Recruiter) Email: nanchanok.r@ thaibev.com.
- Company name: DIGITAL AND TECHNOLOGY SERVICES CO., LTD.
- Office Locattion: F.Y.I Center 2525 Rama IV Rd, Khlong Tan, Khlong Toei, Bangkok 10110.
- MRT QSNCC Station Exit 1.
Skills:
CompTIA Security+
Job type:
Full-time
Salary:
negotiable
- Security Analyst (SOC), Monitoring and analysis of cyber security events with the use of security tools.
- Escalating significant security incidents and conducting cyber investigations.
- Collaborating with engineering, security, and management teams on issue resolution and reporting.
- Managing operational tasks according to service level agreements (SLAs).
- Operating on a 24/7 rotating schedule with 12-hour daily shifts.
- Bachelor's degree in Computer Science, Computer Engineering, Information Technology, or related fields.
- Fresh graduates are welcome to apply.
- Some experience in technical analysis of computer system, network, email headers, links, and attachments.
- Ability to identify malicious emails and execute protective remediation techniques.
- Strong analytical and problem-solving capabilities.
- Knowledge of SIEM, Network Security, Application Security, Data Security, and Endpoint/User Security.
- Team-oriented approach with strong work ethic.
- High sense of responsibility and punctuality.
- Discretion and perseverance.
- CompTIA Security+, Network+, or CySA+ credentials provide competitive advantage.
Skills:
Risk Management, Automation, ISO 27001, Assurance, Python
Job type:
Full-time
Salary:
negotiable
- การบริหารจัดการบัญชีผู้ใช้และสิทธิ์การเข้าถึง (Identity & Access Management Administration).
- จัดการ Account Lifecycle Management (Provisioning, Deprovisioning, Account Recertification) สำหรับพนักงาน ผู้ใช้งานภายนอก และบัญชี Service Accounts.
- บริหารจัดการ Role-Based Access Control (RBAC) และ Least Privilege Access.
- ตรวจสอบและบังคับใช้ Multi-Factor Authentication (MFA), Single Sign-On (SSO) และ Password Policy.
- การเฝ้าระวังและตรวจสอบกิจกรรมการเข้าถึง (Access Monitoring & Auditing).
- เฝ้าระวังและวิเคราะห์ Access Logs และ Authentication Events เพื่อระบุความผิดปกติหรือพฤติกรรมที่เสี่ยงต่อความปลอดภัย.
- จัดทำ Identity & Access Review (IAR) ตามข้อกำหนดด้าน Compliance เช่น ISO 27001.
- วิเคราะห์และจัดทำรายงาน Access Certification และ Privileged Access Management (PAM) Review.
- การรักษาความปลอดภัยของบัญชีผู้ใช้และการเข้าถึง (Identity Security & Risk Management).
- ป้องกันและตรวจจับ Identity Threats เช่น Account Takeover (ATO), Credential Stuffing, และ Insider Threats.
- บริหารจัดการ Privileged Access Management (PAM) เช่น CyberArk, BeyondTrust, Delinea, PAM360.
- บังคับใช้ Zero Trust Security และ Identity Threat Detection & Response (ITDR).
- การจัดการและบูรณาการระบบ IAM (IAM Systems & Integration).
- ดูแลและปรับแต่งระบบ IAM Solutions เช่น Microsoft Entra ID (Azure AD), Okta, Ping Identity, One Identity, ForgeRock.
- บูรณาการระบบ IAM กับ Cloud (Azure AD), On-Premise AD, HR Systems และ Business Applications.
- พัฒนา IAM Automation & Workflows ด้วย API และ Scripting เช่น PowerShell, Python.
- การวิเคราะห์ช่องโหว่และเสริมสร้างความมั่นคงปลอดภัย (IAM Security Assessment & Hardening).
- ตรวจสอบ IAM Misconfigurations และ Excessive Permissions เพื่อลดความเสี่ยง.
- ทำ Privilege Escalation Testing และ Identity Threat Hunting เพื่อตรวจจับบัญชีที่อาจถูกแทรกแซง.
- บังคับใช้แนวทาง Just-In-Time Access (JIT) และ Passwordless Authentication.
- การปฏิบัติตามข้อกำหนดและมาตรฐานด้านความปลอดภัย (IAM Compliance & Governance).
- ดูแลให้ IAM Policies & Procedures สอดคล้องกับมาตรฐาน เช่น ISO 27001, NIST 800-53, CIS Controls.
