- No elements found. Consider changing the search query.
ทักษะ:
Compliance, ISO 27001
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Lead shift operations, ensuring proper execution of inspections, monitoring, and preventive maintenance.
- Supervise and guide technicians/engineers; conduct shift handovers and maintain accurate reports and logs.
- Monitor and control critical systems (electrical, mechanical, and fire safety) to ensure stable operations.
- Monitor and control electrical systems (UPS, PDUs, switchgear), mechanical systems (CRAC/CRAH, chillers), and fire safety systems.
- Respond to alarms, incidents, or system faults per SOPs/EOPs, performing initial containment and escalation.
- Coordinate maintenance work, vendor activities, and ensure compliance with safety and work permit standards.
- Support clients and internal teams with access, troubleshooting, and on-site assistance.
- Maintain adherence to safety, security, and operational standards (ISO 27001, TIA-942, Uptime Tier).
- Job Qualifications.
- Bachelor s degree in Electrical, Mechanical, or related Engineering fields.
- Minimum 5 years of experience in data center, critical facility, or industrial plant operations.
- Strong understanding of electrical and HVAC systems, UPS, generators, BMS, and fire systems.
- Experience working in 24x7 rotating shifts.
- Fluent in English both written and verbal (Minimum 600 TOEIC score).
- Goal-Oriented, Unity, Learning, Flexible.
- Preferred Qualifications.
- Data center certifications such as CDCP, CDCS, or equivalent are a plus.
- Experience working in Tier III or Tier IV environments.
- Familiarity with ISO 27001, TIA-942, and safety protocols (e.g., Lockout-Tagout, EHS standards).
- Able to work independently and lead small teams during high-pressure situations.
ทักษะ:
Compliance, ISO 27001
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Lead shift operations, ensuring proper execution of inspections, monitoring, and preventive maintenance.
- Supervise and guide technicians/engineers; conduct shift handovers and maintain accurate reports and logs.
- Monitor and control critical systems (electrical, mechanical, and fire safety) to ensure stable operations.
- Monitor and control electrical systems (UPS, PDUs, switchgear), mechanical systems (CRAC/CRAH, chillers), and fire safety systems.
- Respond to alarms, incidents, or system faults per SOPs/EOPs, performing initial containment and escalation.
- Coordinate maintenance work, vendor activities, and ensure compliance with safety and work permit standards.
- Support clients and internal teams with access, troubleshooting, and on-site assistance.
- Maintain adherence to safety, security, and operational standards (ISO 27001, TIA-942, Uptime Tier).
- Job Qualifications.
- Bachelor s degree in Electrical, Mechanical, or related Engineering fields.
- Minimum 5 years of experience in data center, critical facility, or industrial plant operations.
- Strong understanding of electrical and HVAC systems, UPS, generators, BMS, and fire systems.
- Experience working in 24x7 rotating shifts.
- Fluent in English both written and verbal (Minimum 600 TOEIC score).
- Goal-Oriented, Unity, Learning, Flexible.
- Preferred Qualifications.
- Data center certifications such as CDCP, CDCS, or equivalent are a plus.
- Experience working in Tier III or Tier IV environments.
- Familiarity with ISO 27001, TIA-942, and safety protocols (e.g., Lockout-Tagout, EHS standards).
- Able to work independently and lead small teams during high-pressure situations.
ทักษะ:
Automation, Compliance, ISO 27001
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Design, implement, and maintain enterprise IAM solutions supporting identity lifecycle, authentication, and authorization.
- Manage user onboarding, access provisioning, and deprovisioning workflows integrated with ITSM and ITAM platforms.
- Develop and enforce access policies, governance standards, and automation processes for managing users and assets.
- Integrate IAM systems with core productivity, communication, and collaboration platforms.
- Implement and monitor privileged access controls to safeguard critical systems and infrastructure.
- Oversee secure remote access and connectivity across networks and cloud environments.
- Collaborate with IT, Security, and Operations teams to align IAM practices with ITSM change, incident, and request processes.
- Maintain accurate asset and account inventories through ITAM integrations to ensure compliance and visibility.
- Troubleshoot identity-related incidents and support audits, reviews, and internal controls.
- 3-5 years of experience in identity and access management engineering or IT administration.
- Strong understanding of IAM concepts: SSO, OIDC, SCIM,MFA, RBAC, lifecycle automation, and access governance.
- Experience integrating IAM with ITSM and ITAM systems for end-to-end user and asset lifecycle management.
- Hybrid Identity & Access Management, Managed AD and Google Workspace.
- Familiarity with privileged access controls, VPNs, and secure network access solutions.
- Knowledge of IT operations and service delivery processes (incident, change, and request management).
- Scripting or automation experience to streamline access and provisioning workflows.
