About the Company
BankX is committed to building a secure digital banking environment that fosters customer trust and supports growth. Our mission is to leverage cutting-edge technology while ensuring the highest standards of cybersecurity.
About the Role
Reporting directly to the CEO and Board, the CISO will own BankX's cybersecurity strategy, governance, and operations — building the security foundation that enables safe digital banking growth and sustains customer trust at scale.
Responsibilities
Cybersecurity Strategy & Leadership
- Define and own BankX's enterprise cybersecurity strategy, aligned to business and digital transformation goals
- Act as the primary security advisor to the CEO, Board, and Executive Committee
- Establish security frameworks, policies, and standards that scale with the organisation
- Build and lead a high-performing cybersecurity team; embed a culture of security awareness across the bank
Risk Management & Governance
- Identify, assess, and manage cyber risks across all business domains in line with BankX's risk appetite
- Provide regular reporting to the Board on risk posture, threat landscape, and key metrics
- Maintain a robust governance framework that supports regulatory compliance and business confidence
Compliance & Business Resilience
- Ensure full compliance with Bank of Thailand (BOT) regulations, Thailand's PDPA, and global standards (ISO 27001, NIST, PCI-DSS)
- Lead Business Continuity Management (BCM) and Disaster Recovery (DR) planning and testing
- Monitor and respond proactively to the evolving regulatory landscape in Thailand and internationally
Security Operations & Incident Response
- Oversee the Security Operations Centre (SOC), threat intelligence, and cyber defend programs
- Lead incident response planning and execution; ensure clear stakeholder communication during incidents
- Drive ongoing vulnerability management and penetration testing activities
Technology & Platform Security
- Secure BankX's cloud infrastructure (Microsoft Azure), APIs, data platforms, and customer-facing applications
- Embed security into DevSecOps pipelines and the software development lifecycle
- Govern identity and access management, data classification, and AI/ML security practices
- Partner with Technology and Product teams to make security a business enabler
Qualifications
Essential:
- 10+ years of progressive cybersecurity leadership experience
- Prior experience in banking, financial services, or fintech strongly preferred
- Proven expertise in cloud security (Azure preferred), risk management, and incident response
- Demonstrated knowledge of Thailand's regulatory environment: BOT guidelines and PDPA
- Ability to communicate complex security topics clearly to Board-level and non-technical audiences
- Track record of building and leading high-performing security teams
- Strong understanding of modern threats, zero-trust architecture, and AI/ML security considerations
Preferred Skills:
- CISSP – Certified Information Systems Security Professional
- CISM – Certified Information Security Manager
- CISA – Certified Information Systems Auditor
- CCSP – Certified Cloud Security Professional
Languages
- Fluency in English required; Thai language skills advantageous
Equal Opportunity Statement
BankX is committed to diversity and inclusivity in the workplace. We encourage applications from all qualified individuals regardless of race, gender, age, sexual orientation, disability, or any other characteristic protected by law.