Principal Information Security Officer
ประกาศจากแหล่งภายนอกคุณสมัครได้โดยตรง — เราจะพาคุณไปยังหน้าสมัครงานของบริษัท ไม่ต้องสมัครสมาชิก ไม่มีคนกลาง ไม่ต้องล็อกอิน ThaiJobz
รายละเอียดงาน
About the Role
As a Local Information Security Officer (ISO) at Allianz Technology Thailand, you will drive the implementation and evolution of the Allianz SE Group and Technology Information Security Framework and related guidelines, ensuring compliance and providing control assurance for services offered to customers and consumed by the hub. The role also covers Digital Resilience activities including IT risk identification and management, implementation of controls and compliance, ITOM, assurance activities and TPRM coordination.
Responsibilities
- Information Security Officer (ISO 70-80%): Drive implementation of and ensure compliance with Group-wide standards, regulatory requirements and industry security standards (including Global information security framework assessment, Global functional rule assessment, DORA, NIS2) in all Allianz Technology services and projects.
- Oversee the compliance reporting process for local entities; assess and address deviations from security policies and contractual security provisions and develop strategies to mitigate identified information security risks.
- Lead local Information Security Steering Boards and support preparation of Information Security action plans; implement actions under the LISO's responsibility and proactively manage follow-up measures.
- Support local executive body in regulatory Information Security-related governance requirements and ensure IS governance documents are ratified by local entity management; follow up on implementation.
- Serve as local contact point for information security matters, liaise with business, partners, customers and safeguarding functions, and provide information security consulting to stakeholders.
- Systematically assess effectiveness of security controls in services provided by Allianz Technology, partners and third-party providers; drive Security Risk Management and lifecycle of security risk assessments.
- Ensure all IS deviations (IS risks) are reported in the GRC tool and managed per the information security risk management process.
- Promote awareness of Allianz Technology security requirements and processes; manage local roll-out of global information security trainings and monitor/report attendance.
- Engage with senior stakeholders and provide regular, high-impact reports to regional management, the Allianz Technology Thailand Board of Directors and the Board of Management of Allianz Technology.
- Regularly exchange with and contribute to the regional and global Allianz Technology ISO community and support the annual IT compliance reporting process for the local entity.
- Digital Resilience Officer (DRO 20-30% capacity): Coordinate implementation and maintenance of digital resilience and IT risk management for the Allianz Technology branch/local entity. Reports functionally to AZT Head of Digital Resilience and disciplinarily to Head of Branch Operations.
- Establish and maintain effective digital risk controls integrated into operational processes; lead digital risk identification, assessment and management across applications and services.
- Ensure digital risks are managed in line with the DIRM framework and monitored within defined timelines (within 30 days); participate in the local Risk Council and report on local digital risks.
- Strengthen digital risk management relationships with customers and act as local coordination point across safeguarding functions; participate in Central DR sessions and engage with global risk communities.
- Conduct TPRM assessments for all services and contracts; ensure documentation of active contracts in line with DORA, compliance with tiering outcomes and mandatory clauses, maintain D&O trackers, and ensure approved exit strategies and validated BCDR plans are in place.
- Coordinate responses to customer audits, support AzTech internal audits relevant for COO function, and support Assurance and Risk Shield activities.
- Ensure ITOM compliance and adherence to regulatory requirements; conduct compliance benchmarking across branches and follow up prior-year risks and ATPIT deviations.
- Deliverables & Timelines: perform annual IT compliance self-assessment (by 30 Sept.), ensure remediation gaps are logged and tracked (by 30 Nov.), and provide quarterly IT risk reporting to Central.
Qualifications
- Bachelor or master degree in Computer or Information Technology or related field.
- Recognized Information Security certifications preferred, e.g., CISSP, CISA, CISM, CRISC, PCI DSS or ISO27001 Lead Auditor.
- 8+ years of experience in information security, information risk management, controls assurance & compliance programs.
- Experience with internal controls, ris
สวัสดิการที่ได้รับ
คุณสมบัติผู้สมัคร
- ประสบการณ์
- มากกว่า 10 ปี
- การศึกษา
- ไม่ระบุ