- Strong documentation, communication, and cross-team collaboration skills.
- Nice to Have.
- Experience in fintech, blockchain, or crypto environments.
- Exposure to zero trust and identity governance models.
- Understanding of compliance and security frameworks (SOC 2, ISO 27001, NIST).
- Knowledge of basic network and infrastructure.
ประสบการณ์:
2 ปีขึ้นไป
ทักษะ:
Network Infrastructure, Problem Solving, ISO 27001, English
ประเภทงาน:
งานประจำ
เงินเดือน:
฿25,000 - ฿35,000
- Manage, configure, and troubleshoot enterprise network infrastructure, including switches, routers, and wireless networks.
- Administer firewalls (e.g., Fortinet, Palo Alto, Cisco FirePower) and implement security policies, VPNs, and threat prevention strategies.
- Administer Proxy (ForcePoint) and implement security policies,URL filtering.
- Monitor and optimize network performance, availability, and security using SIEM and monitoring tools.
- Server & Infrastructure Administration.
- Deploy, maintain, and secure Windows/Linux servers, virtualization (VMware/Hyper-V), and storage solutions.
- Manage Active Directory, DNS, DHCP, and other core IT services.
- Perform system backups, disaster recovery planning, and business continuity testing.
- IT Security & Compliance.
- Ensure IT infrastructure complies with ISO 27001 and other relevant security standards.
- Conduct risk assessments, vulnerability management, and security audits.
- Implement and enforce security best practices, access controls, and incident response plans.
- Project & Team Management.
- Assist in IT project planning, execution, and documentation.
- Collaborate with internal teams and vendors to support IT initiatives.
- Provide guidance, training, and support to IT staff and end-users.
- Any other duties and responsibilities that may be assigned to you by the management from time to time, within your category of employment in the organization and for the effective implementation, maintenance and continual improvement of the Quality Management System.
- Bachelor s degree in Computer Science, IT, or a related field.
- 2+ years of experience in IT infrastructure, networking, and security.
- Strong knowledge of firewall management, network protocols, and server administration.
- Experience with ISO 27001 compliance, IT security frameworks, and best practices.
- Hands-on experience with Cisco, Fortinet, Palo Alto, Windows/Linux servers, VMware/Hyper-V.
- Certifications such as CCNA, CCNP, Fortinet NSE, Microsoft Azure, CISSP, CISM, or ISO 27001 Lead Implementer are a plus.
- Excellent problem-solving, analytical.
- Excellent communication skills in both written and spoken English.
- Director and the team..
ทักษะ:
ISO 27001, Negotiation
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Extensive understanding of security principles, concepts, and technologies, including knowledge of NIST CSF, ISO 27001, and cybersecurity solutions.
- A proven track record in achieving and exceeding sales and financial goals.
- Skill in delivering engaging sales presentations and elevator pitches.
- Meticulousness in maintaining up-to-date, accurate sales forecasts and close plans.
- Experience in a team-selling approach and knowledge of competitors and competing sales strategies.
- Strong negotiation skills to craft solutions beneficial to customers, partners, and our organization.
- The ability to develop and maintain meaningful customer relationships up to the C-level.
- A client-centric mindset with the capability to understand customer problems and find best-fit solutions.
- Flexibility and adaptability to meet urgent deadlines and short missions.
- A bachelor's degree or equivalent in a technical or sales field or related area.
- Industry/Vendor sales certifications required.
- On-site Working About NTT DATA
- NTT DATA is a $30+ billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long-term success. We invest over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure, and connectivity. We are also one of the leading providers of digital and AI infrastructure in the world. NTT DATA is part of NTT Group and headquartered in Tokyo.
- Equal Opportunity Employer
- NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
ทักษะ:
Compliance, Project Management, ISO 27001
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Assists in conducting risk assessments and vulnerability assessments.
- Contributes to the development and maintenance of security policies and procedures.
- Collaborates with internal stakeholders to ensure compliance with industry standards and regulations.
- Participates in security awareness and training initiatives.
- Supports incident response activities and investigations as required.
- Monitors and reports on security compliance metrics.
- Assists in the implementation of security controls and best practices.
- Stays updated with emerging security threats and trends.
- Performs any other related task as required.
- To thrive in this role, you need to have: Seasoned familiarity with information security frameworks and standards.
- Seasoned understanding of risk assessment methodologies, compliance, and policy development.
- Strong communication and interpersonal skills for effective collaboration.
- Strong attention to detail and ability to follow established processes.
- Seasoned project management skills for coordinating security initiatives.
- Academic qualifications and certifications: Bachelor s degree or equivalent in Information Technology or Computer Science degree or related field.
- Security certifications such as CISA, CRISC, COBIT, IIA or equivalent preferred.
- Certifications such as Lead audit/Implementer - ISO 27001, SOC TSP desirable.
