· Manage the end-to-end evidence collection process for ISO 27001, PDPA, and PCI-DSS — define evidence requirements, assign collection tasks to control owners, validate completeness, and organise evidence repositories
· Coordinate internal and external audit schedules — manage logistics, prepare control owners for audit interviews, ensure evidence packages are ready, and track audit finding responses
· Track and drive remediation of audit findings and compliance gaps — maintain a remediation tracker with owners, deadlines, and status; escalate overdue items; validate closure evidence
· Conduct control validation testing — verify that documented controls are operating effectively through sample testing, walkthroughs, and evidence review
· Produce and maintain the compliance dashboard — real-time view of compliance status across frameworks, evidence collection progress, remediation pipeline, and upcoming audit milestones
· Manage the security exception register — track approved exceptions, monitor expiration dates, ensure risk acceptance documentation is complete, and trigger renewal reviews
· Support vendor compliance assessments — collect and review vendor security questionnaires, track vendor compliance gaps, and maintain the vendor risk register
· Coordinate with IT and business teams on control implementation — translate compliance requirements into operational tasks and track implementation progress
· Maintain compliance documentation — audit reports, finding responses, remediation evidence, exception approvals, and compliance correspondence with regulators and auditors
· Compliance frameworks: ISO 27001 (control mapping), PDPA requirements, PCI-DSS basics
· Evidence management: Document management systems, evidence repositories, audit trail maintenance
· Tracking and reporting: Project management tools, compliance dashboards, Excel/Google Sheets for tracker management
· Control testing: Basic understanding of IT controls — access management, change management, logging, backup — to validate evidence
These are non-negotiable. If you do not meet all of these, this role is not the right fit.
· 4+ years in information security, IT audit, or compliance operations
· Hands-on experience with audit evidence management — you’ve collected, organised, and presented evidence to external auditors
· Working knowledge of ISO 27001 controls and audit processes — you understand what auditors look for and how to prepare for assessments
· Strong project management and tracking skills — ability to manage multiple concurrent compliance workstreams with different deadlines
· Excellent attention to detail and organisational skills — you can manage hundreds of evidence items across multiple frameworks without dropping anything
· Fluent in Thai; reading English proficiency for compliance frameworks and documentation