Job Description
Our client is the Bangkok technology hub of a global enterprise group, delivering IT solutions and services to group companies worldwide. They are hiring a Principal Information Security Officer to own local information security governance and digital resilience.
Location: Bangkok (hybrid working)
Type: Full-time, permanent
About the role
The role is roughly 70-80% Information Security Officer and 20-30% Digital Resilience Officer. You drive the implementation and evolution of the group's information security framework locally, provide control assurance for services delivered from the hub, and coordinate IT risk management and third-party risk. You report to an overseas functional manager and the local Head of Operations, working daily with international senior stakeholders, so excellent spoken and written English is essential.
Responsibilities - Information Security (70-80%)
- Drive implementation of and compliance with group-wide standards, regulatory requirements and industry security standards (including DORA and NIS2) across all services and projects
- Oversee the local compliance reporting process; assess deviations from security policies and contractual provisions and develop mitigation strategies
- Lead the local Information Security Steering Board and prepare IS action plans
- Support local executive management on regulatory IS governance requirements and sound organizational structures
- Serve as the local contact point for all information security matters across business, partners, customers and safeguarding functions
- Systematically assess the effectiveness of security controls across services, partners and third-party providers
- Own security risk management end to end, with all deviations reported and managed in the GRC tool
- Promote security awareness across the workforce and manage rollout of global security trainings
- Deliver high-impact reporting to regional management and the local Board of Directors, and contribute to the group's global ISO community
Responsibilities - Digital Resilience (20-30%)
- Establish and maintain digital risk controls integrated into operational processes; lead digital risk identification and assessment across applications and services
- Participate in the local Risk Council and report on local digital risk status
- Conduct third-party risk management (TPRM) assessments for all services and contracts, ensuring documentation, tiering compliance, exit strategies and validated BCDR plans in line with DORA
- Coordinate responses to customer audits and support internal audit and assurance activities
- Ensure ITOM compliance; run the annual IT compliance self-assessment and quarterly IT risk reporting
Requirements
- Bachelor's or Master's degree in Computer Science, Information Technology or related field
- Recognized security certifications preferred: CISSP, CISA, CISM, CRISC, PCI DSS or ISO 27001 Lead Auditor
- 8+ years in information security, information risk management, controls assurance and compliance programs
- Experience with internal controls, risk assessments, IT control testing or operational auditing
- Experience reviewing and gap-analyzing security policies against cybersecurity frameworks (PCI DSS, GLBA, NYDFS, ISO, NIST, etc.)
- Strong presentation skills, attention to detail, analytical thinking and integrity
- Excellent communication skills in English, written and spoken - the role works daily with regional and global leadership
What's offered
- Hybrid work model with work-from-home allowance
- Company bonus scheme and provident fund
- Comprehensive health insurance covering family members
- Premium gym membership, learning programs and international career mobility