Overview
Security & Compliance Specialist Jobs in Bangkok City, Thailand at Quantium
Title: Security & Compliance Specialist
Company: Quantium
Location: Bangkok City, Thailand
About the role:
We are looking for a Security & Compliance Specialist to support and continuously improve our information security and compliance program.
The role combines security governance and compliance responsibilities with practical knowledge of Microsoft Azure and Microsoft security solutions.
You will support SOC 2 Type II and GDPR compliance, coordinate audits, maintain policies and evidence, respond to client security questionnaires, and work with internal teams to address security and compliance gaps.
As the role supports international and European clients, strong written and spoken English is required.
What we are looking for:
- A practical and proactive approach to security and compliance.
- Strong judgment when handling sensitive or confidential information.
- Ability to provide accurate and appropriately cautious responses to client security questions.
- Confidence communicating with clients and internal stakeholders in English.
- Ability to balance compliance requirements with practical business and technical considerations.
- Willingness to learn and develop across both compliance and Microsoft security technologies.
Key responsibilities:
- Support ongoing SOC 2 Type II compliance and external audit activities.
- Coordinate audit evidence collection, control reviews, and remediation follow-up.
- Support GDPR compliance, privacy assessments, and data protection requirements.
- Prepare and maintain security policies, procedures, risk registers, control records, and compliance documentation.
- Complete client security and compliance questionnaires accurately and professionally.
- Participate in client meetings and explain the company’s security and compliance controls in English.
- Conduct security risk assessments, access reviews, vendor reviews, and control assessments.
- Track security findings, compliance gaps, risks, and remediation actions through completion.
- Coordinate security and compliance activities with Engineering, DevOps, HR, Operations, and other internal teams.
- Support security awareness training, incident response exercises, business continuity, and disaster recovery testing.
- Review and improve security controls across Microsoft Azure and Microsoft 365.
- Support identity and access management activities using Microsoft Entra ID, including MFA, Conditional Access, RBAC, and access reviews.
- Support device security and compliance policies using Microsoft Intune.
- Support data protection and Data Loss Prevention controls using Microsoft Purview.
- Review security findings and recommendations from Microsoft Defender, Defender for Cloud, and related monitoring tools.
- Stay informed about relevant changes to security, privacy, and compliance requirements.
Qualifications:
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Information Systems, or a related field.
- Approximately 3–5 years of experience in information security, IT compliance, IT audit, governance, risk management, or a related role.
- Practical experience supporting SOC 2 Type II, GDPR, ISO 27001, or similar security and privacy frameworks.
- Experience preparing audit evidence, security policies, risk assessments, or client security questionnaires.
- Good understanding of security governance, risk management, identity and access management, data protection, incident response, and business continuity.
- Practical knowledge of Microsoft Azure and Microsoft security solutions.
- Familiarity with Microsoft Entra ID, Intune, Purview, Defender, or Defender for Cloud.
- Strong written and spoken English, with the confidence to participate in client meetings.
- Strong analytical, documentation, communication, and problem-solving skills.
- Good attention to detail, ownership, and ability to follow issues through to completion.
- Ability to communicate security and compliance requirements to both technical and non-technical stakeholders.
Preferred qualifications:
- Experience working in a SaaS, cloud, financial technology, or regulated business environment.
- Experience supporting international or European clients.
- Familiarity with Microsoft Sentinel, vulnerability management, penetration testing, and third-party risk management.
- Relevant certifications in information security, IT audit, risk, compliance, ISO 27001, or Microsoft cloud security would be an advantage.