- Required experience: Seasoned experience in information security or related roles.
- Seasoned exposure to risk assessment, compliance, security awareness, or policy development is beneficial.
- On-site Working About NTT DATA
- NTT DATA is a $30+ billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long-term success. We invest over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure, and connectivity. We are also one of the leading providers of digital and AI infrastructure in the world. NTT DATA is part of NTT Group and headquartered in Tokyo.
- Equal Opportunity Employer
- NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
ทักษะ:
ISO 27001
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Comprehensive knowledge of security domains such as network security, application security, cloud security, DATA protection, identity and access management, cryptography, and secure coding practices.
- Extensive understanding of vendor products, business, and technology positioning.
- Proficiency in enterprise architecture principles and frameworks (e.g., TOGAF).
- Understanding of security regulations, standards, and frameworks (e.g., ISO 27001, NIST, PCI dSS) and their practical application.
- Previous experience as a Security Technical Architect or similar role, with hands-on experience in security technologies and tools.
- Excellent analytical and problem-solving skills, capable of assessing risks and analysing complex security issues.
- Good client engagement skills with a technical consulting mindset.
- Collaborative and effective communication skills within a team environment.
- Bachelor s degree in information technology, Computer Science, Information Systems, or a related field.
- On-site Working About NTT DATA
- NTT DATA is a $30+ billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long-term success. We invest over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure, and connectivity. We are also one of the leading providers of digital and AI infrastructure in the world. NTT DATA is part of NTT Group and headquartered in Tokyo.
- Equal Opportunity Employer
- NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
ทักษะ:
ISO 27001, Python, PowerShell
ประเภทงาน:
งานประจำ
เงินเดือน:
฿60,000 - ฿80,000, สามารถต่อรองได้
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 5 years of experience in IT security and governance.
- Strong understanding of IT security principles, practices, and technologies.
- Knowledge of relevant security standards and regulations (e.g., ISO 27001, NIST, GDPR, HIPAA, PCI DSS).
- Experience with risk assessment and vulnerability management.
- Experience with security incident response and management.
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team..
- Relevant certifications (e.g., CISSP, CISM, CISA, Security+).
- Experience with cloud security (AWS, Azure, GCP) and On-Premises.
- Experience with security information and event management (SIEM) systems.
- Experience with scripting languages (e.g., Python, PowerShell).
- Experience with penetration testing.
- Ability to maintain confidentiality and handle sensitive information.
- Ability to adapt to changing technologies and security threats.
- Strong attention to detail and organizational skills.
- Ability to create and maintain clear and concise documentation..
- โบนัสประจำปี.
- ลาพักร้อน เมื่อพ้นทดลองงาน.
- ลา Workcation.
- กองทุนสำรองเลี้ยงชีพ.
- ประกันสังคม / ประกันสุขภาพ / ประกันชีวิต / ประกันอุบัติเหตุ.
- วันหยุดตามกฏหมาย (ไม่น้อยกว่า 13วัน).
- ลาหยุดในเดือนเกิด.
- ตรวจสุขภาพประจำปี.
- เงินช่วยเหลือสมรส.
- สิทธิคุณพ่อลาเลี้ยงบุตร.
- เงินช่วยเหลือฌาปนกิจ.
- Co working Space.
- ฟิตเนต.
- Point แลกของรางวัล.
- บริการปรึกษานักจิตวิทยาออนไลน์..
- การเดินทาง.
- BTS: สถานีหมอชิต, ห้าแยกลาดพร้าว.
- MRT: สถานีพหลโยธิน.
- บริการเรียกรถผ่าน App MuvMi..
- ติดตามข่าวสารจาก SC ASSET ได้ที่.
- http://insidesc.scasset.com/..
ทักษะ:
ISO 27001, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- รับผิดชอบการ Monitoring ควบคุมและจัดการระบบพื้นฐานเกี่ยวกับ ไฟฟ้า และระบบปรับอากาศ ระบบเครือข่าย เพื่อสนับสนุนการจัดการ.
- ตอบสนองความต้องการของลูกค้า และประสานงาน การติดตั้งและการแก้ไขปัญหาระบบของผู้บริการ (vendor) เพื่อให้ถูกต้องและสมบูรณ์ตามหลักปฎิบัติ.
- ควบคุมและประสานงานการบำรุงรักษาและการซ่อมแซม (Preventive Maintenance) ระบบพื้นฐานต่างๆ เครื่องกำเนิดไฟฟ้า Generator, เครื่องสำรองไฟฟ้า UPS, ระบบตู้ไฟฟ้า, ระบบปรับอากาศ และการติดตั้งอุปกรณ์ระบบเครือข่าย (Network) เป็นต้น.
