- No elements found. Consider changing the search query.
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
ISO 27001, Legal, Finance
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Design and implement a cybersecurity strategy that aligns with the organization's overall business objectives.
- Conduct regular security risk assessments, vulnerability assessments, and penetration testing to evaluate the organization s cyber defenses; subsequently, develop and implement security risk mitigation strategies and programs.
- Lead and coordinate response efforts in the event of security incidents, overseeing investigation, mitigation, and post-incident analysis.
- Compliance & Regulatory ManagementEnsure adherence to relevant laws, regulations, and standards (e.g., PDPA).
- Implement and lead initiatives for security and compliance audit certifications, including ISO 27001, NIST, the Cyber Resilience Assessment Framework (C-RAF), and other applicable standards and best practices.
- Recommend, implement, and manage continuous monitoring of IT security systems and tools.
- Collaborate with legal and data protection teams to establish policies and safeguards for sensitive and personal data.
- IT GovernanceEstablish and maintain an IT governance framework, policies, and processes that align with the organization s business goals while ensuring compliance with legal, regulatory, corporate, and industry requirements.
- Work in partnership with management, legal, finance, and external auditors to promote transparency and alignment in governance practices.
- Generate and present reports on IT governance performance, compliance status, and the risk landscape to stakeholders.
- Data GovernanceDevelop and implement data governance policies that ensure data quality, security, and compliance.
- Manage the data lifecycle, align data strategies with business objectives, and collaborate with cross-functional teams to enhance data integrity.
- Oversee data stewardship, regulatory compliance, and provide best practices for data management to support effective decision-making.
- Team Leadership and DevelopmentLead and mentor a small team of IT governance, compliance, and security professionals.
- Foster a culture of continuous improvement and knowledge sharing within the team and across business units.
- Requirements:Bachelor s or Master s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 5 years of experience in IT governance, cybersecurity, and compliance, with at least 2 years in a managerial role.
- Strong understanding of IT governance frameworks (e.g., ITIL, COBIT), cybersecurity standards (e.g., ISO 27001, NIST), and regulatory requirements (e.g., PDPA).
- Possession of basic IT governance and cybersecurity certifications (e.g., CISSP, CISM) is advantageous.
- Proficient in common technical team/project management tools (e.g., JIRA, Asana, Github). Collaborative team player with strong interpersonal skills, capable of working effectively with both internal and external teams.
- Working-level fluency in English and Thai. Proficient in English equivalent to IELTS 5.5, CEFR B2, or TOEFL 72; excellent spoken and written communication to effectively work with a global management team.
- Familiarity with local regulatory bodies (e.g., OIC, SEC, BOT) is a plus.
- Experience in the insurance industry will be an added advantage.
ประสบการณ์:
2 ปีขึ้นไป
ทักษะ:
Risk Management, Microsoft Office
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Serve as the main point of contact for gathering evidence, CCTV footage, and relevant information for assigned fraud cases.
- Coordinate with other relevant teams to prepare for interrogation sessions.
- Participate in the interrogation sessions of offenders,witnesses, and/or other relevant parties.
- Draft investigation reports.
- Act as a CCTV real-time monitor as requested or assigned by the supervisor.
- Participate in security-related projects and tasks as assigned.
- Requirements: Bachelor's degree in Laws, Political Science or related field. (Fresh Graduate is welcome.).
- Availability to work in the office 5 days a week and 1 day from home.
- Minimum of 0-2 years of experience in Fraud Investigation, Fraud Prevention, Loss Prevention, Government Affairs, Government Relations, or Risk Management-related positions.
- Experience in the logistics industry is a plus.
- Previous experience as a Police/Military Official or other government official is advantageous.
- Familiarity with reviewing CCTV footage.
- Skills in offender interrogation or interviewing.
- Strong analytical and problem-solving abilities.
- Excellent interpersonal skills.
- Proficient in GSuite or Microsoft Office.
- Must have a private vehicle and a valid driver's license.
- Availability to be on-call for emergency issues.
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
Problem Solving, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Design, implement and maintain the IT Security of the organization which involves developing and executing security strategies, standards and procedures to protect IT assets from cyber threats and vulnerabilities.
- Develops solution conceptual designs and solution blueprints for IT projects.
- Design security architecture elements to mitigate emerging threats.
- Reviewing security measures and recommending to implementing enhancements.
- Review and advise security solution architect for the proposed system such as: Network Segmentation, Application protection, Defense-in-depth, Remote Access, Encryption Technologies.
- Conducting security advisory consultancy and working with RED and BLUE team for security testing along the pipeline of the system delivery.
- Essential Skills & PrerequisitesBachelors or Masters Degree in Computer Engineering, Computer Science or related field.
- At least 5 years of experience of IT Security Advisory, Penetration tester or Enterprise Architect or related role.
