IT GRC & Privacy Manager (Acting DPO)
ประกาศจากแหล่งภายนอกPlan B Media Public Company Limited
เทคโนโลยี
ทำงานที่ออฟฟิศลงประกาศ 62 วันที่แล้ว
สมัครที่เว็บไซต์บริษัท
คุณสมัครได้โดยตรง — เราจะพาคุณไปยังหน้าสมัครงานของบริษัท ไม่ต้องสมัครสมาชิก ไม่มีคนกลาง ไม่ต้องล็อกอิน ThaiJobz
รายละเอียด
เงินเดือนตามตกลง
ประเภทการจ้าง
เต็มเวลา
รูปแบบ
ทำงานที่ออฟฟิศ
รายละเอียดงาน
About the Role
Plan B Media Public Company Limited — IT GRC & Privacy Manager (Acting DPO). Combined IT GRC and Data Protection Officer duties with clear independence boundaries under PDPA.
Responsibilities
- IT Risk & Compliance: Maintain IT Risk Register and Risk Heat Map (quarterly review); own IT Control Framework aligned to ISO 27001 Annex A; coordinate internal and external audits and keep an audit-ready evidence repository; draft and maintain IT policies (Security, Access Management, Acceptable Use, Change Management, Incident Response, BCP); run periodic control testing including access reviews, change management sampling, and backup-restore validation.
- Vendor & Third-Party Risk: Conduct security and privacy due diligence on new vendors and SaaS tools; maintain Vendor Risk Register with criticality tiering and review cycles; review security and privacy clauses in contracts with Legal.
- PDPA / Privacy (DPO duties): Serve as designated DPO per PDPA s.41 — inform, advise, and monitor compliance; maintain Records of Processing Activities (ROPA) for controllers and processors; operate Data Subject Request (DSR) workflow within PDPA timelines (30 days, extendable to 60 days); conduct Data Protection Impact Assessments (DPIAs) for new systems, products, and high-risk processing including AI/ML; maintain cross-border transfer mechanisms (SCCs, adequacy decisions, consent frameworks); review and negotiate Data Processing Agreements (DPAs) with processors; lead privacy breach response with Security and notify PDPC within 72 hours when required; act as point of contact for data subjects and PDPC.
- AI Governance (cross-functional): Permanent member of the AI Governance Council; review lawful basis, data minimization, and retention for data used in AI model training; assess privacy and security risks in LLM and RAG implementations.
- Reporting, Awareness & Training: Deliver quarterly IT Risk & Privacy reports to CIO, Audit Committee, and Board; produce monthly KRI/KPI dashboard (open risks, overdue remediations, audit findings aging, DSR backlog); lead annual PDPA and security awareness training for all employees.
Qualifications
Education
- Bachelor's degree or above in IT, Computer Science, Law, Accounting, or related field; LLM or Master's in IT Law / Data Protection is an advantage.
Experience
- 5–8 years in IT Audit, IT GRC, Information Security, or Privacy with depth in at least one domain; core: 5+ years in IT Audit, IT GRC, InfoSec Management, or Privacy/Compliance.
- GRC track: experience participating in or leading ISO 27001 program, internal audit, or risk assessment cycles.
- Privacy track: working knowledge of PDPA B.E. 2562, DSR obligations, and DPIA methodology.
- Preferred: Big 4/consulting background or in-house compliance/IT security experience at regulated industries (banking, insurance, media, tech).
- Business-level fluency in Thai and English (both required for PDPC communication).
Certifications
- At least one active certification required; commitment to obtain a second within 18 months. Accepted certifications include: CISA, CISM, CRISC, CIPM, ISO 27001 Lead Auditor/Lead Implementer, CDPSE.
Skills / Technical Skills
- PDPA compliance, DPIAs, ROPA and DSR workflow management.
- ISO 27001-aligned control frameworks, audit coordination and control testing.
- Vendor security & privacy due diligence; DPA and contract clause review.
- AI model data governance (LLM / RAG) and privacy risk assessment.
- Monthly KRI/KPI dashboarding and reporting to senior stakeholders.
Additional Information
- CRITICAL INDEPENDENCE BOUNDARY: Under PDPA Section 42 the DPO must act independently. The role-holder must never be assigned: ownership of any system that processes personal data; operational responsibility for Marketing Data, HR Data, or Customer Data; sign-off authority on DPIAs they authored; approval of audit findings that assess their own work.
คุณสมบัติผู้สมัคร
- ประสบการณ์
- 6-10 ปี
- การศึกษา
- ไม่ระบุ
ใบรับรอง / ทักษะเพิ่มเติม
IT Risk ManagementComplianceData ProtectionPrivacy ManagementISO 27001Audit CoordinationVendor Risk ManagementData Subject RequestsData Processing AgreementsPrivacy Breach ResponseAI GovernanceTraining and AwarenessRisk AssessmentPolicy DevelopmentSecurity Management
เกี่ยวกับบริษัท
Plan B Media Public Company Limited
www.linkedin.com/company/plan-b-public-company-limited