About the role
AI summarisedThe Regional Manager for CDI Business and Product Security GRC leads security governance and oversight across Thales' APAC operations, including physical, logical, and cloud security. The role ensures compliance with regulatory standards, conducts risk assessments, and advises sites on security certifications and industry initiatives.
Aerospace & DefenseOnsite
Key Responsibilities
- Report to the CDI Regional Security Director and be accountable for Security Governance and Oversight of CDI Asia Business Security
- Act as the Tactical Process Manager, bridging security personnel and organizational leaders to facilitate achievement of strategic security objectives
- Oversee business and operational security management related to personnel, physical, production, and IT security across Secure Product manufacturing and personalization sites
- Provide expert advisory and guidance to sites for achieving and maintaining required accreditations and ongoing compliance with security regulations such as GSMA-SAS, ISO 14298, ISO 27001, PCI-CP
- Act as Regional Point of Contact for Industry 4.0 initiatives for Manufacturing and Banking activities
- Conduct risk assessments and regular audits for internal and external stakeholders
- Ensure security risks and issues are identified, managed, and mitigated in a measurable manner following corporate policies and customer requirements
- Serve as domain expert and trusted advisor to provide management with inputs and recommendations to proactively manage risks and protect CDI, customer, and partner information, assets, and data
Requirements
- 10 years of progressive experience in IT / IT Security, Security Governance, Risk, and Compliance (GRC), ideally within high-security manufacturing, data center and adjacent industries
- 3+ years of experience leading external audits for GSMA-SAS, PCI-CP, or ISO 27001 certifications
- Preferred certifications: CISSP, CISA, CISM
- Operational Physical and IT Security knowledge and experience
- Knowledge in Cyber & Cloud Security
- Expertise in conducting formal risk assessments and business impact analyses
- Experience with GRC tools and security dashboards such as Splunk, Grafana, Kibana, Power BI
- Ability to travel 20-30% of time within Asia as needed