- Comprehensive understanding of the IT Security Concept, Security Architect, Risk assessment.
- Ability to analyst finding form Offensive and Defensive Security team.
- Ability to analyze end-to-end security processes and provide advice in order to reduce risk to acceptable levels.
- Strong analytical and problem solving.
- Rapid learning capability and able to work under pressure.
- Good command in written and spoken Thai and English language.
- Ability to present technical solutions with stakeholders in an easy way.
- Knowledge of International Security frameworks, Standards, and Guidelines e.g., NIST-800-53, PCI-DSS, OWASP, and etc.
- Professional Certificated related to work e.g. (CISSP, CSSLP, CDPSE, OSCP, TOGAF) is desirable.
- Why Ascend Money?Contribute to a safer digital world.
- Gain hands-on experience with cutting-edge cybersecurity challenges.
- Grow your career in a dynamic, fast-moving environment.
- Don t miss this opportunity to be part of something big! Apply now and take the next step with Ascend Money.
- Apply Now: CLICK
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
Problem Solving, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Design, implement and maintain the IT Security of the organization which involves developing and executing security strategies, standards and procedures to protect IT assets from cyber threats and vulnerabilities.
- Develops solution conceptual designs and solution blueprints for IT projects.
- Design security architecture elements to mitigate emerging threats.
- Reviewing security measures and recommending to implementing enhancements.
- Review and advise security solution architect for the proposed system such as: Network Segmentation, Application protection, Defense-in-depth, Remote Access, Encryption Technologies.
- Conducting security advisory consultancy and working with RED and BLUE team for security testing along the pipeline of the system delivery.
- Bachelors or Masters Degree in Computer Engineering, Computer Science or related field.
- At least 5 years of experience of IT Security Advisory, Penetration tester or Enterprise Architect or related role.
- Comprehensive understanding of the IT Security Concept, Security Architect, Risk assessment.
- Ability to analyst finding form Offensive and Defensive Security team.
- Ability to analyze end-to-end security processes and provide advice in order to reduce risk to acceptable levels.
- Strong analytical and problem solving.
- Rapid learning capability and able to work under pressure.
- Good command in written and spoken Thai and English language.
- Ability to present technical solutions with stakeholders in an easy way.
- Knowledge of International Security frameworks, Standards, and Guidelines e.g., NIST-800-53, PCI-DSS, OWASP, and etc.
- Professional Certificated related to work e.g. (CISSP, CSSLP, CDPSE, OSCP, TOGAF) is desirable.
- Location: True Digital Park, Punnawithi.
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
Linux, Good Communication Skills, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Conduct advanced penetration tests to identify vulnerabilities in computer systems, networks, and applications.
- Perform vulnerability assessments and security audits to evaluate the effectiveness of existing security measures.
- Develop and execute simulated cyber attacks to assess the organization s readiness to defend against real-world threats.
- Employ various attack methodologies to test the resilience of systems against hacking attempts and security breaches.
- Perform threat modeling to anticipate potential attack vectors.
- Analyze risks associated with identified vulnerabilities and recommend appropriate mitigation strategies.
- Develop custom tools and scripts to automate penetration testing and exploit known vulnerabilities.
- Keep up-to-date with the latest exploitation techniques and security tools.
- Prepare detailed reports on findings from penetration tests and security assessments.
- Document and present risks and vulnerabilities to relevant stakeholders, along with recommended countermeasures.
- Collaborate with the Blue Team to enhance the organization s defensive strategies based on offensive findings.
- Share insights and knowledge on emerging threats and attack techniques with the cybersecurity team to continually improve defensive measures.
- Essential Skills & PrerequisitesBachelors or Masters Degree in Computer Engineering, Computer Science or related field.
- At least 5 years of experience in penetration testing and vulnerability assessments or related roles.
- Strong knowledge of network and application security, ethical hacking, and cybersecurity principles.
- Familiarity with penetration testing tools (e.g., Metasploit, Burp Suite, Kali Linux).
- Excellent problem-solving skills and ability to think like an adversary.
- Good communication skills for effective reporting and stakeholder engagement.
- Rapid learning capability and able to work under pressure.
- Good command in written and spoken Thai and English language.
- Ability to present technical solutions with stakeholders in an easy way.
- Knowledge of International Security frameworks, Standards, and Guidelines e.g., NIST-800-53, PCI-DSS, OWASP, and etc.
- Professional Certificated related to work e.g. (CISSP, OSCP, OSWE) is desirable.
- Why Ascend Money?Contribute to a safer digital world.
- Gain hands-on experience with cutting-edge cybersecurity challenges.
- Grow your career in a dynamic, fast-moving environment.
- Don t miss this opportunity to be part of something big! Apply now and take the next step with Ascend Money.
