{"id":1304391,"url":"https://alion.io/job/deestone-cybersecurity-lead","title":"Cybersecurity Lead","company":{"id":3813938,"name":"Deestone","domain":"deestone.com","url":"https://alion.io/company/deestone","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Samut Sakhon, Thailand"],"countries":["TH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":32000,"max_usd":82000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":330},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"DLP","optional":false},{"name":"Docker","optional":false},{"name":"GCP","optional":false},{"name":"GDPR","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"NIST CSF","optional":false},{"name":"PCI DSS","optional":false},{"name":"SIEM","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-25T06:25:54Z","employer_posted_date":null,"last_verified_at":"2026-09-25T06:25:54Z","board_verified":false,"closed_at":null,"days_open":2,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":2},"description":"1. วัตถุประสงค์ของตำแหน่งงาน (Job Purpose)วางแผน กำกับดูแล และขับเคลื่อนกลยุทธ์ด้านความมั่นคงปลอดภัยทางสารสนเทศขององค์กรให้ครอบคลุมทั้งมิติเทคโนโลยี กระบวนการ และบุคลากร ทำหน้าที่เป็นผู้นำในการบริหารจัดการความเสี่ยงทางไซเบอร์ การตอบสนองต่อเหตุการณ์ละเมิดความปลอดภัยขั้นสูง (Advanced Incident Response) รวมถึงการกำกับดูแลให้ระบบและโครงสร้างพื้นฐานดิจิทัลทั้งหมดสอดคล้องกับกฎหมาย มาตรฐานสากล และรองรับการเติบโตทางธุรกิจอย่างมั่นคง2. หน้าที่ความรับผิดชอบหลัก (Key Responsibilities)2.1 การกำหนดกลยุทธ์ สถาปัตยกรรม และนโยบายความปลอดภัย (Cybersecurity Strategy & Governance)ร่วมกับผู้บริหารระดับสูงในการออกแบบและขับเคลื่อนกลยุทธ์ Security Architecture (เช่น Zero Trust Architecture) ให้สอดคล้องกับทิศทางธุรกิจทบทวน จัดทำ และปรับปรุงนโยบายความมั่นคงปลอดภัยสารสนเทศ (Information Security Policies) และแนวทางปฏิบัติ (Guidelines/SOPs) ให้ทันสมัยตามมาตรฐานสากล (ISO 27001, NIST)กำกับดูแลการนำกรอบการทำงานด้าน Cybersecurity มาประยุกต์ใช้ในทุกระบบ ทั้ง On-Premises, Multi-Cloud และ Hybrid Environment2.2 การบริหารจัดการความเสี่ยง และการปฏิบัติตามข้อกำหนด (Risk Management & Compliance)ประเมินความเสี่ยงทางไซเบอร์ขององค์กร (Cyber Risk Assessment) และจัดทำแผนบรรเทาความเสี่ยง (Risk Mitigation Plan) เสนอต่อคณะกรรมการหรือผู้บริหารควบคุมดูแลการตรวจสอบความปลอดภัยของคู่ค้าภายนอกและระบบซัพพลายเชน (Third-Party / Vendor Risk Management)กำกับดูแลให้กระบวนการทำงานและการเก็บรักษาข้อมูลสอดคล้องกับกฎหมาย ข้อบังคับ และมาตรฐานสากล (เช่น PDPA, GDPR, PCI-DSS, ISO/IEC 27001)อำนวยความสะดวกและเป็นผู้นำทีมในการรับการตรวจประเมินจากผู้สอบบัญชีด้านความปลอดภัย (Internal & External Security Audits)2.3 การจัดการเหตุการณ์ภัยคุกคาม และ SOC Oversight (Incident Response & Threat Intelligence)เป็นผู้นำ Incident Response Team (IRT) ในการรับมือ วิเคราะห์ และแก้ไขสถานการณ์เมื่อเกิดเหตุการณ์บุกรุก หรือการละเมิดความปลอดภัยระดับร้ายแรง (Critical Incident)กำกับดูแลการทำงานของ Security Operations Center (SOC) ทั้งแบบ In-house หรือ Outsourced ให้มีประสิทธิภาพสูงสุดในการตรวจจับและตอบสนอง (MTTD/MTTR)\nQualifications\nปริญญาตรีขึ้นไป สาขาวิชาวิทยาการคอมพิวเตอร์, เทคโนโลยีสารสนเทศ, วิศวกรรมคอมพิวเตอร์, หรือสาขาที่เกี่ยวข้อง\n\nประสบการณ์ทำงานรวมด้าน IT/Cybersecurity ไม่น้อยกว่า 5 - 8 ปีขึ้นไป โดยมีประสบการณ์ในระดับบังคับบัญชา หัวหน้าทีม หรือบริหารโครงการด้าน Cybersecurity อย่างน้อย 2 - 3 ปี\n\nมีความเชี่ยวชาญระดับสูงเกี่ยวกับ Security Frameworks (เช่น NIST CSF, ISO/IEC 27001, CIS Controls, MITRE ATT&CK Framework)\n\nมีความรู้ลึกซึ้งด้าน Network Security, Endpoint Protection, Cloud Security (AWS, Azure, GCP), IAM และ Application Security\n\nมีความเชี่ยวชาญในการบริหารจัดการเครื่องมือด้าน Security ชั้นนำ เช่น SIEM, SOAR, EDR/XDR, DLP, WAF, Vulnerability Scanners\n\nเข้าใจโครงสร้างกฎหมายด้านข้อมูลและเทคโนโลยี เช่น พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล (PDPA), พ.ร.บ. การรักษาความมั่นคงปลอดภัยไซเบอร์\n\nมีความเข้าใจด้าน DevSecOps, Container Security (Docker, Kubernetes) และ CI/CD Pipeline Security\nBenefits\n- กองทุนสำรองเลี้ยงชีพ- ชุดยูนิฟอร์ม- โบนัส- เบี้ยขยัน- ตรวจสุขภาพประจำปี- กองทุนประกันสังคม- กองทุนเงินทดแทน- เงินสังสรรค์ประจำปี- พนักงานดีเด่น- ฌาปนกิจสงเคราะห์- รถรับ - ส่ง (เฉพาะเส้นทางที่จัด)- เปิดบัญชีธนาคารโดยไม่เสียค่าใช้จ่าย- หอพักพนักงานรายวัน(สำหรับบุคคลที่อยู่ต่างจังหวัด)- สำหรับงานออฟฟิศสำนักงาน ทำงานหยุดเสาร์เว้นเสาร์ (ยกเว้นงานที่ทำในโรงงาน)","description_format":"text","description_chars":3213,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-26T12:33:12Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":2,"expected_fill_days":23,"reasons":["seen:2","win:early"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/deestone-cybersecurity-lead","json_url":"https://alion.io/job/deestone-cybersecurity-lead.json","meta":{"generated_at":"2026-09-28T06:12:39Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4323,"day_limit":5000,"remaining_today":677,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}