Head of Business Security and Resilience

Responsibilities

Cybersecurity

  1. Leads and oversee the successfully implementation of Security program to meet the regulation, policies, and industry standard (not only IT Security but Group Security Strategic Plan at GTI/GTL level, in line with indications received from the Group Chief Security Officer function).
  2. Conduct on-going assessment on the effectiveness of Security controls and recommend improvement plans for any identified gaps.
  3. Conduct on-going Security awareness program via different channels such as e-Learning, regular briefing, circular and email alerts.
  4. Coordinate, monitor and respond to Security threats, alerts and security incidents with the regional Incident Respond Team (IRT).
  5. Evaluate new project and collaborates with other team to ensure information security requirements are defined, documented, tested, and delivered as part of project deliverables including application security, cloud security, data security and security testing.
  6. Support on-going services monitoring including WAF, IRT.
  7. Ensure the implementation of the third parties security management process and monitor compliance.
  8. Customer Assurance (Group Customers).
  9. Risk Management tasks (Cyber Risk assessment, Digital Risk assessment, risk review, RMC pack, DRM pack, IT Risk quarterly report, ad-hoc requests).
  10. Compliance tasks (questionnaire, gap, assessment, hearing, etc.).
  11. Regulators (OIC and SEC) tasks (meetings, questionnaire, gap, assessment, hearing, etc.).
  12. Data Security monitoring and investigation.
  13. Data Security Improvement – proactively search through any data risks in business usages and drive data security improvements.
  14. Support at least 10 audits annually (IT for Financial Audit, OIC annual IT Risk Audit, SEC annual IT Risk Audit, 2-3 Internal Audits, 6-10 OIC annual e-commerce applications recertification, OIC new e-commerce application approval request).
  15. Management Review – BoD, EC, ITSC, Monthly Group KPI report, Regional and Group sessions.

Business Resilience

  1. Develops and maintains a business recovery plan and procedure; reviews, revises, and expands existing plans and protocols.
  2. Conducts risk assessments for various departments and functions, analyzing potential business impact of unpredictable business interruptions such as natural disasters, security breach, legal claims, and market disruptions.
  3. Collaborates with IT staff to develop and implement best practices to protect and restore data and systems in the event of disasters.
  4. Identifies and implements recovery operations and methods to allow the company to function at limited or partial capacity in the event that part or all of the infrastructure is damaged or destroyed.
  5. Creates and facilitates practice drills for plan execution. Develops and provides staff training on risk management and disaster recovery.

Corporate & Physical Security (Crisis Management Model, Travel Security and Event Security)

  1. Implement security standards, policies, and procedures.
  2. Develop safety standards, policies, or procedures.
  3. Identify, investigate, or resolve security risks and breaches.
  4. Crisis: Implementing and maintaining its own Crisis Management Model, in compliance with the Group Guideline provisions and setting up a program for regularly testing the effectiveness and readiness of Crisis Management Model.
  5. Travel: Evaluating the country/area risk level assigned by Group and support local travellers in travel security.
  6. Event: Evaluating the event risk level, in compliance with the Group Guideline provision and supporting the event owner/planner to assess the necessity of security measures.
  7. Physical Security: Respond to Physical Security situations like medical emergencies, bomb threats, fire alarms, or intrusion alarms, following emergency response procedures.
  8. Communicate security status, updates, and actual or potential problems.

Qualification

  • Master’s Degree in Information technology
  • At least one Cibersecurity certification like: CISSP, CISA, CISM, CEH, GCIH, SSCP, etc…
  • At least 10 years working experience, preferable in security related fields
  • Analytical skill and able to work independently
  • Outgoing personality, positive attitude and strong contribution for teamwork
  • Service minded and good interpersonal skill
  • Fluent in English both written and spoken

เราใช้คุกกี้เพื่อมอบประสบการณ์ที่ดีในการใช้เว็บไซต์ หากคุณใช้เว็บไซต์ต่อ ถือว่าคุณยอมรับการใช้คุกกี้และ นโยบายคุกกี้ คลิก ตั้งค่า เพื่อตั้งค่าคุกกี้

ตั้งค่าความเป็นส่วนตัว

คุณสามารถเลือกการตั้งค่าคุกกี้โดยเปิด/ปิด คุกกี้ในแต่ละประเภทได้ตามความต้องการ ยกเว้น คุกกี้ที่จำเป็น

ยอมรับทั้งหมด
จัดการความเป็นส่วนตัว
  • คุกกี้ที่จำเป็น
    เปิดใช้งานตลอด

    เราใช้คุกกี้ที่จำเป็นสำหรับการทำงานพื้นฐานของเว็บไซต์ เช่น การรักษาความปลอดภัยและการบริหารจัดการเครือข่าย เป็นต้น เพื่อให้คุณสามารถเข้าชมและใช้งานเว็บไซต์ได้อย่างเป็นปกติ หากไม่มีคุกกี้นี้เว็บไซต์จะไม่สามารถทำงานได้อย่างเหมาะสม คุณไม่สามารถปิดการใช้งานคุกกี้นี้ได้
    รายละเอียดคุกกี้

  • คุกกี้เพื่อการวิเคราะห์

    คุกกี้ประเภทนี้จะทำการเก็บข้อมูลการใช้งานเว็บไซต์ของผู้เข้าชม เพื่อเป็นประโยชน์ในการวัดผล ปรับปรุง และพัฒนาประสบการณ์ที่ดีในการใช้งานเว็บไซต์ ถ้าคุณปิดการใช้งานคุกกี้นี้ เราจะไม่สามารถวัดผล ปรับปรุงและพัฒนาเว็บไซต์ได้

  • คุกกี้เพื่อปรับเนื้อหาให้เข้ากับกลุ่มเป้าหมาย

    คุกกี้ประเภทนี้จะเก็บข้อมูล เช่น เว็บไซต์หรือเนื้อหาที่คุณเยี่ยมชม เป็นต้น เพื่อให้เราสามารถนำมาวิเคราะห์ และนำเสนอเนื้อหา ให้ความเหมาะสมและตรงกับความสนใจของคุณ ถ้าคุณปิดการใช้งานคุกกี้นี้ คุณจะยังเห็นเนื้อหาและโฆษณาทั่วไป ซึ่งมีเนื้อหาและโฆษณาที่ไม่ตรงกับความสนใจของคุณ

  • คุกกี้เพื่อช่วยในการใช้งาน

    คุกกี้ประเภทนี้จะช่วยจดจำการกรอกข้อมูล เช่น สมัครงาน สนใจผลิตภัณฑ์ เพื่อให้คุณสามารถใช้งานเว็บไซต์ได้สะดวกยิ่งขึ้น โดยไม่ต้องกรอกข้อมูลใหม่ทุกครั้งที่เข้าใช้เว็บไซต์ ถ้าคุณปิดการใช้งานคุกกี้นี้ คุณอาจใช้งานเว็บไซต์ได้ไม่สะดวกและไม่เต็มประสิทธิภาพ

บันทึก