- Apply Now: CLICK
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Oversee the planning, execution, and monitoring of security-related projects.
- Coordinate with cross-functional teams to ensure successful project delivery.
- Develop project plans, schedules, and budgets, and track progress against established objectives.
- Communicate project status, risks, and issues to relevant stakeholders.
- Identify, assess, and prioritize security risks across the organization.
- Develop and implement risk mitigation strategies and controls.
- Monitor and report on the effectiveness of risk management activities.
- Collaborate with stakeholders to ensure a consistent approach to risk management across the organization.
- Develop, review, and maintain security policies, standards, and procedures.
- Ensure alignment with regulatory requirements and industry best practices.
- Collaborate with stakeholders to promote the adoption and enforcement of security policies and standards.
- Provide guidance and support to the organization in the interpretation and implementation of security policies and procedures.
- Effectively communicate security issues and concerns to the technology team.
- Collaborate with the technology team to develop and implement solutions to address identified security issues.
- Provide ongoing support and guidance to the technology team regarding security best practices and risk mitigation.
- Foster a strong working relationship between the security governance function and the technology team to promote a culture of security awareness and collaboration.
- Positive, can-do attitude, who naturally expresses a high degree of empathy to others.
- Bachelor s degree in Information Security, Computer Science, or a related field.
- A minimum of 5 years of experience in information security, with a focus on security governance.
- Professional certifications such as CISSP, CISM, or CRISC are preferred.
- Strong understanding of information security principles, frameworks, and best practices.
- Experience in audit management, risk assessment, and policy development.
- Excellent project management and organizational skills.
- Strong communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams and communicate complex security issues in a clear and concise manner.
- Demonstrated ability to work independently and deliver results under tight deadlines.
- Talent to identify and create a broad vision for a security solution and to execute it.
- Systems Thinking - the ability to see how parts interact with the whole (big picture thinking).
- Proven experience of acting as an expert in project teams.
- Ability to explain your thoughts or findings also to non- technical professionals.
- Good command in written and spoken Thai and English language.
- Location: True Digital Park, Punnawithi.
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Oversee the planning, execution, and monitoring of security-related projects.
- Coordinate with cross-functional teams to ensure successful project delivery.
- Develop project plans, schedules, and budgets, and track progress against established objectives.
- Communicate project status, risks, and issues to relevant stakeholders.
- Security Risk Management: Identify, assess, and prioritize security risks across the organization.
- Develop and implement risk mitigation strategies and controls.
- Monitor and report on the effectiveness of risk management activities.
- Collaborate with stakeholders to ensure a consistent approach to risk management across the organization.
- Establishment of Policies, Standards, and Procedures:Develop, review, and maintain security policies, standards, and procedures.
- Ensure alignment with regulatory requirements and industry best practices.
- Collaborate with stakeholders to promote the adoption and enforcement of security policies and standards.
- Provide guidance and support to the organization in the interpretation and implementation of security policies and procedures.
- Communication and Collaboration with Technology Team:Effectively communicate security issues and concerns to the technology team.
- Collaborate with the technology team to develop and implement solutions to address identified security issues.
- Provide ongoing support and guidance to the technology team regarding security best practices and risk mitigation.
- Foster a strong working relationship between the security governance function and the technology team to promote a culture of security awareness and collaboration.
- Essential Skills & PrerequisitesA positive, can-do attitude, who naturally expresses a high degree of empathy to others.
- Bachelor s degree in Information Security, Computer Science, or a related field.
- A minimum of 5 years of experience in information security, with a focus on security governance.
- Professional certifications such as CISSP, CISM, or CRISC are preferred.
- Strong understanding of information security principles, frameworks, and best practices.
- Experience in audit management, risk assessment, and policy development.
- Excellent project management and organizational skills.
- Strong communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams and communicate complex security issues in a clear and concise manner.
- Demonstrated ability to work independently and deliver results under tight deadlines.
- Talent to identify and create a broad vision for a security solution and to execute it.
- Systems Thinking - the ability to see how parts interact with the whole (big picture thinking).
- Proven experience of acting as the expert in project teams. PERSONAL SKILLS: Ability to explain your thoughts or findings also to non- technical professionals.
- Good command in written and spoken Thai and English language.
- Why Ascend Money?Contribute to a safer digital world.
- Gain hands-on experience with cutting-edge cybersecurity challenges.
- Grow your career in a dynamic, fast-moving environment.
- Don t miss this opportunity to be part of something big! Apply now and take the next step with Ascend Money.
- Apply Now: CLICK
ประสบการณ์:
3 ปีขึ้นไป
ทักษะ:
System Security
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Participate in gathering and analyzing business and technical requirements to develop enterprise-wide Identity and Access Management (IAM) processes and procedures.
