The Information Technology (IT) Security Manager role leads and strengthens the organisation’s security, risk management, and compliance initiatives. The position develops and maintains security programmes, manages security operations, supports compliance activities, and collaborates with business and technology teams to protect the organisation’s information assets.
Responsibilities
Security Management
Develop, implement, and maintain the organisation’s information security strategy, policies, and standards
Identify, assess, and manage cybersecurity risks across systems, applications, and infrastructure
Monitor emerging threats and recommend appropriate mitigation measures
Lead security incident response activities and coordinate investigations when required
Conduct security assessments and recommend improvements to strengthen the organisation’s security posture
Promote security awareness and best practices across the organisation
Risk & Compliance
Ensure compliance with relevant security standards, regulations, and industry best practices
Support internal and external audits, assessments, and certification activities
Maintain security documentation, policies, procedures, and control frameworks
Track remediation activities and ensure identified risks are addressed appropriately
Assist in establishing governance processes and security controls across the organisation
Security Operations
Oversee vulnerability management activities, including risk reviews and remediation tracking
Coordinate security testing, assessments, and vendor reviews
Evaluate and implement security tools and technologies to enhance protection and monitoring capabilities
Monitor security metrics and prepare reports for management
Stakeholder Management
Work closely with IT, engineering, operations, and business teams to integrate security into daily operations
Provide security guidance and recommendations for technology initiatives and projects
Support customer security reviews, questionnaires, and due diligence processes when required
Act as a trusted adviser on information security matters for internal stakeholders
Requirements
Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field
At least 8 years of experience in information security, cybersecurity, IT risk, IT governance, or a related discipline
Experience managing security programmes, policies, and operational controls
Strong understanding of information security principles, risk management, and security governance
Familiarity with cloud security, network security, vulnerability management, and incident response
Experience working with security frameworks and compliance standards
Strong analytical, problem-solving, and decision-making skills
Excellent communication and stakeholder management abilities
Good command of written and spoken English
Preferred qualifications:
Professional certification such as CISSP, CISM, CISA, Security+, CEH, or an equivalent qualification
Experience working with cloud environments such as AWS, Azure, or GCP
Exposure to security audits, compliance assessments, or governance programmes
Experience leading cross-functional security initiatives
Background in technology, software, digital services, fintech, e-commerce, or enterprise IT environments
About the company
A technology company providing cloud-based recruitment software to businesses and recruitment teams. Its platform supports recruitment processes through candidate management, workflows, collaboration, and related hiring tools.
#LI-JACTH
#citybangkok