J
Posted 4d agoNawamin, Bangkok, Thailand

GRC and Supplier Assurance

MiddleOn-site (Nawamin)Salary undisclosed
Job Description

We are looking for a professional who can balance exceptional delivery for customers on what matters, engaging teams and colleagues, with the needs of the business. This role is often the first layer of management of people or projects.

Responsibilities:

•Understand and interpret requirements across relevant IT Risk, Cybersecurity, Regulatory and map requirements against the organization’s technology and security policies, standards and control

•Develop, establish, maintain, and continuously improve the organization’s Information Security Policies, Standards and Guidelines ensuring alignment with business requirements, regulatory obligations, and industry best practices.

•Conduct Technology Risk Assessments across applications, infrastructure, products, projects, and operations. Identify risks and control gaps, recommend appropriate remediation or mitigating controls, and track risks through closure or formal risk acceptance.

•Manage the Risk Acceptance process, ensuring exceptions have appropriate business justification, compensating controls, accountable risk owners, defined expiry dates, and periodic review.

•Coordinate with internal audit, external audit and other stakeholders to support audit and assessment, provide the information as audit request and regular report status to IT and Security management.

•Define and monitor Security KPIs, KRIs, compliance metrics, and management dashboards to measure control effectiven

Similar Openings in Other

View all in category