Overview
Information Technology Security Manager (Insurance) Jobs in Bangkok City, Thailand at Phillip Life Assurance
Title: Information Technology Security Manager (Insurance)
Company: Phillip Life Assurance
Location: Bangkok City, Thailand
Roles & Responsibilities:
Security Operation
- Manage security system relate operation include DDEI and TrendMicro
Security incident Response
- Manage and respond to security alerts, incidents, and breaches from SOC
Security Inspection
- Identify vulnerabilities in the current network and server infrastructure, and collaborate with IT to ensure timely remediation
- Performing penetration tests to find any flaws on website and collaborate with IT to ensure timely remediation
- Review and validate system hardening and baseline configurations, working with IT to ensure prompt remediation
Response IT Audit
- Conduct Reporting Findings. Document and report audit findings, recommendations, and follow-up actions
- Collaborate with Teams: Work with IT and related teams to address identified issues.
- Response audit finding from OIC including Annual OIC IT Audit, CRAF, IT Environment Survey and Electronic Registration and Certificate
- Response audit finding from external IT audit
- Performing account review on AD
- Conduct high privilege account review.
Cybersecurity Awareness and Training
- Maintain Security awareness and security training video for new staff
- Annual security awareness and training programs for all staffs
- Security awareness and training for individuals who clicked on links during the cyber drill
- Develop Training Programs: Create training materials and programs related to IT security
- Promote a Security Culture: Foster a culture of security awareness within the organization through ongoing education
Information Security Management System (ISMS)
- Maintain, document control and publish up-to-date IS Policy, Procedure and form
- Documentation Control. Maintain an organized documentation system for all ISMS-related documents
- Facilitate management reviews of the ISMS
- Implement a continuous improvement process to enhance the ISMS based on audit findings audit findings
Required Skills
- Cybersecurity vulnerability assessment and remediation
- Penetration testing coordination
- IT audit and regulatory compliance management
- Active Directory and privileged access review
- Security awareness and phishing simulation programs
- IT risk assessment and third-party risk management
- KRI monitoring and reporting
- Information Security Management System (ISMS) governance
- Security policy and documentation management
- Cross-team collaboration and security culture promotion