- เป็น 1st level support & troubleshooting ของระบบ Facility ใน Data Center เช่น ระบบ Network, ระบบไฟฟ้า, ระบบปรับอากาศ เป็นต้น.
- จัดทำกระบวนการปฎิบัติงาน และคู่มือการทำงานในการดูแลระบบพื้นฐาน โดยอิงตามมาตราฐาน ISO หรือมาตรฐานอื่นที่เกี่ยวข้องกับการปฏิบัติงาน (เช่น ISO 20000 ด้านบริการ, ISO 27001 ด้านความปลอดภัย,ISO 50001 ด้านบริหารพลังงาน และอื่นๆ เช่น ISO22301, PCIDSS, TCOS) รวมทั้งรูปแบบใบบันทึก, รายงานต่าง ๆ.
- สรุปและรายงานผลสำหรับปัญหาวิกฤติใด ๆ ต่อหัวหน้าทีม รวมทั้ง การจัดทำรายงานสถิติ,รายงานวิเคราะห์แบบรายวัน, รายเดือน รายไตรมาส ด้วย.
- Bachelor s degree in electrical power, mechanic or related fields.
- Thai nationality, Male, Age 20 - 25 years old.
- Have basic technical knowledge in Data Center facilities (Electrical/Mechanical).
- Able to work under pressure.
- Able to work with a team.
- Fair communication in English.
ทักษะ:
Risk Management, ISO 27001, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Oversee the technology risk management practices of banking and digital asset subsidiaries to ensure they align with the parent company s standards and regulatory requirements.
- Establish a robust governance framework to monitor and control technology risks across all subsidiaries.
- Ensure regular and detailed reporting of technology risk management performance, including key metrics and risk indicators, to senior management and the board of direct ...
- Oversee the reporting of any technology-related incidents or anomalies, ensuring timely communication and resolution.
- Communicate and enforce technology risk management policies and standards across all subsidiaries, ensuring that all relevant stakeholders are aware of and adhere to these guidelines.
- Provide expert advice and support to subsidiaries on technology risk management issues, helping them to implement best practices and mitigate risks effectively.
- If you meet below qualifications and are ready to take on a challenging role, we encourage you to apply..
- Bachelor s degree or higher in Information Technology, Cybersecurity, Risk Management, or a related field.
- Relevant work experience at least 5 years of experience in technology risk management..
- Proficiency in identifying, evaluating, and mitigating technology risks.
- Knowledge of regulatory requirements and best practices in IT governance.
- Familiarity with risk management frameworks and tools, such as NIST, ISO 27001, and COBIT.
- Ability to effectively communicate risk-related information to stakeholders at all levels both Thai and English.
- Commitment to staying updated with the latest trends and developments in technology risk management.
ประสบการณ์:
2 ปีขึ้นไป
ทักษะ:
Public Relations, Legal, ISO 27001, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Executes cybersecurity engineer tasks including, but not limited to, security patch management, security vulnerability management, and security configuration management.
- Tests, implements, deploys, maintains, reviews, and administers the cybersecurity tools.
- Assist in identifying, prioritizing, and coordinating the protection of critical cyber defense infrastructure and key resources.
- Coordinate with Cyber Defense Analysts to manage and administer the updating of rules and signatures (e.g., intrusion detection/protection systems, antivirus, and content blacklists) for specialized cyber defense applications.
- Identify potential conflicts with the implementation of any cyber defense tools (e.g., tool and signature testing and optimization).
- Operates and maintains production information security systems.
- Ensures proper cybersecurity documentation is in place regarding standard operating procedures.
- Monitors the industry and external environment for emerging threats and advises relevant stakeholders on appropriate courses of action.
- Oversees incident response planning and the investigation of security breaches and assists with any associated disciplinary, public relations, and legal matters.
- Applies expert knowledge and skills to resolve problems, including support concepts and methods, problem isolation and troubleshooting procedures, system and file recovery processes, and operating system and network configurations.
- Prepares and presents cogent and cohesive analyses and briefings advising management on new technological developments, techniques, and enhancements that result in increased time and cost efficiencies.
- Provides advice and assistance to troubleshoot the most complex problems in a manner that minimizes interruptions in the ability to carry out critical business activities.
- Supports rapid response teams in response to customer service problems resulting from catastrophic events such as virus infections or widespread power outages.
- Supports the development of a formal cyber security risk assessment program.
- Supports and assists in maintaining a vulnerability/gap/response assessment program.
- Supports the ongoing maintenance of the cyber-Kill Chain for the company, focusing on phases of cyber-attack and remediation/mitigation for each phase.
- Supports ongoing activities to develop, communicate, and support appropriate standards and risk controls associated with digital data.
- Supports the development and maintenance of a company Data Protection program.
- Responds to cybersecurity alerts.
