GRC and Supplier Assurance

Posted Yesterday
Be an Early Applicant
Nawamin, Bueng Kum, Bangkok, THA
In-Office
Senior level
Marketing Tech • Retail • Software
The Role
Manage information security governance, risk, compliance, policies, audits, supplier assurance, and technology risk assessments. The role maps regulatory and industry requirements to security controls, manages risk acceptance and remediation, coordinates audits, monitors security KPIs and KRIs, and oversees third-party security assessments. It also requires enterprise Identity and Access Management experience and knowledge of ISO 27001, PCI DSS, NIST CSF, and PDPA/PDPL.
Summary Generated by Built In

We are looking for a professional who can balance exceptional delivery for customers on what matters, engaging teams and colleagues, with the needs of the business. This role is often the first layer of management of people or projects.

Responsibilities:

•Understand and interpret requirements across relevant IT Risk, Cybersecurity, Regulatory and map requirements against the organization’s technology and security policies, standards and control

•Develop, establish, maintain, and continuously improve the organization’s Information Security Policies, Standards and Guidelines ensuring alignment with business requirements, regulatory obligations, and industry best practices.

•Conduct Technology Risk Assessments across applications, infrastructure, products, projects, and operations. Identify risks and control gaps, recommend appropriate remediation or mitigating controls, and track risks through closure or formal risk acceptance.

•Manage the Risk Acceptance process, ensuring exceptions have appropriate business justification, compensating controls, accountable risk owners, defined expiry dates, and periodic review.

•Coordinate with internal audit, external audit and other stakeholders to support audit and assessment, provide the information as audit request and regular report status to IT and Security management.

•Define and monitor Security KPIs, KRIs, compliance metrics, and management dashboards to measure control effectiveness, risk exposure, remediation progress, and overall security governance maturity.

•Perform other related duties as assigned


Requirements
  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • 5+ years working in IT filed with a focus on information security or IT audit.
  • Knowledge of ISO27001, PCIDSS and IT security control
  • Exceptional communication, problem solving and cross-group collaboration skills
  • Good command of written and spoken English
  • Ability to present ideas in business-friendly and user-friendly language
  • Extensive experience in implementing and managing enterprise-level Identity and Access Management solutions, ensuring compliance with regulatory requirements and leading cross-functional teams to maintain a secure IAM environment.

Operational skills relevant to this role:

• IT Risk & Compliance Frameworks: ISO 27001, PCI DSS, NIST CSF and PDPA/PDPL – mapping overlapping requirements into one policy and standard set.

• Third-Party & Supplier Assurance: Vendor risk assessment, due-diligence questionnaires, contractual security requirements and ongoing monitoring.

• Governance & Policy Management: Policies, standards and procedures; security steering committees, charters and approval flows.

• Audit & Evidence Management: Internal, external and certification audits; control testing, evidence collection and remediation tracking to closure.

• Risk Reporting & Metrics: KPI/KRI design, risk registers, and vulnerability/pen-test reporting with prioritized remediation.

Skills Required

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field
  • 5+ years of experience working in IT, focused on information security or IT audit
  • Knowledge of ISO 27001, PCI DSS, and IT security controls
  • Exceptional communication, problem-solving, and cross-group collaboration skills
  • Good command of written and spoken English
  • Ability to present ideas in business-friendly and user-friendly language
  • Extensive experience implementing and managing enterprise-level Identity and Access Management solutions
  • Experience ensuring IAM compliance with regulatory requirements and leading cross-functional teams
  • Experience with NIST CSF and PDPA/PDPL frameworks
  • Experience with vendor risk assessments, due-diligence questionnaires, contractual security requirements, and supplier monitoring
  • Experience managing security policies, standards, procedures, steering committees, charters, and approval flows
  • Experience supporting internal, external, and certification audits, including control testing and evidence management
  • Experience designing security KPIs, KRIs, risk registers, and remediation reporting
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Khet Suan Luang, Bangkok
103 Employees

What We Do

Makro PRO is an exciting new digital venture by the iconic Makro. Our proud purpose is to build a technology platform that will help make business possible for restaurant owners, hotels, and independent retailers, and open the door for sellers. Makro PRO brings together the best talent across multi-nationals to transform the B2B marketplace ecosystem. We welcome bold, energetic, and thoughtful people who share our belief in collaboration, diversity, excellence, and putting customers at the heart of our work.

Similar Jobs

Wise Logo Wise

Thailand Country Manager

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
9000 Employees

UL Solutions Logo UL Solutions

Laboratory Technician

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
15000 Employees

Capco Logo Capco

QA Automation Tester (Mobile Banking)

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
6000 Employees

Capco Logo Capco

Data Architect

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Bangkok, Phra Nakhon, Bangkok, THA
6000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account