ตำแหน่งงาน
ที่ไหน

18,236 ตำแหน่ง

กลับไปยังหน้าหางาน
อัพโหลด CV ของคุณ

เราจะใช้ AI อ่าน แล้วช่วยหาโอกาสที่ใช่ให้คุณ

คลิกเพื่ออัพโหลด หรือลากไฟล์มาวาง · PDF, DOC, DOCX · ไม่เกิน 10 MB

DHL eCommerce

Information Security Manager

ประกาศจากแหล่งภายนอก
DHL eCommerce
เทคโนโลยี
กรุงเทพมหานครทำงานที่ออฟฟิศลงประกาศ 69 วันที่แล้ว
สมัครที่เว็บไซต์บริษัท

คุณสมัครได้โดยตรง — เราจะพาคุณไปยังหน้าสมัครงานของบริษัท ไม่ต้องสมัครสมาชิก ไม่มีคนกลาง ไม่ต้องล็อกอิน ThaiJobz

รายละเอียด
เงินเดือนตามตกลง
ประเภทการจ้าง
เต็มเวลา
รูปแบบ
ทำงานที่ออฟฟิศ

รายละเอียดงาน

About the Company

Welcome to DHL eCommerce! We provide international and domestic parcel delivery and selected fulfillment services across more than 35 countries. As part of the DHL Group, we design e-commerce logistics solutions leveraging a global network and technology to support customers in the APAC region.

About the Role

You are a Security Professional with a solution mindset and strong understanding of security architecture, risk management and security governance. This role defines, maintains and enforces security standards and validates security controls through hands-on security testing (penetration testing, DAST and SAST). You will be based in Bangkok, TH and be part of the Information Security team for DHL eCommerce APAC responsible for IT systems and applications used by Thailand, Malaysia and Australia.

Responsibilities

  • Perform security testing (Pentest, DAST and SAST) of selected business-critical in-house web and mobile applications.
  • Own and lead end-to-end coordination of security testing by collaborating with testing teams, application development teams and product owners.
  • Work closely with the Regional Information Security Officer (RISO) to implement the Information Security mandate in APAC.
  • Consult as SME on assessment of new applications/projects introduced to the APAC IT landscape.
  • Track and report security risks, metrics and remediation progress to stakeholders.
  • Facilitate and lead post-test discussions and triage sessions, providing security inputs to testing and IT project teams.
  • Assist in vendor security assessments and represent InfoSec in weekly change review meetings.
  • Maintain records of security activities for audits and contribute to periodic security reporting.
  • Manage information security management processes, standards and procedures to ensure control effectiveness and compliance.
  • Collaborate with external security service providers to secure and ensure compliance of cloud environments (DPDHL ISTM/Cloud standards).
  • Support security awareness initiatives across APAC and apply industry-standard methodologies and frameworks.

Qualifications

  • At least 12 years of industry experience with strong background in information security testing and GRC (Governance, Risk Management and Compliance).
  • Hands-on experience with penetration testing, DAST and SAST tooling and market trends.
  • Sound understanding of secure application and system development, cloud security and security project management.
  • Demonstrated capability in risk management to support regional risk functions.
  • Familiarity with business continuity, disaster recovery, security operations and incident management.
  • Working familiarity with cybersecurity standards and frameworks (e.g., ISO27000 family, OWASP Top 10).
  • Ability to review cloud security configuration for MS Azure and AWS and guide application teams on hardening measures.
  • Industry-recognized certifications (CompTIA Security+, CISM, CRISC, CISSP, etc.).
  • Verbal and written proficiency in English and ability to work in a regional setup with remote stakeholders.
  • Self-starter mindset with ability to own end-to-end assignments and deliver with minimal supervision.

Additional Information

  • Location: Bangkok, Thailand (onsite).
  • Employment type: Full-time.

คุณสมบัติผู้สมัคร

ประสบการณ์
มากกว่า 10 ปี
การศึกษา
ไม่ระบุ
ใบรับรอง / ทักษะเพิ่มเติม
Information SecurityRisk ManagementSecurity GovernancePenetration TestingDASTSASTCloud SecuritySecurity TestingApplication DevelopmentSecurity AwarenessIncident ManagementBusiness ContinuityDisaster RecoveryCybersecurity Best PracticesISO27000

เกี่ยวกับบริษัท