About this role
MAIN PURPOSE Ensuring effective compliance across the enterprise, while maintaining strong governance and operational alignment with external security service providers. Conducting risk assessments, developing and maintaining security policies, and reinforcing a culture of compliance and security across the region KEY RESPONSIBILITIES Security Governance & Compliance Develop and maintain security policies, standards, and procedures. Ensure compliance with regulatory frameworks such as Shiseido Security Framework, ISO 27001, NIST, GDPR, and PDPA. Support internal and external audits and manage remediation of findings. Risk Management Collaborate with IT business partners to conduct risk assessments for upcoming IT projects, ensuring security compliance with global standards. Collaborate with IT and application teams to remediate identified risks. Maintain a risk register and report on risk posture to senior leadership. Security Awareness & Training Promote a culture of security awareness through training programs and phishing simulations. Provide guidance to business units on secure practices and data protection. Reporting & Documentation Maintain documentation information security policies and procedures. Prepare regular reports on security metrics, incident trends, and security rating system Security Innovation & Trends Monitor emerging threats and technologies. Recommend strategic investments in security innovation. Ad hoc Support Additional information security-related tasks given by the supervisor or management team REQUIREMENTS Bachelor’s degree in information security, Computer Science, or related field. 5+ years of experience in cybersecurity operations, with at least 2 years in vendor management. Hands-on experience with security frameworks, policies, and audit processes Familiarity with enterprise risk management and corporate governance practices. The position requires regular communication and collaboration with stakeholders across the APAC region, where English is the primary business language. Clear communicator with both technical and non-technical audiences Certifications such as CISSP , CISM , GIAC , or ISO 27001 Lead Implementer preferred. Ability to travel within the APAC region as needed.