- Cascade and leverage cybersecurity control and practice to the entire company group.
- Bachelor s or Master s degree in Computer Engineering, MIS, IT, or a related field.
- At least 2 years experience in computer security and 5 years in IT infrastructure.
- Have a foundation in good information security practices.
- Knowledge of International Security frameworks, Standards, and Guidelines, e.g., COBIT, NIST-800, ISO 27001, PCI-DSS, OWASP, etc.
- Experience in Security tools, e.g., EDR, ATP, WAF, IPS/IDS, Deception, TI/TIP, Anti DDoS.
- Experience in Cloud Environments, e.g., Google Cloud, AWS, Microsoft Azure.
- Experience with system and application security management and control.
- Experience with system, network, and OS hardening techniques. (e.g., remove unnecessary services, password policies, network segmentation, enable logging, least privilege, etc.).
- Experience with facilitating information security risk assessments.
- Technical writing, documentation development, process mapping, and visual communication skills.
- Hands-on experience with computer programming languages and/or scripting languages such as Python, Java, and Shell for automation.
- Professional certificates related to work (e.g., CISSP, CISM, AWS Certified Security, or similar general security certification) are desirable.
- Talent to identify and create a broad vision for a security solution and to execute it;.
- Systems Thinking - the ability to see how parts interact with the whole (big picture thinking).
- Proven experience of acting as an expert in project teams.
- A positive, can-do attitude who naturally expresses a high degree of empathy to others.
- Ability to explain your thoughts or findings also to non-technical professionals.
- Strong problem-solving and analytical abilities Able to work under minimal supervision, detail oriented.
- Excellent English (Spoken and Written).
- Location: True Digital Park, Punnawithi.
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
Risk Management, ISO 27001, Project Management
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Develop and implement IT governance frameworks, policies, and procedures that align with industry best practices, regulatory requirements, the company and technology team objectives.
- Design and implement controls and mitigation strategies to address identified risks and ensure compliance with relevant regulations and industry standards.
- Collaborate with key stakeholders to identify and document IT governance goals, objectives, and key performance indicators (KPIs) that align with the company and techno ...
- Collaborate with IT and business stakeholders to balance business agility and IT risk.
- Coordinate and participate in audits and assessments to evaluate the effectiveness of IT governance controls and ensure compliance with internal policies and external regulations.
- Monitor and report on the effectiveness of IT governance controls, identify areas for improvement, and recommend appropriate remediation actions.
- Regularly review existing policies and procedures to identify gaps and areas of improvement.
- Maintain a thorough understanding of emerging trends, technologies, and regulatory changes that could impact the company s IT operations and governance.
- Bachelor s degree in Computer Science/Engineering, Information Systems, or IT related field.
- At least 5 years of work experience and 2 years in IT governance, risk management, or IT audit.
- Strong knowledge of IT governance standards and frameworks such as COBIT, ITIL, ISO 27001, etc.
- Solid understanding of cyber security principles and data privacy regulations.
- Exceptional communication skills with the ability to present complex IT concepts to non-technical stakeholders.
- Analytical mindset with strong problem-solving skills and attention to detail.
- Proven project management and leadership skills.
- Familiarity with cloud technologies and their governance requirements.
- Experience in a startup or tech-oriented environment.
- If you are passionate about IT governance and want to make a significant impact in a dynamic startup environment, we would love to hear from you!.
ประสบการณ์:
3 ปีขึ้นไป
ทักษะ:
Compliance, ISO 27001
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
มีการฝึกอบรมให้ก่อนการเริ่มงาน โดยไม่มีค่าใช้จ่ายแต่อย่างใด.
ทักษะ:
Risk Management, Kubernetes, Docker
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Design, develop, and maintain security systems, tools, and best practices across the stack (frontend, backend, mobile, and infrastructure).
- Identify, assess, and mitigate security vulnerabilities through proactive risk management and threat modeling.
- Collaborate with product managers and developers to embed security into the software development lifecycle (SDLC).
- Develop and enforce policies for secure coding, data protection, and incident response.
- Implement robust authentication and authorization mechanisms.
- Conduct regular security assessments, including penetration testing and code reviews.
- Monitor, detect, and respond to security incidents using advanced tools and methodologies.
- Enhance infrastructure security using Kubernetes, Docker, and cloud platforms (GCP, AWS).
- Stay current on emerging threats, vulnerabilities, and security trends, and recommend actionable insights to improve defenses.
- Champion security awareness across the organization, including training sessions and knowledge-sharing activities.
- Ensure compliance with relevant security standards and regulations such as ISO 27001, PDPA, GDPR, SOC 2, or PCI DSS.
- Basic QualificationsProven expertise in application security, cloud security, and infrastructure security.
- Proficiency in securing systems built with technologies such as Node.js, Golang, Elixir, Python, React, Svelte, or Flutter.
