Head of Information Security
Indexed description
About Central Pattana:
Central Pattana Public Company Limited is on a mission to shape the future of retail-led property development and lifestyle destinations for all. We are seeking highly passionate and talented individuals to join our dynamic team and play a crucial role in driving innovation and fostering new business ventures.
About the Role:
Lead enterprise cybersecurity, data security, and technology risk management to protect CPN’s digital assets, strengthen resilience, and enable secure business growth across malls, offices, hotels, platforms, and enterprise systems. Translate cyber risks into clear business decisions, drive governance and execution, and build sustainable security capability across people, process, technology, and partners.
Roles & Responsibilities
1. Security Strategy, Governance & Risk Management
- Define and drive enterprise cybersecurity, information security, and technology risk strategy aligned with CPN’s business priorities, digital roadmap, and risk appetite.
- Establish security governance, policies, standards, controls, and operating model across people, process, technology, and partners to be in compliance with Group’s policy/guideline.
- Clarify roles and accountability between CPN Digital Technology, Group CISO, business units, vendors, and managed security service providers.
- Enforce security practices to all related stakeholders including Digital Technology, business units’ users, vendors, and management to ensure CPN achieve and maintain world-class security standards.
- Provide clear cyber risk reporting, residual risk visibility, and decision support to management, ExCo, Risk Committee, and Board.
- Ensure compliance with applicable regulatory, audit, privacy, and group security requirements, including timely closure of findings and remediation actions.
2. Security Architecture & Secure-by-Design
- Embed security-by-design across applications, servers and cloud, infrastructure, networks, ERP, data platforms, and digital ecosystems.
- Define security requirements for identity and access management, privileged access, endpoint protection, remote access, network segmentation, logging, monitoring, and backup resilience.
- Review architecture and technology changes to ensure security controls are practical, scalable, and aligned with enterprise standards.
- Partner with Enterprise Architecture, Infrastructure, Application, Data, and business teams to reduce risk while enabling business agility.
3. Security Operations, Monitoring & Incident Readiness
- Oversee security operations, threat monitoring, vulnerability management, incident response, and cyber crisis readiness.
- Work with product team on security scan and security compliance from design to deployment.
- Strengthen detection and response capability through clear playbooks, escalation protocols, security tooling, automation, and measurable service levels.
- Design Incident Response Plan in detail. Ensure all related stakeholders know their roles and scopes should incident happen.
- Ensure timely detection, escalation, containment, recovery, post-incident review, and continuous improvement for security incidents.
- Drive risk-based vulnerability and patch management across critical systems, infrastructure, applications, and cloud environments.
- Improve resilience of critical business services through tested backup, disaster recovery, crisis simulation, and ransomware-resilient recovery controls.
4. Stakeholder, Vendor & Business Alignment
- Partner with business leaders, Group CISO, Digital Technology teams, Enterprise Architecture, Risk, Legal, Compliance, Procurement, Vendors, and External advisors.
- Translate complex cyber risks into practical business implications, investment priorities, and decision options.
- Manage security vendors, managed security services, and external experts with clear scope, SLAs, deliverables, and accountability.
- Promote secure business growth by balancing protection, compliance, customer trust, operational resilience, and speed of execution.
5. Organization & Capability Development
- Build a capable, accountable, and business-oriented security team with clear ownership, priorities, and performance expectations.
- Define security roles, capability gaps, learning plans, succession pipeline, and operating cadence to reduce dependency on individuals.
- Develop specialized security capability in areas such as cloud security, SAP/ERP security, identity security, threat detection, and incident response.
- Promote security awareness, responsible digital behavior, and proactive risk ownership across CPN.
Qualifications and Experience
- 12–15+ years of experience in cybersecurity, information security, technology risk, security operations, or IT leadership, with proven team leadership experience.
- Strong background in enterprise security across cloud, ERP/SAP, applications, infrastructure, network, identity, endpoint, and digital platforms.
- Hands-on experience in security governance, risk management, incident response, vulnerability management, third-party security, and security operating model design.
- Proven ability to communicate cyber risk and remediation priorities to senior management, ExCo, Risk Committee, or Board-level stakeholders.
- Experience managing team, internal stakeholders, vendors, managed security services, external cybersecurity experts, and cross-functional remediation programs.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001, cloud security, or TOGAF are preferred.
- Strong communication skills in Thai and English, with the ability to simplify technical issues for business audiences.
Leadership Expectations
- Own outcomes with strong execution discipline, urgency, and follow-through.
- Think strategically while staying close to critical risks, operational details, and remediation progress.
- Lead through influence across own internal team, business, technology, risk, legal, vendors, and group security stakeholders.
- Stay calm and structured during cyber incidents, business escalations, and high-pressure situations.
- Make balanced decisions that consider business growth, customer trust, compliance, cyber resilience, and operational continuity.
- Build a high-accountability team culture with clarity, ownership, collaboration, continuous learning, and measurable improvement.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search