Senior Information Security Specialist
We are looking for an experienced Information Security Specialist who can operate independently and keep KKCompany’s rapidly scaling business aligned with ISO/IEC 27001, ISO/IEC 27701, and other relevant security and privacy requirements. You will drive internal audits, policy development, and security-awareness initiatives while collaborating with colleagues across product, operations, and compliance to embed a security-first mindset as the company grows. If you want a role that blends strategic impact with hands-on ownership of security and privacy, you’ll feel right at home here.
Responsibilities:
Lead internal audits against ISO 27000-series standards, track remediation, and manage external audit schedules and evidence.Develop, update, and enforce information security and privacy policies, procedures, and records to meet regulatory and standard requirements.Monitor developments in security and privacy regulations (e.g., PDPA) and advise on control adjustments.Conduct annual risk assessments, maintain the risk register, and coordinate mitigation actions across teams.Design and deliver security and privacy awareness training and campaigns to raise organization wide security awareness.Collaborate with engineering, cloud operations, legal, and external consultants to ensure controls remain effective and aligned with business needs.
2 years of experience required
No management responsibility