Head of Business Security and Resilience

Responsibilities

Cybersecurity: Local CSO, not only IT Security

  1. Leads and oversee the successfully implementation of Security program to meet the regulation, policies, and industry standard. (not only IT Security but Group Security Strategic Plan at GTI/GTL level, in line with indications received from the Group Chief Security Officer function.
  2. Conduct on-going assessment on the effectiveness of Security controls and recommend improvement plans for any identified gaps
  3. Conduct on-going Security awareness program via different channels such as e-Learning, regular briefing, circular and email alerts
  4. Coordinate, monitor and respond to Security threats, alerts and security incidents with the regional Incident Respond Team (IRT)
  5. Evaluate new project and collaborates with other team to ensure information security requirements are defined, documented, tested, and delivered as part of project deliverables including application security, cloud security, data security and security testing.
  6. Support on-going services monitoring including WAF, IRT,
  7. Ensure the implementation of the third parties security management process and monitor the
  8. Customer Assurance (Group Customers)
  9. Risk Management tasks (Cyber Risk assessment, Digital Risk, assessment, risk review, RMC pack, DRM pack, IT Risk quarterly report, ad-hoc requests)
  10. Compliance tasks (questionnaire, gap, assessment, hearing, etc.)
  11. Regulators (OIC and SEC) tasks (meetings, questionnaire, gap, assessment, hearing, etc.)
  12. Data Security monitoring and investigation
  13. Data Security Improvement – proactively search through any data risks in business usages and drive data security improvements.
  14. Support at least 10 audits annually (IT for Financial Audit, OIC annual IT Rist Audit, SEC annual IT Risk Audit, 2-3 Internal Audits, 6-10 OIC annual e-commerce applications recertification, OIC new e-commerce application approval request)
  15. Management Review – BoD, EC, ITSC, Monthly Group KPI report, Regional and Group sessions

Business Resilience:

  1. Develops and maintains a business recovery plan and procedure; reviews, revises, and expands existing plans and protocols.
  2. Conducts risk assessments for various departments and functions, analyzing potential business impact of unpredictable business interruptions such as natural disasters, security breach, legal claims, and market disruptions.
  3. Collaborates with IT staff to develop and implement best practices to protect and restore data and systems in the event of disasters.
  4. Identifies and implements recovery operations and methods to allow the company to function at limited or partial capacity in the event that part or all of the infrastructure is damaged or destroyed.
  5. Creates and facilitates practice drills for plan execution. Develops and provides staff training on risk management and disaster recovery.

Corporate (Crisis Management Model, Travel Security and Event Security) and Physical Security:

  1. Implement security standards, policies, and procedures.
  2. Develop safety standards, policies, or procedures.
  3. Identify, investigate, or resolve security risks and breaches.
  4. Crisis: implementing and maintaining its own Crisis Management Model, in compliance with the Group Guideline provisions and setting up a program for regularly testing the effectiveness and readiness of Crisis Management Model;
  5. Travel: Evaluating the country/area risk level assigned by Group and support local travellers in travel security.
  6. Event: Evaluating the event risk level, in compliance with the Group Guideline provision and supporting the event owner/planner to assesses the necessity of security measures.
  7. Physical Security: Respond to Physical Security situations like medical emergencies, bomb threats, fire alarms, or intrusion alarms, following emergency response procedures.
  8. Communicate security status, updates, and actual or potential problems

Qualification

  • Master’s Degree in Information technology
  • At least one Cibersecurity certification like: CISSP, CISA, CISM, CEH, GCIH, SSCP, etc…
  • At least 10 years working experience, preferable in security related fields
  • Analytical skill and able to work independently
  • Outgoing personality, positive attitude and strong contribution for teamwork
  • Service minded and good interpersonal skill
  • Fluent in English both written and spoken

We use cookies to enhance your site experience. by continuing to browse, you agree to our use of cookies & Cookies Policy  Click Settings to manage.

Privacy Preferences

You can set up your cookies preference by clicking the available sliders to ‘On’ or ‘Off’, except only Necessary cookies. Then, click “Save Preference”.

ยอมรับทั้งหมด
Manage Consent Preferences
  • Necessary cookies
    Always Active

    These cookies are necessary for the website to function and cannot be disabled. We use necessary cookies to enable core functionality such as security and network management, and, to allow you to browse the website normally. Without this cookies, the website would not be able to work properly.
    Cookies Details

  • Analytics cookies

    These cookies are used to collect information about how visitors use our website. We use the information to measure and improve the performance of our website. If you disable these cookies, we will not be able to use the information for improving our website.

  • Advertising Cookies

    These cookies are used to collect information about your activities (ex. sites or contents you’ve visited) to analyze and display content or advertisement that are relevant to your interests. If you disable these cookies, you will still see generic advertisement on your browser (not targeted content or advertisement).

  • Functional cookies

    These cookies enable the website to remember the information that you’ve pre-filled on the website (i.e. join our team or leave your contact for your interest in our product). The intention is to allow you to use the website more convenient. If you disable these cookies, then some or all of these services may not function properly.

Save