Regional Information Security Officer - Governance
MAIN PURPOSE
- Ensuring effective compliance across the enterprise, while maintaining strong governance and operational alignment with external security service providers.
- Conducting risk assessments, developing and maintaining security policies, and reinforcing a culture of compliance and security across the region
KEY RESPONSIBILITIES
- Security Governance & Compliance
- Develop and maintain security policies, standards, and procedures.
- Ensure compliance with regulatory frameworks such as Shiseido Security Framework, ISO 27001, NIST, GDPR, and PDPA.
- Support internal and external audits and manage remediation of findings.
- Risk Management
- Collaborate with IT business partners to conduct risk assessments for upcoming IT projects, ensuring security compliance with global standards.
- Collaborate with IT and application teams to remediate identified risks.
- Maintain a risk register and report on risk posture to senior leadership.
- Security Awareness & Training
- Promote a culture of security awareness through training programs and phishing simulations.
- Provide guidance to business units on secure practices and data protection.
- Reporting & Documentation
- Maintain documentation information security policies and procedures.
- Prepare regular reports on security metrics, incident trends, and security rating system
- Security Innovation & Trends
- Monitor emerging threats and technologies.
- Recommend strategic investments in security innovation.
- Ad hoc Support
- Additional information security-related tasks given by the supervisor or management team
REQUIREMENTS
- Bachelor’s degree in information security, Computer Science, or related field.
- 5+ years of experience in cybersecurity operations, with at least 2 years in vendor management.
- Hands-on experience with security frameworks, policies, and audit processes
- Familiarity with enterprise risk management and corporate governance practices.
- The position requires regular communication and collaboration with stakeholders across the APAC region, where English is the primary business language.
- Clear communicator with both technical and non-technical audiences
- Certifications such as CISSP, CISM, GIAC, or ISO 27001 Lead Implementer preferred.
- Ability to travel within the APAC region as needed.
Job Segment:
Compliance, Risk Management, Law, Legal, Finance