- Demonstrate a solid understanding of risk and change management, security policies and controls, user account lifecycle management, onboarding/offboarding, role-based access control (RBAC), access governance, and directory services.
- Translate business requirements into specific system, application, or process designs.
- Collaborate with cross-functional teams, including business units and technical stakeholders, to identify and define functional requirements, and contribute to or lead the design of IAM solutions.
- Engage in a broad range of IAM design activities from requirements analysis to implementation.
- Apply your knowledge of various IAM products and domains, with the ability to quickly adapt to new tools and technologies through self-learning or formal training.
- Provide support for identity provisioning, governance platforms, and privileged access management (PAM) tools.
- Lead and contribute to IAM-related projects to ensure successful delivery of objectives.
- Identify and communicate high-level functional gaps, risks, and potential issues, and propose effective solutions.
- Monitor service delivery against SLAs and escalate exceptions as needed.
- Perform IAM-related risk assessments and consult on project implementations to ensure alignment with RBAC frameworks and internal security policies.
- Drive improvements in RBAC processes, governance policies, and IAM lifecycle workflows.
- Lead or contribute to incident and problem management efforts, ensuring root cause analysis and future incident mitigation.
- Participate in on-call production support rotations and work with vendors to resolve technical issues.
- Influence the IAM strategy by making informed decisions on complex technical challenges.
- Support internal and external audit readiness by preparing and organizing required audit documentation.
- Design and implement key management controls to ensure encryption key security throughout the lifecycle.
- Conduct physical access control reviews and physical security assessments for restricted areas.
- Promote and extend secure access control practices across the organization and its affiliates.
- Essential Skills & PrerequisitesA positive, proactive mindset with strong empathy and team collaboration skills.
- Bachelor s or Master s degree in Computer Engineering, Information Security, MIS, or a related field.
- Minimum of 3 years of experience in cybersecurity or IAM domains.
- Solid foundation in information security principles and best practices.
- Knowledge of international security frameworks and standards, such as COBIT, NIST 800 series, ISO/IEC 27001, PCI-DSS, and OWASP.
- Familiarity with end-to-end security architecture including network, platform, and application layers.
- Experience with application/system security controls, IAM risk assessments, and access governance.
- Strong skills in technical writing, documentation, process mapping, and visual communication.
- Ability to develop and execute a clear vision for IAM and security solutions.
- Why Ascend Money?Contribute to a safer digital world.
- Gain hands-on experience with cutting-edge cybersecurity challenges.
- Grow your career in a dynamic, fast-moving environment.
- Don t miss this opportunity to be part of something big! Apply now and take the next step with Ascend Money.
- Apply Now: CLICK
ประสบการณ์:
1 ปีขึ้นไป
ทักษะ:
Express
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Apply a learning mindset and take ownership for your own development.
- Appreciate diverse perspectives, needs, and feelings of others.
- Adopt habits to sustain high performance and develop your potential.
- Actively listen, ask questions to check understanding, and clearly express ideas.
- Seek, reflect, act on, and give feedback.
- Gather information from a range of sources to analyse facts and discern patterns.
- Commit to understanding how the business works and building commercial awareness.
- Learn and apply professional and technical standards (e.g. refer to specific PwC tax and audit guidance), uphold the Firm's code of conduct and independence requirements.
- Minimum years experience required.
- 1-2 years of experiences in Cyber - Penetration tester.
- Additional application instructions.
- N/A.
- Education (if blank, degree and/or field of study not specified).
- Degrees/Field of Study required: Degrees/Field of Study preferred:Certifications (if blank, certifications not specified).
- Required Skills.
- Optional Skills.
- Accepting Feedback, Accepting Feedback, Active Listening, Cloud Security, Communication, Conducting Research, Cyber Defense, Cyber Threat Intelligence, Emotional Regulation, Empathy, Encryption, Inclusion, Information Security, Intellectual Curiosity, Intelligence Analysis, Intelligence Report, Intrusion Detection, Intrusion Detection System (IDS), IT Operations, Malware Analysis, Malware Detection Tools, Malware Intelligence Gathering, Malware Research, Malware Reverse Engineering, Malware Sandboxing {+ 11 more}Desired Languages (If blank, desired languages not specified).
- Travel Requirements.
- Not Specified
- Available for Work Visa Sponsorship?.
- Yes
- Government Clearance Required?.
- No
- Job Posting End Date.
ประสบการณ์:
4 ปีขึ้นไป
ทักษะ:
Web Services
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Conduct security assessments on systems, networks, and applications.
- Simulate cyber attacks to identify system vulnerabilities.
- Software/Web Application/Web Services penetration testing.
- Network Penetration Testing.
- Mobile Application Penetration Testing.
- Thick Client Penetration Testing.