- จัดทำเอกสาร IAM Risk Assessment และ Audit Report สำหรับทีมบริหารและหน่วยงานกำกับดูแล.
- ประสานงานกับทีม Security Engineer, SOC และ Risk Management เพื่อปรับปรุงการจัดการสิทธิ์ให้ปลอดภัยยิ่งขึ้น.
- การพัฒนาและฝึกอบรมทีมงานเกี่ยวกับ IAM (IAM Awareness & Training).
- อบรมพนักงานเกี่ยวกับ Identity Hygiene และ Access Security Best Practices.
- พัฒนา IAM Playbook และ Incident Response Procedures สำหรับการบริหารจัดการบัญชีผู้ใช้ที่ถูกบุกรุก.
- สนับสนุนและให้คำแนะนำด้าน IAM แก่ทีม IT, HR, และผู้ใช้งานทั่วไป.
- อื่น ๆ.
- ดูแล ควบคุม และป้องกันภัยคุมคามต่าง ๆ ทางด้านเทคโนโลยีและไซเบอร์ ให้เป็นไปตามมาตรฐานสำหรับความมั่นคงปลอดภัยของระบบเทคโนโลยีสารสนเทศ.
- จัดทำเอกสารสำหรับบันทึกปัญหา วิธีการแก้ไข รวมทั้งสาเหตุที่เกิดขึ้น เพื่อเก็บเป็นประวัติและแนวปฏิบัติในอนาคต.
- จัดทำรายงานข้อมูลความมั่นคงสารสนเทศ นำเสนอต่อผู้บังคับบัญชา.
- ร่วมในการวางแผนศึกษา/ปรับปรุงระบบ ในการนำเสนอเทคโนโลยีใหม่ ๆ เพื่อให้ระบบของโรงพยาบาลมีความมั่นคง ปลอดภัยที่เหมาะสม.
- ปฏิบัติตามนโยบาย ระเบียบ ข้อกำหนดของหน่วยงานให้เป็นไปตามมาตรฐาน ISO27001 และ JCI.
- ปริญญาตรีหรือปริญญาโท สาขาวิทยาศาสตร์หรือวิศวกรรมศาสตร์คอมพิวเตอร์, Information Security, Cyber Security and Information Assurance.
Skills:
Computer Security
Job type:
Full-time
Salary:
negotiable
- Validates, classifies, priorities and opens ticket.
- Acting as focal contact point for report security incidents.
- Document and escalate incidents (including event's history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment.
- Provide daily summary reports of security incidents.
- Responds to security alerts generate within the SLA time window.
- Follow-up and tracking security incidents base on team process.
- Examine network topologies to understand data flows through the network.
- Validate security incidents alerts against network traffic using packet analysis tools.
- Isolate or remove malware.
- Identify applications and operating systems of a network device based on network traffic.
- Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave.
- Notify cybersecurity service provider team members of suspected cyber incidents, status, and potential impact for further action in accordance with the organization's cyber incident response plan.
- Work with stakeholders to resolve computer security incidents and vulnerability compliance.
- Who are we looking for?.
- Knowledge of computer networking concepts and protocols, and network security methodologies.
- Analytical and problem-solving skills are required.
- Knowledge of network traffic analysis methods.
- Knowledge of cyber defense and information security policies, procedures, and regulations.
- Experience in IT Security, Network Security or Security Compliance.
- Knowledge of common security tools such as anti-virus, firewall and intrusion detection system.
- Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
- Able to work in shift.
Skills:
Project Management, Risk Management, Security Design, Multitasking, Recruitment
Job type:
Full-time
Salary:
negotiable
- Manage and Control IT Security of company's Infrastructure such as Firewalls, Cloud-based hosting, Internet policies and etc.
- Perform IT security assessments, monitor and analyze cyber security event.
- Work on IT security design and analysis, and business continuity management.
- Evaluate and analyze threat, vulnerability, impact and risk to security issues discovered from security assessments.
- Advise company on the security issues, including explanation on the technical details and how they can remediate the vulnerabilities in the processes and controls.
- Assist company's internal developers and the development team in patching any security vulnerabilities.
- Implement security guidelines for all company's collaboration with the team.
- Operationalize Cyber Security Risk Management capabilities such as Business Impact Assessment of the Business unit's digital portfolio of services and applications to identify Crown jewels to be protected in line with Risk appetite.
- Deployment of relevant cybersecurity controls, including required local regulatory compliance, to ensure digital solutions, both applications and services, are developed with a secure-by-design principle.
