Jobless Developer
CP Axtra logo

Posted 10 days ago

Open

Department Manager - Governance, Risk & Compliance (Lotus Nawamin Office)

BangkokOn-siteFull-time

AI Summary

Manages governance, risk, and compliance for IT and information security, conducting risk assessments, maintaining security policies, and coordinating with internal and external audit stakeholders.

About this role

  • Understand and interpret requirements across relevant IT Risk, Cybersecurity, Regulatory and map requirements against the organization’s technology and security policies, standards and control
  • Develop, establish, maintain, and continuously improve the organization’s Information Security Policies, Standards and Guidelines ensuring alignment with business requirements, regulatory obligations, and industry best practices.
  • Conduct Technology Risk Assessments across applications, infrastructure, products, projects, and operations. Identify risks and control gaps, recommend appropriate remediation or mitigating controls, and track risks through closure or formal risk acceptance.
  • Manage the Risk Acceptance process, ensuring exceptions have appropriate business justification, compensating controls, accountable risk owners, defined expiry dates, and periodic review.
  • Coordinate with internal audit, external audit and other stakeholders to support audit and assessment, provide the information as audit request and regular report status to IT and Security management.
  • Define and monitor Security KPIs, KRIs, compliance metrics, and management dashboards to measure control effectiveness, risk exposure, remediation progress, and overall security governance maturity.
  • Perform other related duties as assigned

Requirements

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • 5+ years working in IT filed with a focus on information security or IT audit.
  • Knowledge of ISO27001, PCIDSS and IT security control
  • Exceptional communication, problem solving and cross-group collaboration skills
  • Good command of written and spoken English
  • Ability to present ideas in business-friendly and user-friendly language

Skills

Compliance MetricsCybersecurityInformation Security PoliciesISO 27001IT AuditIT Security ControlsKPIsKRIsManagement DashboardsPCI DSSRegulatory ComplianceRisk AcceptanceRisk Assessments

Explore related jobs

Browse these categories

Market data for this role

All reports →