- Develop and execute penetration testing methodologies.
- Prepare detailed reports on the findings of penetration tests.
- Recommend and implement improvements to security policies.
- Stay updated with the latest penetration testing tools and techniques.
- Train staff on security awareness and procedures.
- Collaborate with IT staff to improve system security.
- Your role as a leader: At Deloitte, we believe in the importance of empowering our people to be leaders at all levels. We expect our people to embrace and live our purpose and shared values, challenging themselves every day to identify issues that are most important to our clients, our people and the communities, and to make an impact that matters. Additionally, Senior Consultants across our Firm are expected to:Actively seek out developmental opportunities for growth, act as strong brand ambassadors for the firm as well as share their knowledge and experience with others.
- Understand the goals of our internal and external stakeholder to set personal priorities as well as align their teams work to achieve the objectives.
- Constantly challenge themselves, collaborate with others to deliver on tasks and take accountability for the results.
- Build productive relationships and communicate effectively in order to positively influence teams and other stakeholders.
- Project integrity and confidence while motivating others through team collaboration as well as recognising individual strengths, differences, and contributions.
- Requirements: If you are someone with:Bachelor's degree in information security, information systems management, computer science, engineering, or other related discipline.
- 4-6 years of experience in information technology, IT audits, or cyber security.
- Proven experience as a Penetration Tester or similar role in cybersecurity.
- Proficiency in using automated tools and manual testing techniques.
- Strong understanding of common vulnerabilities and exploits.
- Relevant certifications (e.g., OSCP, OSWP, CREST, CEH) are a plus.
- Excellent problem-solving and analytical skills.
- Must be able to work under pressure and produce content to tight timelines.
- Ability to self-manage, prioritizing a variety of tasks.
- Due to volume of applications, we regret only shortlisted candidates will be notified.
- Please note that Deloitte will never reach out to you directly via messaging platforms to offer you employment opportunities or request money or your personal information. Kindly apply for roles that you are interested via this official Deloitte website.
- Requisition ID: 112120In Thailand, the services are provided by Deloitte Touche Tohmatsu Jaiyos Co., Ltd. and other related entities in Thailand ("Deloitte in Thailand"), which are affiliates of Deloitte Southeast Asia Ltd. Deloitte Southeast Asia Ltd is a member firm of Deloitte Touche Tohmatsu Limited. Deloitte in Thailand, which is within the Deloitte Network, is the entity that is providing this Website.
ประสบการณ์:
3 ปีขึ้นไป
ทักษะ:
Legal, Financial Analysis, Project Management, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Direct and manage contract guard force to run daily data center operations.
- Handle site security incidents, escalations or any other security related issues.
- Provide after-hours on-call management support and participate in emergent, large scale event response when needed.
- Participate in re-occurring data center security audits and reviews.
- Executes established compliance processes with AWS policies, standards, guidelines and relevant legal and regulatory requirements.
- Provides input on, and may develop security methodologies, policies and procedures.
- Write reports and communicate with management on the status of physical security operations.
- Oversee new security construction or retrofit projects.
- Manage the security P&L for assigned site(s), assist management with financial analysis and contribute to financial decisions for security requirements.
- Collaborate with other teams to protect AWS Data Center personnel, information and assets.
- A day in the life
- Mission: Deliver pioneering physical security by working vigorously to earn and keep customer trust; providing a safe and secure environment for our people, assets, and customer data.
- Vision: Develop exceptional security professionals, consistently apply security processes, and pioneer new technologies that effectively balance security requirements with operational needs.
- Diverse Experiences
- AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn t followed a traditional path, or includes alternative experiences, don t let it stop you from applying.
- Why AWS?
- Amazon Web Services (AWS) is the world s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating that s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
- Inclusive Team Culture
- AWS values curiosity and connection. Our employee-led and company-sponsored affinity groups promote inclusion and empower our people to take pride in what makes us unique. Our inclusion events foster stronger, more collaborative teams. Our continual innovation is fueled by the bold ideas, fresh perspectives, and passionate voices our teams bring to everything we do.
- Mentorship & Career Growth
- We re continuously raising our performance bar as we strive to become Earth s Best Employer. That s why you ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
- Work/Life Balance
- We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there s nothing we can t achieve.
- BASIC QUALIFICATIONS.
- 3+ year s experience managing contract security and physical security operation programs such as Access Control/Intrusion Detection and CCTV Surveillance systems.
- 3+ years in Project Management experience and creating process improvement procedure.
- Experience in managing vendors/vendor teams.
- PREFERRED QUALIFICATIONS.
- Bachelor s degree and or equivalent professional experience in corporate or government security environment.
- 3+ years experience creating and implementing emergency planning programs, physical security countermeasures.
- Excellent oral and written communication skills.