- Experience with tools like Docker, Kubernetes, and cloud services (GCP, AWS).
- Strong understanding of cryptographic principles and secure communication protocols.
- Familiarity with CI/CD pipelines and secure DevOps practices.
- Hands-on experience with security tools for vulnerability scanning, penetration testing, and threat detection.
- Deep understanding of database security, especially with PostgreSQL or other relational or non-relational databases.
- Strong analytical and problem-solving skills with a security-first mindset.
- Excellent communication skills and the ability to collaborate effectively in Agile teams.
- Self-motivation, adaptability, and a strong work ethic.
- Preferred Qualifications We re especially excited if you bring:Experience leading security initiatives or mentoring other engineers in security best practices.
- Expertise in compliance frameworks such as ISO 27001, PDPA, GDPR, SOC 2, or PCI DSS.
- Advanced knowledge of security monitoring and incident response systems.
- Strong system design skills with a focus on secure architectures and long-term trade-offs.
- A proven track record of securing fast-paced, high-growth tech environments.
- A passion for securing user-centric products and contributing to their success.
- Perks & Benefits Flat Structure As we continue to grow fast, we strive to retain our culture where everyone is heard, contributes, and grows with the company..
- Work-life Harmony We believe that quality time outside of work is important to sustaining a healthy and happy lifestyle.
- Remote Work Hybrid-mode activated! It comes with the package: flexibility, focus and productivity!.
- Urban Office One breath from Phrom Phong BTS. No sweat whatsoever! The office should also feel like a second home so we dedicated a lot of care and resources into building the best environment for you to wake up to every morning.
- Fun Workshop The best relationships are built over new experiences, that s why we have workshops filled with a range of activities for you to look forward to and enjoy.
- Game Tournament It s getting fun and competitive! Challenge doesn t only have to come from work. Own the championship and show the peeps how great of a gamer (and player) you are.
- Group Insurance Health comes first, we know, don t worry, we ve got you covered.
- Health & Wellness Only a healthy army wins the war. We invest to take care of you from physical, mental and happiness-level. Adopted health & wellness applications plus activities to make sure everyone here is on cloud nine
ประสบการณ์:
3 ปีขึ้นไป
ทักษะ:
System Security
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Participate in gathering and analyzing business and technical requirements to develop enterprise-wide Identity and Access Management (IAM) processes and procedures.
- Demonstrate a solid understanding of risk and change management, security policies and controls, user account lifecycle management, onboarding/offboarding, role-based access control (RBAC), access governance, and directory services.
- Translate business requirements into specific system, application, or process designs.
- Collaborate with cross-functional teams, including business units and technical stakeholders, to identify and define functional requirements, and contribute to or lead the design of IAM solutions.
- Engage in a broad range of IAM design activities from requirements analysis to implementation.
- Apply your knowledge of various IAM products and domains, with the ability to quickly adapt to new tools and technologies through self-learning or formal training.
- Provide support for identity provisioning, governance platforms, and privileged access management (PAM) tools.
- Lead and contribute to IAM-related projects to ensure successful delivery of objectives.
- Identify and communicate high-level functional gaps, risks, and potential issues, and propose effective solutions.
- Monitor service delivery against SLAs and escalate exceptions as needed.
- Perform IAM-related risk assessments and consult on project implementations to ensure alignment with RBAC frameworks and internal security policies.
- Drive improvements in RBAC processes, governance policies, and IAM lifecycle workflows.
- Lead or contribute to incident and problem management efforts, ensuring root cause analysis and future incident mitigation.
- Participate in on-call production support rotations and work with vendors to resolve technical issues.
- Influence the IAM strategy by making informed decisions on complex technical challenges.
- Support internal and external audit readiness by preparing and organizing required audit documentation.
- Design and implement key management controls to ensure encryption key security throughout the lifecycle.
- Conduct physical access control reviews and physical security assessments for restricted areas.
- Promote and extend secure access control practices across the organization and its affiliates.
- Essential Skills & PrerequisitesA positive, proactive mindset with strong empathy and team collaboration skills.
- Bachelor s or Master s degree in Computer Engineering, Information Security, MIS, or a related field.
- Minimum of 3 years of experience in cybersecurity or IAM domains.
- Solid foundation in information security principles and best practices.
- Knowledge of international security frameworks and standards, such as COBIT, NIST 800 series, ISO/IEC 27001, PCI-DSS, and OWASP.
- Familiarity with end-to-end security architecture including network, platform, and application layers.
- Experience with application/system security controls, IAM risk assessments, and access governance.
- Strong skills in technical writing, documentation, process mapping, and visual communication.
- Ability to develop and execute a clear vision for IAM and security solutions.
- Why Ascend Money?Contribute to a safer digital world.
