Team lead of Business Security and Resilience
Indexed description
Highlights
- Fixed bonus and performance bonus
- Hybrid Working and remote teaming
- Work from Anywhere
- Equality Welfare & Benefit (LGBTQA+)
- Global online training modules to personalized learning journey
- International Opportunities for Career Growth
- Community Support with Employee well-being resource groups
At Generali Thailand
We celebrate diversity and believe that different perspectives make us stronger. For this role, strong Thai communication skills are essential because you will work closely with our local team and collaborate on daily operations.
We are looking for someone who can:
- Speak and understand Thai confidently (reading and writing are not required)
- This requirement ensures smooth communication and effective teamwork. While we embrace diversity in all other aspects, this language skill is critical to the success of the role.
About the Role
We are seeking an experienced Head of Business Security and Resilience to lead and oversee Cyber Security, Physical Security, and Business Resilience across the organization. This role is responsible for ensuring compliance with Generali policies, regulatory requirements, and industry standards while strengthening the organization’s ability to prevent security threats, manage crises, and maintain business continuity.
Key Responsibilities
Cybersecurity (60%)
- Lead and oversee the successful implementation of security programs aligned with regulatory requirements, Group Security Strategic Plans, and industry standards.
- Conduct ongoing assessments of security controls and drive remediation and improvement plans for identified gaps.
- Develop and deliver security awareness initiatives through e-learning, briefings, communications, and alerts.
- Coordinate, monitor, and respond to security threats, alerts, and incidents in collaboration with regional Incident Response Teams.
- Ensure security requirements are defined, documented, tested, and delivered across projects, including application, cloud, and data security.
- Support ongoing security service monitoring, including WAF and incident response services.
- Implement and monitor third-party security management processes.
- Support customer assurance activities and Group customer security requirements.
- Lead cyber risk management activities, including cyber risk assessments, digital risk reviews, risk committee reporting, and ad hoc risk requests.
- Manage compliance-related activities, including assessments, questionnaires, gap analyses, and regulatory reviews.
- Support engagements with regulators, including OIC and SEC meetings, assessments, hearings, and regulatory submissions.
- Monitor and investigate data security incidents and risks.
- Drive proactive data security improvements by identifying and mitigating business-related data risks.
- Support internal, external, financial, and regulatory audits, including annual IT risk audits and e-commerce application certification activities.
- Provide security reporting and management updates to the Board of Directors, Executive Committee, IT Steering Committee, Regional, and Group stakeholders.
Key Results Areas
- Compliance with Group and industry policies
- Cyberattack prevention
Business Resilience (30%)
- Develop, maintain, review, and enhance business recovery plans and procedures.
- Conduct risk assessments across business functions to evaluate the impact of potential disruptions, including natural disasters, security breaches, legal claims, and market events.
- Collaborate with IT teams to establish data and system protection and recovery best practices.
- Design and implement recovery strategies that enable business operations to continue during infrastructure disruptions.
- Create and facilitate disaster recovery and business continuity exercises.
- Develop and deliver training programs on business continuity, disaster recovery, and risk management.
Key Results Areas
- Compliance with Group and industry policies
- Disaster recovery exercise outcomes
- Crisis management and disaster recovery effectiveness
Corporate Security, Crisis Management & Physical Security (10%)
- Implement and maintain security standards, policies, and procedures.
- Develop and enhance corporate safety standards, policies, and practices.
- Identify, investigate, and resolve security risks, incidents, and breaches.
- Implement and maintain the Crisis Management Model in line with Group guidelines and conduct regular effectiveness testing.
- Evaluate country and regional travel risks and support employees on travel security matters.
- Assess event-related security risks and advise event owners on appropriate security measures.
- Respond to physical security incidents, including medical emergencies, fire alarms, bomb threats, and intrusion alarms in accordance with established procedures.
- Communicate security status, updates, and emerging risks to relevant stakeholders.
Key Results Areas
- Compliance with Group and industry policies
- Security incident prevention and resolution
Qualifications / Requirements
- Master’s Degree in Information Technology.
- Professional cybersecurity certification such as CISSP, CISA, CISM, CEH, GCIH, SSCP, or equivalent.
- Minimum 10 years of professional experience, preferably in cybersecurity, security management, or related fields.
- Strong analytical and problem-solving capabilities with the ability to work independently.
- Positive, proactive, and collaborative approach to teamwork.
- Strong service mindset and interpersonal skills.
- Excellent communication skills with fluency in spoken and written English.
Key Stakeholders
External
- Generali Asia Regional Office
- Generali Head Office
- Office of Insurance Commission (OIC)
- Thai Life Assurance Association (TLAA)
- Thai General Insurance Association (TGIA)
Internal
- Information Technology Department
- Human Resources Department
- Executive Committee
- Marketing Department
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search