This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
FCM is one of the world’s largest travel management companies and a trusted partner for nationals and multinational companies. With a 24/7 reach in 97 countries, FCM’s flexible technology anticipates and solves client needs, supported by experts who provide in-depth local knowledge and duty of care as part of the ultimate personalised business travel experience. As part of the ASX-listed Flight Centre Travel Group, FCM delivers the best market-wide rates, unique added-value benefits, and exclusive solutions. A leader in the travel tech space, FCM has proprietary client solutions. FCM provides specialist services via FCM Consulting and FCM Meetings & Events.
Job Responsibility:
Assist the Information Security Risk and Compliance Manager, CPO Asia, Risk and Business Leadership to identify information security risk exposures and manage them within risk appetite
Implement and maintain an information security risk register to record, track and manage information security risk for the region
Monitor new threats as they evolve and recommend adjustments to risk management plans and security controls as necessary
Lead the implementation and maintenance of the Information Security Management System (ISO 27001) within Asia
Facilitate and provide secretarial support (agenda, meeting pack, and minutes) for the quarterly Information Security Management Forums (ISMF)
Collaborate with internal stakeholders to collate assurance documentation and evidence to support audit activity
Perform internal and coordinate external audit and security testing programs to maintain compliance with Corporate security standards, certifications and regulatory requirements
Assist with the assessment of third-party security risk for suppliers with whom FCTG has a requirement to share information or business processes
Assist Sales and Account Management teams to respond to customer security questions
Feed customer requirements into ongoing assurance activities to ensure new compliance risks are known, owned, and managed
Requirements:
3+ years of experience in information security, governance, risk and compliance (GRC), or a technical security operations role
In-depth knowledge of Security frameworks such as ISO27001/2, PCI DSS, NIST, SOC 2, etc
Working knowledge of Risk Frameworks such as ISO 31000
Demonstrated ability in implementing and maintaining an Information Security Management System (ISMS) for ISO 27001
Nice to have:
ISO 27001 Internal Auditor or Lead Implementor
CISSP, CISM, or equivalent certification desirable but not mandatory
What we offer:
Competitive market salary
Relevant training courses and tools
Fun and energetic culture
Work life balance with paid annual leave
Travel perks with industry discounts
Career advancement opportunities
Flexible working arrangement
Reward and recognition at Buzz Nights and annual Global Gathering