top of page

Career

Security and Digital Trust Manager

Technology

|

Permanent

Technology

Permanent

About Us

Do you want to be part of Thailand banking transformation? Data is the core of the new financial services era, and we are open for the opportunity to be part to drive this change at the core.

SCB DATAx is a new venture of the Siam Commercial Bank (SCB) holdings, a leading financial services and digital services holdings in Thailand and ASEAN.

As part of the transformation of SCB into a group of product and technology companies, under the SCBx brand, SCB DATAx is the technology company to centralize data and provide AI and data science services and products to the group.

With a leading-edge cloud native data & AI platform, our vision is to support the group to providing everyone in our region with the opportunity to prosper.

We work on forward-thinking challenges of centralizing, analyzing and sharing information. We collaborate with companies and experts in many different domains, embrace diversity and all that while having a good laugh and joy in work.

Discover job openings on our career page. To apply, email with the role's title as the subject, attach your CV, and specify your contact information. We're eager to learn more about you.

 I acknowledge that I have read and agreed to DataX's Terms and Conditions and Privacy Notice

Benefits

Other

Preferred Qualifications

Qualifications

Education

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.

  • Master’s degree in Cybersecurity, Information Security, or Business Management is preferred


Professional Experience

  • 10–15+ years of experience in Cybersecurity, Technology Risk, Security Operations, or Security Architecture.

  • At least 5 years in security leadership or management roles.

  • Strong experience managing enterprise security functions across architecture, governance, engineering, and operations.

  • Experience in banking, financial services, or regulated industries preferred.

  • Experience working with executive management, regulators, auditors, and risk management functions.


Technical Skills

  • Strong understanding of enterprise security architecture, Zero Trust, cloud security, IAM, endpoint security, DevSecOps, and AI security.

  • Knowledge of cloud platforms such as Azure (preferred), AWS, Kubernetes, and modern enterprise platforms.

  • Familiar with security technologies including SIEM, XDR/EDR, DLP, PAM, CSPM, firewall, and vulnerability management tools.

  • Strong understanding of NIST, ISO 27001, CIS Benchmark, PCI DSS, and banking regulatory requirements.

  • Experience with security governance, risk assessment, incident management, and audit coordination.

  • Familiarity with policy-as-code, automation, and secure SDLC practices.


Certifications (Preferred)

  • CISSP – Certified Information Systems Security Professional.

  • CISM – Certified Information Security Manager.

  • CCSP – Certified Cloud Security Professional.

  • CRISC – Certified in Risk and Information Systems Control.

  • TOGAF®, SABSA, or cloud security certifications.

  • Microsoft/Azure security certifications (SC-100, AZ-500).


Soft Skills

  • Strong leadership and people management skills.

  • Excellent communication and stakeholder management capabilities.

  • Ability to communicate complex security topics to executive and non-technical audiences.

  • Strong strategic thinking, analytical, and decision-making skills.

  • Ability to manage security incidents and critical escalations under pressure.

  • Strong collaboration and cross-functional coordination skills.

  • Business-oriented mindset balancing security, operational efficiency, and customer trust

Responsibilities

1. Security Strategy & Governance

  • Define and drive enterprise security strategy, roadmap, and digital trust initiatives.

  • Lead end-to-end 1LOD security operations across architecture, engineering, governance, and operations.

  • Establish security governance frameworks, policies, standards, and security KPIs aligned with NIST, ISO 27001, and banking regulatory requirements, ensuring effective governance and adherence across the organization.

  • Ensure alignment between technology, security, risk, and business objectives.

  • Govern security budget, resource planning, and capability development.

  • Lead and ensure the implementation of security awareness and training programs to strengthen employees’ understanding of cybersecurity threats, and information security practices.


2. Security Architecture & Secure-by-Design

  • Govern enterprise security architecture, Zero Trust, segmentation, encryption, and secure access strategies.

  • Oversee security architecture review and security sign-off processes through ARB and CAB.

  • Ensure security-by-design adoption across SDLC, cloud, AI, data platform, and infrastructure initiatives.

  • Define security guardrails, baselines, and reference architectures for enterprise platforms.


3. AI Security & Digital Trust

  • Lead AI/GenAI security and digital trust initiatives across enterprise AI platforms and products.

  • Ensure secure adoption of AI technologies including data protection, model security, prompt security, and Responsible AI controls.

  • Define governance and security controls for AI platforms, integrations, and sensitive data usage.

  • Collaborate with Risk and Compliance teams on AI governance and regulatory readiness.


4. Security Operations & Cyber Resilience

  • Oversee cloud, infrastructure, endpoint, IAM, and product security operations.

  • Ensure effective vulnerability management, penetration testing, threat detection, and incident response processes.

  • Govern cyber resilience, security monitoring, threat hunting, and security escalation management.

  • Coordinate with SCBX SOC and internal teams on incident management and threat response activities.


5. Governance, Risk & Compliance

  • Oversee security governance, audit coordination, compliance management, and risk remediation.

  • Ensure compliance with regulatory requirements, customer security obligations, and internal policies.

  • Review security risks, exceptions, compensating controls, and remediation plans.

  • Coordinate with 2LOD Tech Risk and Internal Audit on control testing, assessments, and regulatory activities.


6. Stakeholder & Executive Management

  • Present security posture, KPIs, risks, and strategic initiatives to CTO, CRO, executive committees, and governance forums.

  • Lead governance meetings and security escalations including TSC, ARB, and CAB.

  • Provide executive-level security reporting, dashboards, and management updates.

  • Build strong collaboration across Technology, Engineering, Operations, Risk, Audit, and external stakeholders

About Team & Role

The Security and Digital Trust Manager is responsible for leading end-to-end 1LOD security functions covering security architecture, AI security, governance & compliance, cloud and infrastructure security, IAM, endpoint security, DevSecOps, and security operations.

This role drives enterprise security strategy, security governance, cyber resilience, and digital trust initiatives across cloud, data, AI, and enterprise platforms for financial services and regulated industry customers. The role works closely with CTO, CRO, Technology teams, 2LOD Tech Risk, Internal Audit, and SCBX Group Security functions to ensure alignment with regulatory requirements, risk management expectations, and business objectives.

bottom of page