- Gain hands-on experience with cutting-edge cybersecurity challenges.
- Grow your career in a dynamic, fast-moving environment.
- Don t miss this opportunity to be part of something big! Apply now and take the next step with Ascend Money.
- Apply Now: CLICK
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Support regular group assessments to evaluate security risks, security maturity and compliance gaps across SCBX Group.
- Policy, Procedures, Standards & Guidelines.
- Support the development, review, and update of security policies, procedures, standards, and guidelines to ensure robust organizational controls.
- Regularly update documentation to reflect the evolving threat landscape and regulatory requirements.
- Security Consultation.
- Lead conversation with senior leadership across SCBX Group and provide value-added insights to delivered outcome.
- Develop a comprehensive proposal and project plan that secures buy-in from senior stakeholders, while establishing an effective delivery approach for the working group to ensure successful project delivery and valued outcomes.
- Embrace creative problem-solving and flexible approaches to navigate challenges, ensuring that critical outcomes are consistently achieved while effectively managing obstacles.
- Provide expert guidance and recommendations to internal and external stakeholders on the best security practices and solutions to address operational and compliance issues.
- Recommend improvements for security governance and operational resilience.
- Security Awareness & Training.
- Develop and manage security e-learning programs, newsletters, and knowledge-sharing initiatives to enhance employee awareness.
- Conduct phishing drills and security simulations to assess and improve employee resilience against cyber threats.
- Design specialized training for executives and high-risk users to enhance their understanding of emerging threats and security best practices.
- Implement interactive learning methods such as gamification, security awareness series, real-world security challenges to encourage participation, on-site engagements to reinforce security culture.
- Digital Identity.
- Assist in Identity Governance & Administration (IGA) by supporting policy enforcement, identity lifecycle management, and compliance monitoring.
- Support Access Management by integrating authentication mechanisms such as SSO, MFA, and adaptive access controls into enterprise systems.
- Contribute to Role Management, ensuring structured RBAC/ABAC models and periodic access reviews.
- Help implement Privileged Access Management (PAM) controls, monitoring privileged user sessions, and enforcing security best practices.
- Assist in Identity Integration & Directory Services, ensuring seamless identity synchronization and federation across cloud and on-prem systems.
- Security Innovation.
- Research and evaluate emerging cybersecurity technologies, AI-driven security analytics, and automation tools, conducting PoCs to assess feasibility.
- Explore AI-driven security solutions for threat detection - prevention, and automated security operation to enhance cybersecurity resilience.
- Provide strategic insights to align security innovations with digital transformation, FinTech, and cloud security initiatives across subsidiaries.
- Partner with internal teams, vendors, and industry leaders to benchmark security advancements and drive innovation initiatives..
- Minimum of 5+ years in information security consultancy, with a proven track record in security assessment, identity & access and data security.
- Experience in conduct IAM solutions, including IGA, identity assessment - planning, access management, PAM, and identity integration within enterprise environments.
- Demonstrates a deep understanding of global security frameworks, such as NIST, ISO 27001/27002, PCI-DSS, BOT and CIS Controls.
- Extensive experience in conducting large-scale security assessments, performance measurements, risk management, and security strategy development that align with organizational objectives.
- Relevant certifications such as from identity products or equivalent are highly desirable.
ทักษะ:
Continuous Integration, Legal, Procurement
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Support regular group assessments to evaluate security risks, security maturity and compliance gaps across SCBX Group.
- Policy, Procedures, Standards & Guidelines.
- Support the development, review, and update of security policies, procedures, standards, and guidelines to ensure robust organizational controls.
- Regularly update documentation to reflect the evolving threat landscape and regulatory requirements.
- Security Consultation.
- Lead conversation with senior leadership across SCBX Group and provide value-added insights to delivered outcome.
- Develop a comprehensive proposal and project plan that secures buy-in from senior stakeholders, while establishing an effective delivery approach for the working group to ensure successful project delivery and valued outcomes.
- Embrace creative problem-solving and flexible approaches to navigate challenges, ensuring that critical outcomes are consistently achieved while effectively managing obstacles.
- Provide expert guidance and recommendations to internal and external stakeholders on the best security practices and solutions to address operational and compliance issues.
- Recommend improvements for security governance and operational resilience.
- SDLC Security & DevSecOps Integration.
- Develop and implement security frameworks and best practices within the SDLC to minimize vulnerabilities.
- Collaborate with development, operations, and security teams to embed security controls and processes within continuous integration/continuous deployment (CI/CD) pipelines.
- Advise on the integration of automated security testing tools and manual assessments throughout development, staging, and production phases.
- Monitor and evaluate the effectiveness of security controls, adjusting strategies as required.
- Pentester Governance & Annual Panel Selection.
