Regional Information Security Officer - Governance

Date:  Aug 19, 2026
Location:  Ho Chi Minh
Company:  Shiseido

MAIN PURPOSE

  • Ensuring effective compliance across the enterprise, while maintaining strong governance and operational alignment with external security service providers.
  • Conducting risk assessments, developing and maintaining security policies, and reinforcing a culture of compliance and security across the region

 

KEY RESPONSIBILITIES

  • Security Governance & Compliance
    • Develop and maintain security policies, standards, and procedures.
    • Ensure compliance with regulatory frameworks such as Shiseido Security Framework, ISO 27001, NIST, GDPR, and PDPA.
    • Support internal and external audits and manage remediation of findings.
  • Risk Management
    • Collaborate with IT business partners to conduct risk assessments for upcoming IT projects, ensuring security compliance with global standards.
    • Collaborate with IT and application teams to remediate identified risks.
    • Maintain a risk register and report on risk posture to senior leadership.
  • Security Awareness & Training
    • Promote a culture of security awareness through training programs and phishing simulations.
    • Provide guidance to business units on secure practices and data protection.
  • Reporting & Documentation
    • Maintain documentation information security policies and procedures.
    • Prepare regular reports on security metrics, incident trends, and security rating system
  • Security Innovation & Trends
    • Monitor emerging threats and technologies.
    • Recommend strategic investments in security innovation.
  • Ad hoc Support
    • Additional information security-related tasks given by the supervisor or management team

 

REQUIREMENTS

  • Bachelor’s degree in information security, Computer Science, or related field.
  • 5+ years of experience in cybersecurity operations, with at least 2 years in vendor management.
  • Hands-on experience with security frameworks, policies, and audit processes
  • Familiarity with enterprise risk management and corporate governance practices.
  • The position requires regular communication and collaboration with stakeholders across the APAC region, where English is the primary business language.
  • Clear communicator with both technical and non-technical audiences
  • Certifications such as CISSPCISMGIAC, or ISO 27001 Lead Implementer preferred.
  • Ability to travel within the APAC region as needed.
Salary (Min-Max): 


Job Segment: Compliance, Risk Management, Law, Legal, Finance