Manager – Security Operations Team Leader

[2090600] INTERNATIONAL - TECHNOLOGIES & OPERATIONS - SECURITY OPERATIONS & IDENTITY (TOD-INT-OPSEC)
Thailand


Job Title : Manager – Security Operations Team Leader

Department/Function : TOD-INT-OPSEC

Reporting to Title : Senior Manager - Head of Security Operations, Identity & Monitoring

Main Objectives and Activities:

Within the Technologies & Operations department, you will lead and develop the Security Operations team, comprising three cybersecurity analyst and oversee the managed security service provider (MSSP) activities for BRED IT and the BRED Group’s APACA entities.

Alongside the leadership responsibility, you will personally serve as the central point of contact for level 1 security topics across BRED Group’s APACA entities managed by BRED IT. You will coordinate security controls, security action plans, ICT-related audit recommendations and remediation follow-up, and the rollout of new Group security plans and processes. You will establish consistent oversight across these entities and provide BRED Headquarters with clear, detailed, and consolidated reporting.

The role requires the ability to lead and influence beyond direct hierarchical authority. You will work closely with management, navigate governance and committee structures, and mobilize stakeholders across teams and departments to ensure effective execution. Success in this position will depend on your capacity to combine formal levers, such as management support and governance forums, with informal influence, stakeholder management, and soft power.

Your role will combine the following two responsibilities:

Lead the Security Operations team:

  • Lead, coach, and develop the cybersecurity analysts: set objectives, allocate work, manage capacity, and support individual development.
  • Provide technical guidance and mentor team members in security operations, investigation, vulnerability remediation, and automation.
  • Oversee the MSSP’s service delivery, performance, and escalation against agreed responsibilities and service levels.
  • Manage the team’s delivery of vulnerability management, security incident management, security alert triage, endpoint security management, and certificate management services. Ensure clear priorities, effective escalation and timely follow-up.
  • Improve service quality, efficiency, and scalability through automation, documented procedures, and continuous improvement.

Coordinate level 1 security across the entities in scope:

  • Act as the central point of contact between BRED SA, BRED IT, and designated contacts in the APACA entities managed by BRED IT for Level 1 security topics. Establish common follow-up arrangements and reporting expectations aligned with Group requirements.
  • Coordinate the implementation and periodic execution of Level 1 security controls with the responsible teams. Collect and consolidate control results, supporting evidence, exceptions, and corrective actions, and follow up on missing or incomplete submissions.
  • Maintain a consolidated record of security action plans, including actions, accountable owners, target dates, dependencies, progress, and evidence of completion. Conduct regular follow-up with action owners and escalate overdue actions and unresolved blockers.
  • Coordinate the follow-up of ICT-related audit recommendations and remediation across the entities in scope. Track recommendations, follow up with responsible owners, and consolidate supporting evidence.
  • Coordinate the rollout of new Group security plans, processes, controls, and procedures, aligned with the BPCE Technology & Risk Management framework. Translate requirements into implementation actions, coordinate local adoption, and track implementation gaps and completion.
  • Prepare and present regular consolidated reporting to BRED SA and relevant BRED IT leadership. Include entity-level detail on control results, security action plans, audit remediation, and Group rollouts, highlighting gaps, overdue items, risks, and decisions required.
  • Contribute to the Group cybersecurity roadmap using entity needs, recurring control weaknesses, audit findings, and implementation constraints; advise leadership on priorities and coordinate agreed actions within the entities in scope.

Qualifications:

  • Bachelor’s degree (BSc.) in Computer Science.

Language skills:

  • Very good command of English (both speaking and writing) is mandatory.
  • A good command of French is not mandatory but would be highly regarded.

Experience and Skills Required:

  • At least 5 years of experience in cybersecurity, including security operations and coordination of security controls, security action plans, or ICT-related audit remediation. Experience in banking or another regulated financial services environment is preferred.
  • Proven experience leading cybersecurity teams, including coaching analysts, setting priorities, and managing service delivery. Demonstrated ability to coordinate security initiatives across multiple entities or business units in a multicultural environment, working with stakeholders outside the direct reporting line.
  • Strong analytical and communication skills, with the ability to guide technical teams and explain security requirements, control gaps, and remediation priorities to management.
  • Strong organizational skills, with the ability to balance team leadership with personal coordination deliverables, maintain reliable action registers, and follow up on deadlines across multiple entities.
  • Strong written communication skills, with the ability to prepare clear procedures and concise management reports, supported by detailed, traceable information.
  • The candidate is expected to be proactive, curious, persistent, and autonomous.

Technical Skills Required:

  • Practical knowledge of security controls, control evidence, security action-plan tracking, and the lifecycle of ICT-related audit recommendations and remediation.
  • Ability to translate security requirements into implementation actions and coordinate adoption across entities with different local constraints.
  • The candidate is expected to be proficient in performing risk assessments and anticipating upcoming security threats.
  • The candidate must have experience with vulnerability management tools (e.g., Qualys, Rapid7, Tenable) and a strong understanding of how to manage vulnerabilities from their discovery to closure.
  • The candidate must have experience with endpoint security tools (e.g., Sophos Endpoints, Microsoft Defender, Crowdstrike Falcon, Cortex XDR).
  • The candidate must have experience with Security Orchestration, Automation and Response tools (e.g., Splunk SOAR, Cortex XSOAR, Microsoft Sentinel).
  • The candidate is expected to have hands-on experience with one or more development/scripting languages (e.g., Python, Bash, Java, Powershell) and automation tools (e.g, Airflow, Ansible, SOAR) up to a point where the candidate can mentor more junior employees.
  • An advanced understanding of Linux and Microsoft’s operating systems is expected.
  • Proficiency with Microsoft Office, particularly Excel and Power BI, with the ability to analyze results, maintain action registers, and prepare consolidated dashboards and detailed management reports.
  • A certification such as CISSP or CISM would be highly regarded.
APPLY

About the Company

BRED IT Thailand

BRED IT (Thailand) Ltd. is a wholly owned subsidiary of the French bank BRED Banque Populaire based out of Paris (BPCE Group).


BRED IT was established in 2008 with the objective to become the IT hub for BRED Group Commercial Banks in South East Asia, Pacific Ocean, and the Horn of Africa areas.

In parallel, BRED IT has expanded its activities since 2011 to also provide remote IT services to Paris Headquarters.


Today, with more than 200 employees, BRED IT fully supports Banque Franco Lao in Laos, BRED Bank Cambodia, BRED Bank Vanuatu, BRED Bank Solomon Islands, BRED Bank Fiji and Banque pour le commerce et l’industrie Mer Rouge (BCIMR) in Djibouti:


BRED IT hosts and manages all layers of BRED International Banks Information Systems: From Infrastructures to Applications (Core Banking, Internet/Mobile Banking, E-Payments and etc.), on a 24x7 basis. Half of the activity is currently performed for BRED Headquarters, with a focus on Projects (built with Java, COBOL, PHP, DataStage) and Production/Devops.


We are a unique company, thanks to our identity and our history: We place our expertise at the service of BRED Group and develop our activities with an entrepreneurial structure. By putting BRED group best interests first, it allows us to deliver tailor-made solutions with high value-added.