- Oversee and manage the overall pentesting program, including planning, scoping, and executing external and internal penetration tests.
- Develop and enforce governance policies for third-party penetration testing, ensuring compliance with internal and industry standards.
- Lead the annual selection process of the pentester panel by evaluating vendor capabilities, reviewing performance metrics, and coordinating panel evaluations.
- Collaborate with legal, procurement, and compliance teams to negotiate contracts and service level agreements (SLAs) with selected vendors.
- Application Security Testing.
- Define and maintain comprehensive application security testing strategies, including static and dynamic code analysis, vulnerability assessments, and risk management.
- Coordinate regular security assessments, penetration tests, and vulnerability remediation efforts.
- Analyze findings from testing activities and provide actionable recommendations to mitigate risks.
- Work with development teams to ensure security testing is integrated into agile and DevOps methodologies.
- Identity Architecture & Strategy.
- Define and implement enterprise-wide identity governance frameworks, access models, and role designs.
- Develop future-ready IAM architectures to support Zero Trust security, cloud adoption, and business scalability.
- Design identity lifecycle processes such as automated provisioning, de-provisioning, RBAC, and approval workflows.
- Align IAM practices with global standards (NIST, ISO 27001, CIS) and regulatory mandates (PCI-DSS, GDPR, BOT).
- Establish and maintain a comprehensive security governance framework with clear roles, responsibilities, and performance metrics.
- IAM Solution Delivery & Operations.
- Lead the design, deployment, and integration of solutions including SSO, MFA, PAM, and CIAM.
- Oversee directory services and federation platforms such as Active Directory, Azure AD, and cloud identity providers.
- Collaborate with implementation teams and vendors to configure and deploy IAM technologies that ensure security, scalability, and operational excellence.
- Minimum of 12+ years in information security consultancy, with a proven track record in Application security, DevSecOps integration, Vulnerability Management, Penetration testing and Digital Identity.
- Demonstrated expertise in developing and implementing security frameworks and policies that embed secure coding practices and automated security testing within complex, enterprise-level SDLC environments.
- Demonstrates a deep understanding of global security frameworks, including NIST, ISO 27001/27002, PCI-DSS, BOT and CIS Controls.
- Extensive experience in conducting large-scale security assessments, performance measurements, risk management, and security strategy development that align with organizational objectives.
- Relevant certifications such as CISSP, CISM, CRISC, OSCP, or equivalent are highly desirable.
ทักษะ:
Compliance, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Act as a liaison for internal, external, and regulatory auditors (e.g., Bank of Thailand, PCI, SEC, ISO27001).
- Support and monitor IT audit findings, issue tracking, and resolution progress.
- Assist in managing the IT General Controls (ITGC) framework and SOX compliance program.
- Contribute to IT Security control monitoring and risk assessment activities.
- Promote IT governance, compliance, and operational excellence across teams.
- Bachelor s or Master s degree in Information Technology, Computer Management, or related fields.
- 4 years of experience in IT within banking or financial services, including 2 years in IT audit or compliance roles..
- Knowledge of regulatory and security standards such as ISO 27001, NIST, COBIT, COSO, PCI DSS, ITIL, and SOX compliance..
- Strong analytical, communication, and problem-solving skills.
- Ability to manage multiple tasks, influence stakeholders, and work effectively under pressure.
- Good command of English.
- CISSP, CISA, CISM, CRISC, or ISO 27001 Lead Auditor/Implementer are advantageous..
- Only shortlisted candidates will be contacted.
- Talent Acquisition Department
- Bank of Ayudhya Public Company Limited
- 1222 Rama III Rd., Bangpongpang, Yannawa, Bangkok 10120
- FB: Krungsri Career.
- LINE: Krungsri Career.
- LINKEDIN: Krungsri.
- Applicants can read the Personal Data Protection Announcement of the Bank's Human Resources Function by typing the link from the image that stated below.
- EN: (https://krungsri.com/b/privacynoticeen).
- ผู้สมัครสามารถอ่านประกาศการคุ้มครองข้อมูลส่วนบุคคลส่วนงานทรัพยากรบุคคลของธนาคารได้โดยการพิมพ์ลิงค์จากรูปภาพที่ปรากฎด้านล่าง.
- ภาษาไทย: (https://krungsri.com/b/privacynoticeth).
- หมายเหตุ ธนาคารมีความจำเป็นและจะมีขั้นตอนการตรวจสอบข้อมูลส่วนบุคคลเกี่ยวกับประวัติอาชญากรรมของผู้สมัคร ก่อนที่ผู้สมัครจะได้รับการพิจารณาเข้าร่วมงานกับธนาคารกรุงศรีฯ.
- Remark: The bank needs to and will have a process for verifying personal information related to the criminal history of applicants before they are considered for employment with the bank..
- 1
