Protect the systems that power our business. Safeguard the data that earns our customers trust.
At The Hour Glass, cybersecurity is fundamental to protecting our people, customers, and business. We are looking for an experienced Cybersecurity Manager to lead our cybersecurity and data protection initiatives, ensuring our technology environment remains secure, resilient, and compliant with evolving regulatory requirements.
Working closely with the Digital Technology Services (DTS) team, the Data Protection Officer (DPO), business stakeholders, and external partners, you will play a pivotal role in strengthening our security posture, driving compliance, and fostering a culture of cybersecurity awareness across the Group.
What You'll Do
Cybersecurity Operations
- Monitor and manage enterprise security tools to identify, investigate, and respond to security threats
- Lead incident response, vulnerability management, and remediation activities with internal teams and vendors
- Review the security posture of systems and applications, ensuring timely patching and risk mitigation
Risk, Governance & Compliance
- Lead penetration testing, cybersecurity assessments, and risk reviews
- Develop, maintain, and enhance cybersecurity policies, standards, and procedures
- Drive compliance with the Personal Data Protection Act (PDPA) and other applicable security and privacy regulations
- Lead the organisation's Cyber Trust Mark certification and other security audit initiatives
Security Awareness
- Champion a strong cybersecurity culture through phishing simulations, awareness campaigns, and employee training
- Develop regular security reports and dashboards to provide management with insights into cybersecurity risks and initiatives
Data Protection
- Partner with the Data Protection Officer (DPO) to strengthen privacy governance and secure data handling practices
- Support privacy impact assessments, regulatory reviews, audits, and policy development
- Promote best practices for data protection across business functions
Strategic Projects
- Lead cybersecurity projects, including the implementation of new security technologies and compliance initiatives
- Assess third-party security risks and work with vendors to ensure appropriate security controls are in place
- Contribute to the Group's cybersecurity roadmap and long-term technology strategy
What We're Looking For
- Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related discipline
- Proven experience in cybersecurity, information security, or IT risk management
- Experience leading security operations, incident response, vulnerability management, and security governance initiatives
- Strong understanding of cybersecurity frameworks, risk management, and data protection regulations such as PDPA
- Experience managing penetration testing, security audits, and compliance programmes
- Familiarity with enterprise security technologies, endpoint protection, email security, and vulnerability management platforms
- Relevant cybersecurity certifications (e.g. CISSP, CISM, CEH, Security+, ISO 27001) will be an advantage
- Project management certification (e.g. PMP or PRINCE2) is beneficial
Who You Are
- A strategic thinker who enjoys balancing governance with practical implementation
- Calm and decisive when responding to security incidents and emerging risks
- Strong analytical and problem-solving skills with excellent attention to detail
- An effective communicator who can translate technical concepts for business stakeholders
- A collaborative leader who builds strong relationships across technical and non-technical teams
- Passionate about fostering a security-first culture and driving continuous improvement
Why Join Us
- Lead cybersecurity initiatives that protect a regional business and its customers
- Drive security strategy, governance, and regulatory compliance across the Group
- Work alongside business leaders and technology teams on meaningful transformation initiatives
- Be part of a collaborative environment that values innovation, continuous learning, and operational excellence
If you're passionate about strengthening cybersecurity, protecting critical business assets, and shaping the future of enterprise security, we'd love to hear from you.