- Proficiency in both Thai and English language.
- Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you re applying in isn t listed, please contact your Recruiting Partner.
ประสบการณ์:
2 ปีขึ้นไป
ทักษะ:
Risk Management, Compliance, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Invite and give in the moment feedback in a constructive manner.
- Share and collaborate effectively with others.
- Identify and make suggestions for improvements when problems and/or opportunities arise.
- Handle, manipulate and analyse data and information responsibly.
- Follow risk management and compliance procedures.
- Keep up-to-date with developments in area of specialism.
- Communicate confidently in a clear, concise and articulate manner - verbally and in the materials I produce.
- Build and maintain an internal and external network.
- Seek opportunities to learn about how PwC works as a global network of firms.
- Uphold the firm's code of ethics and business conduct.
- Bachelor s degree in Computer Engineering, Computer Science, Information Systems or a related field.
- 0-2 years of experience.
- Be able to utilize your well-rounded skills and experience related to industries to steer your projects to a successful outcome.
- Team player with strong interpersonal, communication skills.
- Be able to work both independently and as part of a team with professionals at all levels.
- Proficiency in spoken and written English & Thai.
- We thank all applicants. Please note that only short-listed candidates will be contacted for interviews.
- Education (if blank, degree and/or field of study not specified).
- Degrees/Field of Study required: Degrees/Field of Study preferred:Certifications (if blank, certifications not specified).
- Required Skills.
- Optional Skills.
- Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Azure Data Factory, Communication, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Managed Services, Optimism, Privacy Compliance, Regulatory Response, Security Architecture, Security Compliance Management, Security Control, Security Incident Management, Security Monitoring {+ 3 more}Desired Languages (If blank, desired languages not specified).
- Travel Requirements.
- Available for Work Visa Sponsorship?.
- Government Clearance Required?.
- Job Posting End Date.
ประสบการณ์:
3 ปีขึ้นไป
ทักษะ:
Risk Management, Big Data, Teamwork, English
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Providing effective 2nd line of defense on oversight of Technology related risk involving in assessing, in depth, the risks in IT Infrastructure, Cloud strategy, Data Management, IT Outsourcing, IT Operations, and Big Data.
- Assisting to update Ascend Money/True Money s risk appetite for approval by the board.
- Facilitating Risk and Control Self-Assessment (R&CSA) and monitoring the design and testing the operational effectiveness under Key Control Testing (KCT) and incident m ...
- Coordinating and supporting the Country Risk Management team for facilitating Risk and Control Self-Assessment (R&CSA), performing Key Control Testing (KCT), setting and reviewing Key Risk Indicators (KRIs) and Incident Management.
- Challenge business units in implementing a secured architecture aligned with the business goals and future plans, including company policy and regulatory requirements.
- Analysing IT incidents reported by staff and report lessons learned to the Head of International Risk and Fraud Management and the Committee.
- Delivering the oversight, advisory and guidance on new technology risk and emerging risk.
- Investigation, root-cause analysis, and coordination with relevant parties for data loss prevention monitoring and management.
- Assisting the Head of International Risk and Fraud Management to bring together a holistic picture of the technology risk across the company.
- Tracking progress status with the Country Risk Management team around remediation activities to close gaps from policy compliance assessments and various other risk assessments.
- Providing IT & Cyber Risk dashboard for Committee and Senior Management.
- Ad-hoc assignment.
- Bachelor s or Master s Degree in Economic, Finance, IT or related fields.
- Minimum 3 years of professional experience in the IT Risk Management, IT Security or IT Audit with relevant experience in the Financial Services Industry.
- Strong organization, good presentation, communication, writing, interpersonal and teamwork skills.
- Demonstrated ability to complete assigned projects in a timely manner and in a fast-paced, high pressure environment.
- Multiple industry recognized certifications like CISSP, CRISC, CSSP (Cloud), CPT, ISO27001 is a plus.
- Strong analytical and quantitative skills.
- Thorough knowledge of IT governance and control frameworks.
- Understanding of complex IT environments including legacy, hybrid cloud, virtualization, software defined networking is a plus.
- Good command in both oral and written in English communication.
- Able to travel in regional countries (i.e. Myanmar, Vietnam, Cambodia, Indonesia, Malaysia, the Philippines).
ประสบการณ์:
5 ปีขึ้นไป
ทักษะ:
Web Services
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Conduct security assessments on systems, networks, and applications.
- Simulate cyber attacks to identify system vulnerabilities.
- Software/Web Application/Web Services penetration testing.
- Network Penetration Testing.
- Mobile Application Penetration Testing.
- Thick Client Penetration Testing.
- Develop and execute penetration testing methodologies.
- Prepare detailed reports on the findings of penetration tests.
- Recommend and implement improvements to security policies.
