Overview
Information Technology Security Specialist Jobs in Bangkok, Bangkok City, Thailand at DeeMoney
Title: Information Technology Security Specialist
Company: DeeMoney
Location: Bangkok, Bangkok City, Thailand
About DeeMoney
DeeMoney is Thailand’s leading fintech company, simplifying cross-border payments and financial services for individuals and businesses. On our B2B side, we empower Thai SMEs and enterprises with faster, more transparent, and cost-effective money transfer and currency exchange solutions.
Location: Bangkok, Thailand
Department: Product Engineering
Employment Type: Full-time
Key Responsibilities:
Security Strategy & Governance
· Develop, implement, and maintain the organization's information security policies, standards, and procedures.
· Define and manage the security roadmap aligned with business goals and risk appetite.
· Conduct periodic risk assessments and report security posture to senior management.
· Ensure compliance with relevant regulations and standards (e.g., PDPA, ISO 27001, NIST).
Infrastructure & Operations Security
· Oversee and harden network, endpoint, cloud, and application security configurations.
· Manage security tools including firewalls, IDS/IPS, SIEM, endpoint protection, and vulnerability scanners.
· Monitor security alerts and logs; investigate and respond to incidents in a timely manner.
· Coordinate vulnerability assessments and penetration testing; track and remediate findings.
Incident Response & Business Continuity
· Develop and maintain the Incident Response Plan (IRP) and lead response activities during security events.
· Conduct post-incident reviews and implement corrective actions.
· Support Business Continuity Planning (BCP) and Disaster Recovery (DR) efforts from a security perspective.
Awareness & Collaboration
· Design and deliver security awareness training programs for all staff.
· Collaborate with IT, HR, Legal, and business units to embed security into daily operations.
· Manage relationships with third-party vendors and conduct supplier security assessments.
· Serve as the primary point of contact for external security audits and assessments.
Qualifications:
· Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
· 3–6 years of experience in IT security or cybersecurity roles.
· Proven experience managing security in a multi-platform environment (on-premise & cloud).
· Solid understanding of security frameworks (ISO 27001, NIST CSF, CIS Controls).
· Hands-on experience with firewalls, VPN, SIEM, and endpoint protection tools.
· Strong knowledge of networking fundamentals (TCP/IP, DNS, VPN, routing).
· Familiarity with cloud security (AWS, Azure, or GCP).
· Experience conducting risk assessments and writing security policies.
Preferred
· Professional certifications: CISSP, CISM, CompTIA Security+, or equivalent.
· Experience with compliance requirements such as PDPA, GDPR, or PCI-DSS.
· Exposure to DevSecOps practices or secure SDLC.
· Prior experience in a small or growing organization where wearing multiple hats is expected.
Technical Skills
Cybersecurity | SIEM | Log Management | Incident Response | Vulnerability Scanning | Penetration Testing | Firewall | IDS/IPS | Endpoint Protection | Cloud Security | IAM | DLP | Network Security | ISO 27001 | NIST | Security Awareness
Soft skills & Attributes
· Self-driven with the ability to work independently and prioritize effectively.
· Strong analytical and problem-solving mindset.
· Excellent communication skills — able to translate technical risk into business language.
· Pragmatic approach to security, balancing protection with business usability.
· Proactive and adaptable in a fast-changing threat landscape.
· High integrity, trustworthiness, and professional discretion.