JOB PURPOSE
To lead the development, implementation, and continuous improvement of cvbersecurity policies, rules, and frameworks that govern the organization's digital security posture. The role includes managing compliance with regulatory standards, supporting incident response, and collaborating across departments to ensure robust protection mechanisms are in place. The analyst will also mentor junior staff and contribute to strategic security initiatives
KEY RESPONSIBILITIES
1. Policy & Framework Development
- Design, implement, and maintain cybersecurity policies, standards, and frameworks aligned with industry best practices and regulatory requirements (e.g., ISO 27001, PDPA, CIS)
- Lead periodic reviews and updates of security documentation to reflect evolving threats and technologies
- Develop protection mechanisms and controls to safeguard systems, applications, and data
2. Incident Response & Collaboration
Serve as a key member of the Incident Response Team, supporting investigation, containment, and recovery effortsCollaborate with SOC, governance, and IT teams to ensure alignment of security controls and incident handling procedures3. Team Leadership & Awareness
Lead and mentor junior analysts in the Security Rules and Framework teamConduct security awareness training and promote a culture of cybersecurity across the organization4. Technology Oversight
Oversee the secure configuration and operation of security technologies including firewalls, SWG, NGAV, IDS / IPS, WAF, and Email GatewaysMonitor and evaluate the effectiveness of implemented controls recommend improvements5. Project Management
Understanding of security best practices, administration and governance of the provided services including identify and evaluate security gaps and will help to create security project plansParticipate in evaluate, implement, maintain, and support IT Security related systems / devices / projectsJob Challenge
Balancing strategic policy development with hands-on technical oversightEnsuring compliance while adapting to rapidly changing threat landscapesCoordinating across departments and managing stakeholder expectationsWORKING CONDITION
Work on-premises and cloud-based infrastructureMay require extended hours during audits, incidents, or major implementationsDynamic, multicultural environment requiring strong interpersonal and communication skillsWORKING EXPERIENCE
Minimum 5 years in cybersecurity, with strong exposure to policy, compliance, and technical controlsDemonstrable experience in network security management and authorization approaches (role-based access control, direct entitlements-based) specific to SWG, NGAV, Firewall, IDS / / PS, WAF, Network TAP & Email GatewayTechnically competent and kept abreast with network security architecture best practices, standards and frameworks.Broad-based working knowledge of IT Platform, identity federation, networking, application, database, infrastructure and / or server administrationAbility to constantly monitor, detect, and evaluate events which may impact monitored assets, to increase situational awareness of cloud security events that threaten the operations of the networks or systems.Experience in identifying and documenting, tracking and remediating IT audit risks, security risk assessment, assessing IT risk, designing IT controls, business process controls.QUALIFICATION
Bachelor's degree in Computer Science, Information Systems, or related fieldPreferred certifications include CISSP or CISM, ISO 27001 Lead Implementer, or equivalentStrong understanding of security frameworks, risk management, incident response, and technical controls