- Stay updated with the latest penetration testing tools and techniques.
- Train staff on security awareness and procedures.
- Collaborate with IT staff to improve system security.
- Your role as a leader: At Deloitte, we believe in the importance of empowering our people to be leaders at all levels. We expect our people to embrace and live our purpose and shared values, challenging themselves every day to identify issues that are most important to our clients, our people and the communities, and to make an impact that matters. Additionally, Senior Consultants across our Firm are expected to:Actively seek out developmental opportunities for growth, act as strong brand ambassadors for the firm as well as share their knowledge and experience with others.
- Understand the goals of our internal and external stakeholder to set personal priorities as well as align their teams work to achieve the objectives.
- Constantly challenge themselves, collaborate with others to deliver on tasks and take accountability for the results.
- Build productive relationships and communicate effectively in order to positively influence teams and other stakeholders.
- Project integrity and confidence while motivating others through team collaboration as well as recognising individual strengths, differences, and contributions.
- Requirements: If you are someone with:Bachelor's degree in information security, information systems management, computer science, engineering, or other related discipline.
- 5 - 8 years of experience in information technology, IT audits, or cyber security.
- Proven experience as a Penetration Tester or similar role in cybersecurity.
- Proficiency in using automated tools and manual testing techniques.
- Strong understanding of common vulnerabilities and exploits.
- Relevant certifications (e.g., OSCP, OSWP, CREST, CEH) are a plus.
- Excellent problem-solving and analytical skills.
- Must be able to work under pressure and produce content to tight timelines.
- Ability to self-manage, prioritizing a variety of tasks.
- Due to volume of applications, we regret only shortlisted candidates will be notified.
- Please note that Deloitte will never reach out to you directly via messaging platforms to offer you employment opportunities or request money or your personal information. Kindly apply for roles that you are interested via this official Deloitte website. Requisition ID: 112119In Thailand, the services are provided by Deloitte Touche Tohmatsu Jaiyos Co., Ltd. and other related entities in Thailand ("Deloitte in Thailand"), which are affiliates of Deloitte Southeast Asia Ltd. Deloitte Southeast Asia Ltd is a member firm of Deloitte Touche Tohmatsu Limited. Deloitte in Thailand, which is within the Deloitte Network, is the entity that is providing this Website.
ประสบการณ์:
4 ปีขึ้นไป
ทักษะ:
Compliance
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Project Leadership: Lead and support IAM initiatives with a strong emphasis on Identity Governance & Administration (IGA) solutions across cloud and on-premises environments. Drive secure integration practices during application onboarding and ensure alignment with enterprise identity architecture and compliance requirements.
- Client Collaboration: Engage with client stakeholders to understand application landscapes, assess existing access governance frameworks, and define onboarding strategies. Provide guidance on improving user experience, access governance, and security e ...
- SailPoint or equivalent IGA solutions.
- Application onboarding and integration best practices.
- Identity lifecycle and access governance principles.
- Federation technologies (e.g., SAML, OAuth2.0, OIDC, WS-Fed).
- Authentication policies, MFA enforcement, and session security.
- Troubleshooting identity-related issues across complex environments.
- Configuration and Deployment: Support the design, configuration, and deployment of Identity Governance & Administration (IGA) solutions across a range of enterprise and SaaS applications. Ensure integrations follow identity security best practices and align with standards such as Zero Trust and least privilege access.
- Application Onboarding: Work closely with application owners, developers, and platform teams to onboard applications into the organization's IGA platform (SailPoint). Assist in defining identity lifecycle flows, access requests, access certifications, Segregation of Duties (SoD) policies, and performing validation and testing.
- Project Delivery: Contribute to the successful delivery of IGA projects by maintaining accurate documentation, supporting stakeholder communications, tracking progress, and identifying technical or operational risks early. Collaborate with senior engineers and architects to troubleshoot and resolve issues during integration.
- Team Collaboration: Work under the guidance of senior IAM professionals and project leads, supporting initiatives across multiple clients or business units. Actively participate in internal knowledge sharing, reusable asset development, and improvement of onboarding playbooks and frameworks.
- Your role as a leader: At Deloitte, we believe in the importance of empowering our people to be leaders at all levels. We connect our purpose and shared values to identify issues as well as to make an impact that matters to our clients, people and the communities. Additionally, Consultants across our Firm are expected to:Demonstrate a strong commitment to personal learning and development.
- Understand how our daily work contributes to the priorities of the team and business.
- Understand the set expectations and demonstrate accountability in keeping personal performance on track.
- Actively focus on developing effective communications and relationship-building skills with stakeholders, clients and team.
- Demonstrate an appreciation for working with others.
- Understand what is fundamental to Deloitte s success as a business.
- Demonstrate integrity and an awareness of strengths, differences, and personal impact.
