Position Overview:
The Head of Cybersecurity is a strategic leader responsible for managing the organization's cybersecurity strategy and operations across all TIME entities. This role will oversee developing, implementing, and maintaining a comprehensive cybersecurity program to protect the company's critical assets and data.
Roles & Responsibilities;
Strategic Leadership:
- Translate business objectives into a comprehensive cybersecurity strategy and implementation roadmap across all product lines.
- Serve as the primary advisor to executive leadership and the board on cybersecurity risks and mitigation strategies.
- Stay abreast of emerging threats, vulnerabilities, and industry best practices.
- Establish meaningful KPIs, metrics, and reporting cadence to measure and communicate progress.
Risk Management and Compliance:
- Identify, assess, and mitigate security risks to the organization.
- Ensure compliance with relevant regulatory, legal, and industry standards (e.g., PDPA, MCMC guidelines, NACSA CSA, PCI-DSS, ISO 27001, PDPA, NIST, etc.).
- Own digital and cyber risks throughout the lifecycle, including IR.
Policy Development:
- Oversee the enforcement and update of security policy, standards, and procedures.
- Strengthen the security policy and documentation framework to ensure it is well-structured, accessible, and comprehensive.
Collaboration and Stakeholder Engagement:
- Work closely with IT, technology, legal, compliance, and operations teams to embed security into business processes end-to-end.
- Act as a liaison to external regulatory bodies, law enforcement, and industry peers.
- Develop a security culture within TIME, including training programs, phishing simulations, awareness campaigns, etc.
Team and Vendor Management:
- Build and lead a high-performing cybersecurity team.
- Provide leadership and mentorship to the cybersecurity team.
- Foster a culture of security awareness and continuous improvement.
- Manage relationships with third-party vendors, partners, and security solutions providers.
Security Operations and Technological Oversight:
- Oversee the Cybersecurity Operations Center (CySOC) and ensure effective monitoring, detection, and response to security incidents.
- Oversee the design, implementation and maintenance of security system and solutions
- Oversee the execution of vulnerability assessments, penetration tests, and audits.
- Evaluate and deploy advanced security technologies, tools, and protocols (e.g. XDR, Zero Trust Architecture, Cloud-native Security, CASB, DLP, SOAR)
- Ensure a robust and secure architecture across all layers of the IT infrastructure.
Budget Planning and Management:
- Develop, manage, and optimize the cybersecurity budget to support strategic initiatives across multi-year budgets (CAPEX and OPEX).
- Ensure cost-effective allocation of resources, tools, and technologies while maintaining robust security measures.
Your Traits:
- Technical Expertise: A strong technical background in cybersecurity is essential to lead the team and make informed decisions effectively.
- Business Acumen: A good understanding of the business and its operations is crucial to align security initiatives with the organization's goals.
- Leadership Skills: Strong leadership and communication skills are necessary to motivate and inspire the cybersecurity team. Experience presenting to boards, risk committees, and other executive-level stakeholders is preferable.
- Adaptability: Adapting to emerging threats and technologies is essential in the fast-paced cybersecurity landscape.
Your Merits:
- Advanced degree in computer science, information security, or a related field.
- Relevant certifications such as CISSP, CISM, CISA, or equivalent.
- Deep understanding of cybersecurity frameworks, standards, tools, and best practices.
- 10+ years of experience in cybersecurity leadership roles, preferably in the telecommunications industry.
- Proven track record of managing large-scale security incidents and compliance programs.
- Extensive security knowledge across multiple layers, including perimeter, network, endpoint, platform, application (DevSecOps), data, and cloud security.
What you get:
- Cool and innovative work environment
- Work-life balance and our working hours are flexible
- We are too cool for ties. Smart casual is our game!
- We care about you and your family’s health and wellbeing
- Learning and growth opportunity
- We have an indoor slide and a cafe! How fun is that?!
- Free car park within the company compound
*Only shortlisted candidates will be notified. So, make your CV as fun and interesting as possible!
