Senior Cyber Security Engineer (ถนนเพชรบุรีตัดใหม่)
1 Security Architecture & Engineering •Design, plan, and continuously improve the security architecture of networks, servers, cloud environments, and applications in line with international standards such as ISO 27001 and the NIST Cybersecurity Framework. •Install, configure, and manage security tools and infrastructure, including firewalls, IPS/IDS, WAF, EDR/XDR, SIEM, DLP, and proxy solutions. •Evaluate and select new security technologies and solutions to strengthen the organization's defenses against evolving threats. •Define security architecture for cloud environments (IaaS, PaaS, SaaS). 2 Security Analysis •Analyze security events and anomalies through SIEM/SOC platforms on a 24x7 basis. •Lead the response to and management of security incidents, from containment through recovery, and produce post-incident reports (RCA / lessons learned). •Develop and maintain the Incident Response Plan, playbooks, and runbooks for various incident types. •Coordinate with digital forensics teams and external parties in the event of major security incidents. 3 Vulnerability & Risk Management •Conduct and/or oversee regular vulnerability assessments and penetration testing. •Analyze assessment results, prioritize risks, and coordinate remediation with relevant teams within agreed timeframes. •Continuously monitor threat intelligence sources and assess their impact on the organization. 4 Policy, Governance & Compliance •Develop, review, and update cyber security policies, standards, and procedures. •Support and prepare the organization for audits against standards such as ISO 27001, PCI-DSS, and data protection regulations (e.g., PDPA). •Prepare and present security posture reports and KPIs to management and regulators on a regular basis. 5 Team Leadership & Development •Mentor, supervise, and transfer knowledge to junior/mid-level team members, including assigning work and reviewing quality. •Act as project lead for assigned cyber security initiatives, from planning through delivery. •Organize and deliver security awareness training programs for employees across the organization. 6 Other Duties •Liaise with external vendors and managed security service providers (MSSPs) on procurement and maintenance of security systems. •Perform other duties as assigned by management.
Qualifications: Bachelor's degree or higher in Computer Science, Computer Engineering, Information Technology, or a related field. At least 5 years of experience in Cyber Security / Information Security. Experience leading incident response efforts and/or acting as a team lead or project lead is highly preferred. Strong expertise in networking (TCP/IP, routing/switching), operating systems (Windows/Linux), and cloud platforms (AWS/Azure/GCP). Hands-on experience with security tools such as SIEM (Splunk, QRadar), firewalls (Palo Alto, Fortinet, Cisco), EDR/XDR, and vulnerability scanners (Nessus, Qualys). Solid understanding of security standards and frameworks such as ISO 27001, NIST CSF, CIS Controls, and MITRE ATT&CK. Scripting/automation skills (Python, PowerShell, Bash) are a strong plus. Strong analytical, problem-solving, and decision-making skills under pressure. Excellent communication skills, able to engage effectively with both technical teams and senior management. Strong leadership capability, able to manage teams and projects effectively. Good command of English (listening, speaking, reading, writing). Willing to work outside normal hours or be on standby in the event of a security emergency. Preferred Certifications • CISSP, CISM, CEH, CompTIA Security+/CySA+, OSCP, GIAC (GCIH/GCIA), or equivalent