Job Overview:
The IT Governance and Security Manager is responsible for initiating and driving IT/data governance and security initiatives. This role ensures compliance with industry standards and regulatory requirements, enhances security policies, procedures, and controls, and strengthens the organization’s cyber resilience. The IT Governance and Security Manager will work closely with the IT, legal, compliance, data, e-commerce, and other business units to maintain secure and compliant IT systems.
Responsibilities:
1. Cybersecurity & Risk Management
- Design and implement a cybersecurity strategy that aligns with the organization’s overall business strategy
- Conduct regular security risk assessments, vulnerability assessments, and penetration testing to evaluate the organization’s cyber defenses; and design and implement security risk mitigation strategy and programs
- Lead and coordinate response activities in case of security incidents, including investigation, mitigation, and post-incident analysis
2. Compliance & Regulatory Management
- Ensure compliance with relevant laws, regulations, and standards (e.g., PDPA)
- Implement and lead the initiatives for security and compliance audit certifications, including Cyber Trust Mark, ISO 27001, and other certificates
- Suggest, implement, and oversee continuous monitoring of IT security systems and tools
- Work with the legal and data protection teams to implement policies and controls to protect sensitive and personal data
3. IT Governance
- Establish and maintain an IT governance framework, policies, and processes that align with the organization’s business objectives, and ensure compliance with legal, regulatory, and industry requirements
- Collaborate with management, legal, finance, and external auditors to ensure transparency and alignment of governance practices
- Generate and present reports on IT governance performance, compliance status, and risk landscape
4. Data Governance
- Develop and implement data governance policies, ensuring data quality, security, and compliance
- Manage data lifecycle, align data strategy with business objectives, and collaborate with cross-functional teams to enhance data integrity
- Oversee data stewardship, and regulatory adherence, and provide data management best practices for effective decision-making
5. Team Leadership and Development
- Lead and mentor a lean team of IT governance, compliance, and security professionals
- Foster a culture of continuous improvement and knowledge-sharing within the team and business units
Requirements:
- Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related field
- 5+ years of working experience in IT governance, cybersecurity, and compliance, with at least 2 years in a managerial role
- Strong knowledge of IT governance frameworks (e.g., ITIL, COBIT), cybersecurity standards (e.g., ISO 27001, NIST), and regulatory requirements (e.g., PDPA)
- Candidates with basic IT governance and cybersecurity certificates (e.g. CISSP, CISM) will be advantageous
- Team player with strong collaboration skills, able to work effectively with both internal and external teams