Description for Technical Information Security Officer
1. Provide guidance to Business Services Group (BSG) in ensuring that projects/systems comply with security policies and the relevant legal and regulatory frameworks (such as PDPA or Cybersecurity Act) throughout the product lifecycle
2. Perform adequate risk management, including identification, assessment and provide treatment of security risks associated with systems handled by Business Services Group. Risk assessment must be performed in accordance with the organization’s cybersecurity risk management framework
3. Provide guidance to Business Services Group related to vulnerability assessments, source code review and penetration tests so that remediation actions can be undertaken by Business Services Group within the agreed timelines
4. Provide security consulting and advisory to Business Services Group
5. Review RFP proposal compliance with security requirements
6. Review architecture design developed by Enterprise/Solution/Security Architect
7. Perform cybersecurity assurance activities across the different stages of SDLC
8. Evaluate risks related to third-party vendor and products and identify mitigating measures
9. Perform independent assessments of the technical security controls implemented within the projects/systems to determine the overall effectiveness of the controls
Qualification and Requirement
1. Degree in Computer Science, Information Systems, Engineering or equivalent
2. At least 10 years of IT security experience in areas of security governance, risk management, application security design, security project management, security operation, cloud security technologies
3. Strong risk management principles, risk articulation skills, cloud technologies, network security, data protection
4. Knowledge of cloud platforms such as AWS, Azure or Google cloud is desirable
5. Professional security certification is preferable, such as CISSP, CISM, CISA, CCSP or other similar security certifications
6. Self-motivated with the ability to work independently and as a team member with minimal direction
7. Strong interpersonal and stakeholder management skills
8. Good written and communication skills