Assoc. Director - Country Information Security Officer
THAILAND
Job description
Nice to Know:
Being in a team of the Company information security (ISO-Information Security Officer). ISO communicates directly and regularly with the Regional and Group Information Security Officer and may be a member of the Information Security Core Group. The ISO must rely on suitable budget in order to meet their responsibilities which include: Ensure that the GISF (Group Information Security Framework) and the Company specific information security requirements are fulfilled; especially by governing the implementation of the GISF and monitoring and reviewing the resulting processes and mechanisms.
Your Day at Allianz Ayudhya:
- Define and enable the Company specific action plans to attain and maintain compliance to minimum requirements, security standards and OE specific requirements
- Advise the Company management in all information security related issues, regularly report about the information security status to the Company management
- Liaise with and report to the Regional/Group Information Security Officer
- Communicate applicable corporate rules relevant to Information Security in coordination with the Company management
- Prepare the Compliance Report for GISF for the Company Management team
- Govern investigations of information security incidents and escalate to the Group Information Security Officer based on incident severity
- Immediately escalate to Regional/Group ISO and the Company Management team identified breach of the requirements from the GISF
- Ensure that security Service Level Agreements including controls are defined and monitored for used IT services or IT services provided to another related Company
- In respect to these responsibilities the ISO must have a local reporting line (e.g. by regular information meetings, reports) to the Company Chief Operating Officer
- Advise the ISO in all information security related issues, regularly report about the information security status to the ISO
- In respect to these responsibilities the information security team must have a local reporting line (e.g. by regular information meetings, reports) to the ISO
- Other security related matters upon assignments
Must Have:
- Professional experience in Information Security field at least 5 years
- Bachelor’s degree in computer Engineering related field or equivalent
- Statistical report and systematic thinking
- Technical & professional and consulting skills
- Project planning and monitoring
- Very good business English communication
- CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional is an advantage
- Any AI-future skills e.g., ChatGPT, or CoPilot365, will be advantage.