Search Jobs

Search by job, company or skills

Security Analyst

Security Analyst

thai union group pcl.
3-5 Years
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

Thai Union Group PCL

Job Title: Security Analyst

Department: Digital Security

Job Level: Deputy Department Manager (Intermediate - individual contributor)

Location: SM Tower, Thailand, Onsite 5 days (near BTS Sanam Pao)

Employment Type: Full-time, permanent

Job descriptions

1. Digital GRC delivery

  • Support and execute Digital GRC activities across the three pillars — governance, risk and compliance for the Digital area in both IT and OT environments.
  • Take ownership of assigned GRC topics end-to-end, escalating decisions and blockers to the Head of Security where required.

2. Requirement analysis and translation into action

  • Interpret governance requirements, regulations, internal policies, risk findings and compliance obligations arising from applicable standards and frameworks.
  • Translate each requirement into clearly defined action items, specifying the affected business or IT process, the accountable and supporting teams, deliverables and target dates.
  • Coordinate with the responsible teams, track progress against agreed timelines, escalate blockers, and follow each item through to verified closure.

3. Stakeholder coordination

  • Work with internal functions (IT infrastructure, network, application, plant engineering, business units, internal audit, legal, etc.) and external parties (vendors, suppliers, service providers, auditors and certification bodies).
  • Support third-party and vendor security assessments: issue and review security questionnaires, evaluate supporting evidence, and track vendor remediation commitments.
  • Assist with internal and/or external audits, including evidence collection, auditor liaison and follow-up of audit findings to closure.
  • Support the delivery of compliance and certification programs (for example ISO/IEC 27001), including scoping input, control implementation coordination, readiness reviews and surveillance audits.

4. Documentation, policy development, reporting

  • Draft, review and maintain governance documentation within the assigned scope, including policies, standards, procedures, guidelines and control matrices.
  • Prepare and maintain regular risk documentation within the assigned scope, including the risk register, risk assessments, risk treatment plans, risk acceptance records and exception or waiver records.
  • Track and report remediation progress and risk closure status across the responsible teams on a defined reporting cycle.
  • Monitor risk acceptance expiry dates and initiate re-review

5. Contribute to the organisation-wide security awareness program, including quarterly phishing simulation campaigns and the monthly development of awareness content and communications.

Qualifications

  1. Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Information Systems or a related field.
  2. Minimum 3–5 years of experience in a directly or partially related field, such as IT or cybersecurity governance, risk management, compliance, IT audit, information security, or IT operations with a governance/risk/compliance component.
  3. Working knowledge of information security and IT risk management concepts, and familiarity with recognised standards and frameworks.
  4. Ability to communicate in English — reading, writing, listening and speaking — at a level sufficient for effective business communication.
  5. Strong documentation and writing skills, with the ability to produce clear policies, procedures and management reports.

More Info

Key Skills

Risk treatment plans

Risk assessments

Governance risk and compliance

Risk register

IT and OT environments

ISO IEC 27001

Digital GRC

Phishing simulation campaigns