Job Description
Job Title:
Manager - Information Security
Posting Start Date:
19/12/2025
Job Description:
Job Purpose (Accountability)
Develop and implement the organization’s Cyber Security strategy to safeguard information assets and ensure compliance with applicable laws and regulations. Establish, review, and update Cyber Security policies and IT risk controls in collaboration with relevant stakeholders to strengthen the organization’s security posture. Manage and control budgets related to security tools and support effective internal and external audits.
Duties / Responsibilities
- Develop and implement Cyber Security strategies to align with the organization’s mission and objectives.
- Oversee and guide the Information Security team’s operations to ensure efficiency, effectiveness, and compliance with standards.
- Establish, review, and update policies, measures, and practices related to Cyber Security, personal data protection (PDPA Security), and IT risk management on a regular basis.
- Manage and control budgets for Cyber Security tools and solutions, including assessing cost-effectiveness and value of utilization.
- Collaborate with relevant departments and stakeholders to ensure consistent and aligned security operations.
- Monitor, analyze, and assess cyber threat intelligence and provide strategic reports and recommendations to management.
- Support internal (Internal Audit) and external (External Audit) audits related to Cyber Security to ensure compliance with applicable laws, regulations, and relevant standards.
- Conduct analysis of threats, vulnerabilities, and risk assessments, develop preventive measures to mitigate risks, and prepare reports to management for decision-making.
- Foster and develop the capabilities of the Cyber Security team to enhance knowledge, skills, and adaptability to evolving threats and emerging technologies.
- Manage and coordinate the organization’s security incident response and disaster recovery plans.
- Promote and deliver Cybersecurity Awareness training programs for employees across the organization.
Education
Bachelor Degree in Information Technology or Computer sciences
Work Experience
Minimum 8 years experience
Certificate
- Knowledge of ISO 27001, NIST, PDPA, and Risk Management standards.
- Professional certifications such as CISSP, CISM, or CISA are preferred.
TOEIC
Minimum score 650 or above.