- Develop their understanding of Deloitte and offer a fresh perspective.
- Requirements:Bachelor s degree in computer science, Information Security, Engineering, or a related field;.
- Minimum 4 years of experience in Identity and Access Management (IAM) with a strong focus on SailPoint or IGA solutions.
- Minimum 4 years of hands-on experience with SSO platforms such as PingFederate, Azure Active Directory (Entra ID), or ADFS, including configuring authentication protocols like SAML 2.0, OAuth 2.0, and OpenID Connect.
- Willingness and ability to travel, based on client and project requirements across Southeast Asia.
- Reliable team player, with a track record of contributing to successful project delivery by collaborating effectively with cross-functional teams and supporting senior colleagues in meeting project goals.
- Strong communication skills, with the ability to convey technical information clearly, engage with stakeholders professionally, and produce well-structured documentation and reports.
- A structured thinker with strong analytical and problem-solving skills, capable of navigating technical and business complexities with clarity.
- Relevant certifications e.g. SailPoint Certified Identity Security Engineer are a plus.
- Due to volume of applications, we regret that only shortlisted candidates will be notified.
- Please note that Deloitte will never reach out to you directly via messaging platforms to offer you employment opportunities or request for money or your personal information. Kindly apply for roles that you are interested in via this official Deloitte website. Requisition ID: 112127In Thailand, the services are provided by Deloitte Touche Tohmatsu Jaiyos Co., Ltd. and other related entities in Thailand ("Deloitte in Thailand"), which are affiliates of Deloitte Southeast Asia Ltd. Deloitte Southeast Asia Ltd is a member firm of Deloitte Touche Tohmatsu Limited. Deloitte in Thailand, which is within the Deloitte Network, is the entity that is providing this Website.
ประสบการณ์:
2 ปีขึ้นไป
ประเภทงาน:
งานประจำ
เงินเดือน:
สามารถต่อรองได้
- Oversee daily general services operations (courier, drivers, housekeeping).
- Manage preventive and corrective maintenance of electrical, HVAC, UPS, generators, and fire safety systems.
- Coordinate vendors and ensure service quality and compliance.
- Support office renovation, relocation, and workspace planning initiatives.
- Manage security and access control systems, including audits and access reviews.
- Conduct annual non-IT fixed asset inventory and ensure proper reporting.
- Ensure compliance with internal policies and ISO 27001 ISMS principles.
- ABOUT YOU
- Bachelor's degree in Electrical Engineering with valid engineering license.
- Minimum 2 years of experience in facilities or building management.
- Experience in maintenance programs and vendor coordination.
- Strong communication skills in Thai and English.
- Organized, proactive, and solution-oriented mindset.
- WHY AMARIS?
- Global Diversity: Be part of an international team of 110+ nationalities, celebrating diverse perspectives and collaboration.
- Trust and Growth: With 70% of our leaders starting at entry-level, we're committed to nurturing talent and empowering you to reach new heights.
- Continuous Learning: Unlock your full potential with our internal Academy and over 250 training modules designed for your professional growth.
- Vibrant Culture: Enjoy a workplace where energy, fun, and camaraderie come together through afterworks, networking events, and more.
- Meaningful Impact: Join us in making a difference through our CSR initiatives, including the WeCare Together program, and be part of something bigger.
- Equal Opportunity
- Amaris Consulting is proud to be an equal opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.
- Who are we?
- Amaris Consulting is an independent technology consulting firm providing guidance and solutions to businesses. With more than 1000 clients across the globe, we have been rolling out solutions in major projects for over a decade - this is made possible by an international team of 7,600 people spread across 5 continents and more than 60 countries. Our solutions focus on four different Business Lines: Information System & Digital, Telecom, Life Sciences and Engineering. We're focused on building and nurturing a top talent community where all our team members can achieve their full potential. Amaris is your steppingstone to cross rivers of change, meet challenges and achieve all your projects with success.
- Brief Call: Our process typically begins with a brief virtual/phone conversation to get to know you! The objective? Learn about you, understand your motivations, and make sure we have the right job for you!
- Interviews (the average number of interviews is 3 - the number may vary depending on the level of seniority required for the position). During the interviews, you will meet people from our team: your line manager of course, but also other people related to your future role. We will talk in depth about you, your experience, and skills, but also about the position and what will be expected of you. Of course, you will also get to know Amaris: our culture, our roots, our teams, and your career opportunities!
- Case study: Depending on the position, we may ask you to take a test. This could be a role play, a technical assessment, a problem-solving scenario, etc.
- As you know, every person is different and so is every role in a company. That is why we have to adapt accordingly, and the process may differ slightly at times. However, please know that we always put ourselves in the candidate's shoes to ensure they have the best possible experience.
- We look forward to meeting you!
- 1
