Job Openings Cyber Security & IT Compliance Engineer

About the job Cyber Security & IT Compliance Engineer

Cyber Security & IT Compliance Engineer

Job Overview

The Cyber Security & IT Compliance Engineer plays a key role in establishing, maintaining, and enhancing the organization's IT Security Standards to meet international standards.

The role is responsible for conducting Security Risk Assessments, working closely with internal Compliance and Risk teams to establish aligned security policies and guidelines, and supporting the selection and implementation of security technologies.

The position also plays an important role in identifying, mitigating, and preventing cybersecurity threats across both day-to-day operations (BAU) and new organizational projects.

Key Responsibilities

1. Security Governance & Compliance Alignment

  • Maintain and oversee the organization's IT security standards.
  • Collaborate closely with Compliance and Risk teams to establish aligned information security policies, guidelines, and controls.

2. Security Risk Assessment & Management

  • Conduct IT Security Risk Assessments to identify potential security risks and vulnerabilities.
  • Assess system vulnerabilities and recommend appropriate mitigation measures to reduce risks to an acceptable level.

3. Security Incident Management & Prevention

  • Monitor, analyze, respond to, and resolve Information Security Incidents and cybersecurity threats.
  • Develop proactive security measures to prevent recurring security incidents.

4. Security Technology Implementation & Operations

  • Manage, evaluate, procure, implement, and operate information security technologies and tools, such as:

    • Firewall
    • SIEM
    • IAM
    • Endpoint Security
    • Cloud Security Tools

5. Strategic Sourcing & TOR

  • Define, design, draft, and review Terms of Reference (TOR) and RFP documents for the procurement of Cyber Security technologies, equipment, and services.

6. Consulting & Security Awareness

  • Provide recommendations and present Security Architecture concepts and solutions.
  • Conduct Cyber Security awareness training for employees and relevant stakeholders.

7. Other Responsibilities

  • Perform other duties and responsibilities as assigned by the supervisor.

Qualifications

Technical Expertise

  • Strong knowledge and understanding of Cyber Security, Information Security Standards, such as:

    • ISO 27001
    • NIST
    • PDPA
  • Strong knowledge of Network Security and Cloud Security.

Risk & Compliance Mindset

  • Strong ability to conduct security risk assessments and analyze technology vulnerabilities.
  • Good understanding of Compliance frameworks and enterprise risk management processes.

Vendor & Stakeholder Management

  • Strong communication, negotiation, and coordination skills.
  • Ability to work closely with Compliance, Risk, Software Development teams, Vendors, and Outsource partners.

Time & Project Management

  • Excellent time management skills with a high level of responsibility and accountability.
  • Strong commitment to delivering Security projects successfully within defined timelines.

Presentation Skills

  • Ability to clearly and effectively present security concepts, security architecture, and risk assessment results to management and relevant teams.

Preferred Skills

  • Understanding of DevSecOps concepts.
  • Knowledge of Cloud Security.
  • Knowledge of Network Security.
  • Understanding of Infrastructure as Code (IaC).