- Drives Cyber Risk acceptance, risk mitigation, finding management processes, and risk reporting consistently to ensure Cyber Risks are managed and residual risks understood by the leadership.
- Champion Cyber Security Change program activities to drive awareness, behaviors among the business unit, and increase the Cyber Resilience.
- Drive implementation and integration/adoption of security capabilities and change management to ensure business alignment and effectiveness.
- Business-level security KPIs/KRIs (e.g., patch compliance, phishing click rates, third-party risk ratings) dashboards, reports to management level.
- Bachelor's degree in Computer Engineering or related field.
- Minimum 8-10 years of IT Security Management and Project Management in complex projects in banking, fintech, insurance business.
- Good knowledge and understanding in IT and/or Cybersecurity related laws and regulations such as IT Risk Management Implementation, Cyber, Computer Crime Act, Personal Data Protection Act (PDPA), etc.
- Relevant industry certifications are an advantage (e.g., ISO 27001, CISA, CISSP, CGEIT, etc.).
- Working knowledge of local information and cybersecurity-related regulations and requirements is a MUST.
- Ability to develop, review, and maintain documentation on time.
- Excellent English communication and interpersonal skills, with a proven ability to resolve conflicts and build strong, lasting rapport with diverse stakeholders.
- Proven ability in building partnerships across local, regional, and cross-functional teams to align security goals with business objectives.
- A detail-oriented self-starter with strong analytical skills and a result-oriented mindset, capable of multitasking and adapting quickly to shifting priorities in a fast-paced environment.
- Location: Sermmit Tower (Work from office).
Skills:
Cloud Computing, Amazon AWS
Job type:
Full-time
Salary:
฿45,000 - ฿60,000, negotiable
- Endpoint Security Management Direct the deployment and optimization of the security stack across the Mac and Windows fleet. Manage MDM baselines, EDR configuration, and the triage of escalations from managed detection services.
- Cloud Security Operations Maintain least-privilege IAM principles across AWS and GCP environments. Implement SSO, hardware-based MFA, and manage service account hygiene, secrets, and cloud governance guardrails.
- Detection Engineering Centralize telemetry from cloud audit logs, endpoints, and net ...
- Incident Response Serve as the primary responder for security incidents. Conduct investigations, execute containment strategies, and produce comprehensive post-incident reviews while maintaining updated runbooks.
- ISMS Operations Operationalize ISO 27001 controls through automation. Facilitate evidence collection, conduct periodic access reviews, and manage corrective actions to support internal and external audits.
- Security SDLC Integration Collaborate with engineering teams to integrate security into the development lifecycle. Implement secret scanning, dependency analysis, and conduct security reviews for high-risk architectural changes.
- Security Culture & Advocacy Lead security awareness initiatives and phishing simulations. Act as a subject matter expert and accessible resource for security-related inquiries across the organization.
- 3+ years hands-on security or DevOps/infrastructure experience with meaningful security ownership title matters less than what you've operated.
- Working proficiency with at least one major cloud (AWS or GCP): IAM, audit logging, and security tooling (GuardDuty, Security Command Center, or equivalents).
- Experience deploying or administering endpoint management/EDR tooling across a fleet (any of: Intune, Jamf, Kandji, CrowdStrike, SentinelOne, Defender).
- Scripting ability for automation (Python, Bash, or PowerShell) enough to glue systems together and automate evidence collection.
- You can investigate an incident: read logs, build a timeline, distinguish evidence from assumption, and write it up clearly.
- Thai and English working proficiency.
- ISO 27001 exposure from the inside you've lived through an audit, owned controls, or closed nonconformities.
- PDPA familiarity, or GDPR experience that translates.
- Experience at a SaaS or fintech company.
- Infrastructure-as-code experience (Terraform) for codifying security baselines.
- Certifications like AWS Security Specialty, ISO 27001 LA/LI, GIAC, or CISSP valued, never required.
- Competitive salary and benefits package.
- Relocation support and flexible work hours.
- 45 days a year work from anywhere policy.
- Collaborative and friendly work environment.
- Comprehensive training and mentorship program to help you grow your skills and advance your career.
- Opportunities to work on cutting-edge technologies and have an impact on the future of the industry.
- Opportunity for professional growth in a dynamic environment.
- BKK BangRak Office (MRT Samyan or BTS Saladaeng).
- 1
- 2
- 3
- 4
- 5
- 6
- 54
