Ensuring effective compliance across the enterprise, while maintaining strong governance and operational alignment with external security service providers.
Conducting risk assessments, developing and maintaining security policies, and reinforcing a culture of compliance and security across the region
Key Responsibilities
Security Governance & Compliance
Develop and maintain security policies, standards, and procedures.
Ensure compliance with regulatory frameworks such as Shiseido Security Framework, ISO 27001, NIST, GDPR, and PDPA.
Support internal and external audits and manage remediation of findings.
Risk Management
Collaborate with IT business partners to conduct risk assessments for upcoming IT projects, ensuring security compliance with global standards.
Collaborate with IT and application teams to remediate identified risks.
Maintain a risk register and report on risk posture to senior leadership.
Security Awareness & Training
Promote a culture of security awareness through training programs and phishing simulations.
Provide guidance to business units on secure practices and data protection.
Reporting & Documentation
Maintain documentation information security policies and procedures.
Prepare regular reports on security metrics, incident trends, and security rating system
Security Innovation & Trends
Monitor emerging threats and technologies.
Recommend strategic investments in security innovation.
Ad hoc Support
Additional information security-related tasks given by the supervisor or management team
Requirements
Bachelor's degree in information security, Computer Science, or related field.
5+ years of experience in cybersecurity operations, with at least 2 years in vendor management.
Hands-on experience with security frameworks, policies, and audit processes
Familiarity with enterprise risk management and corporate governance practices.
The position requires regular communication and collaboration with stakeholders across the APAC region, where English is the primary business language.
Clear communicator with both technical and non-technical audiences
Certifications such as CISSP, CISM, GIAC, or ISO 27001 Lead Implementer preferred.
Ability to travel within the APAC region as needed.