Position Overview:
The Head of Cybersecurity is a strategic leader responsible for managing the organization's cybersecurity strategy and operations across all TIME entities. This role will oversee developing, implementing, and maintaining a comprehensive cybersecurity program to protect the company's critical assets and data.
Roles & Responsibilities;
Strategic Leadership:
- Translate business objectives into a comprehensive cybersecurity strategy and implementation roadmap across all product lines.
- Serve as the primary advisor to executive leadership and the board on cybersecurity risks and mitigation strategies.
- Stay abreast of emerging threats, vulnerabilities, and industry best practices.
- Establish meaningful KPIs, metrics, and reporting cadence to measure and communicate progress.
Risk Management and Compliance:
- Identify, assess, and mitigate security risks to the organization.
- Ensure compliance with relevant regulatory, legal, and industry standards (e.g., PDPA, MCMC guidelines, NACSA CSA, PCI-DSS, ISO 27001, PDPA, NIST, etc.).
- Own digital and cyber risks throughout the lifecycle, including IR.
Policy Development:
- Oversee the enforcement and update of security policy, standards, and procedures.
- Strengthen the security policy and documentation framework to ensure it is well-structured, accessible, and comprehensive.
Collaboration and Stakeholder Engagement:
- Work closely with IT, technology, legal, compliance, and operations teams to embed security into business processes end-to-end.
- Act as a liaison to external regulatory bodies, law enforcement, and industry peers.
- Develop a security culture within TIME, including training programs, phishing simulations, awareness campaigns, etc.
Team and Vendor Management:
- Build and lead a high-performing cybersecurity team.
- Provide leadership and mentorship to the cybersecurity team.
- Foster a culture of security awareness and continuous improvement.
- Manage relationships with third-party vendors, partners, and security solutions providers.
Security Operations and Technological Oversight:
- Oversee the Cybersecurity Operations Center (CySOC) and ensure effective monitoring, detection, and response to security incidents.
- Oversee the design, implementation and maintenance of security system and solutions
- Oversee the execution of vulnerability assessments, penetration tests, and audits.
- Evaluate and deploy advanced security technologies, tools, and protocols (e.g. XDR, Zero Trust Architecture, Cloud-native Security, CASB, DLP, SOAR)
- Ensure a robust and secure architecture across all layers of the IT infrastructure.
Budget Planning and Management:
- Develop, manage, and optimize the cybersecurity budget to support strategic initiatives across multi-year budgets (CAPEX and OPEX).
- Ensure cost-effective allocation of resources, tools, and technologies while maintaining robust security measures.
Your Traits:
- Technical Expertise: A strong technical background in cybersecurity is essential to lead the team and make informed decisions effectively.
- Business Acumen: A good understanding of the business and its operations is crucial to align security initiatives with the organization's goals.
- Leadership Skills: Strong leadership and communication skills are necessary to motivate and inspire the cybersecurity team. Experience presenting to boards, risk committees, and other executive-level stakeholders is preferable.
- Adaptability: Adapting to emerging threats and technologies is essential in the fast-paced cybersecurity landscape.
Your Merits:
- Advanced degree in computer science, information security, or a related field.
- Relevant certifications such as CISSP, CISM, CISA, or equivalent.
- Deep understanding of cybersecurity frameworks, standards, tools, and best practices.
- 10+ years of experience in cybersecurity leadership roles, preferably in the telecommunications industry.
- Proven track record of managing large-scale security incidents and compliance programs.
- Extensive security knowledge across multiple layers, including perimeter, network, endpoint, platform, application (DevSecOps), data, and cloud security.
What you get:
- Cool and innovative work environment
- Work-life balance and our working hours are flexible
- We are too cool for ties. Smart casual is our game!
- We care about you and your family’s health and wellbeing
- Learning and growth opportunity
- We have an indoor slide and a cafe! How fun is that?!
- Free car park within the company compound
*Only shortlisted candidates will be notified. So, make your CV as fun and interesting as possible!