🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Title: Information Security & Governance Manager Location Type: 100% Onsite Location: Bangkok (Head Office – Sathorn) Role type: Full-time Build the operating system for wellness—starting from Thailand, scaling globally. Aura Wellness is creating a new tech startup to power the next decade of wellness services: aesthetic clinics, spas, longevity/anti-aging clinics, hospitals, and others. This team will work directly under the Teach Team , with fast decisions, direct access to real operating clinics for testing, and a clear multi-year roadmap. If you want to build a real clinic platform with real usage—not slideware. About the Role We are looking for an Information Security & Governance Manager to build and lead the company’s security and IT governance function from the ground up across all four brands. This is a first-in-role position reporting to the Head of Tech, with broad ownership spanning security policy, enterprise controls, cloud security, third-party risk, and day-to-day IT governance operations. This role is directly responsible for execution — not just oversight. You will design the frameworks, implement the controls, run the programs, and own the outcomes. At the same time, you will need to communicate clearly with non-technical stakeholders and help the organization build a genuine security culture. The right person is equally comfortable writing a policy framework, configuring a cloud security baseline, running a phishing simulation, and sitting across the table from a vendor to negotiate data protection terms. Key Responsibilities: Build and own the company’s information security policy framework — policies, standards, guidelines, and procedures — across all brands. Ensure policies are current, communicated organization-wide, and translated into measurable day-to-day controls. Establish and enforce data governance rules covering access to sensitive information, including patient treatment records, CCTV footage, and shared company files, in compliance with PDPA Section 26. Develop and maintain a Business Continuity Plan (BCP) with related business units covering critical systems and data, including recovery priorities, escalation procedures, and periodic testing to ensure the organization can sustain operations during disruptions. Design, implement, and manage enterprise security controls covering both logical controls (IAM, endpoint protection, DLP, email security, conditional access) and physical controls (access card systems, CCTV governance, clean desk policies). Design, deploy, and manage network security architecture (firewalls, network segmentation, VPN, DNS filtering, IDS/IPS) and cloud security across AWS and Azure/M365 environments, including identity governance, security configuration baselines, encryption controls, and CSPM. Design and implement Microsoft 365 compliance controls, including data classification, retention policies, DLP rules, sensitivity labels, and Purview configurations. Identify security risks, vulnerabilities, and control gaps through continuous monitoring. Prioritize and drive remediation with relevant teams, and formally document all security incidents to build a record of control effectiveness. Lead third-party risk management: assess the security posture of technology vendors, SaaS platforms, and external service providers at onboarding and on a periodic review cycle. Define vendor security requirements and ensure contractual data protection obligations align with the company’s risk appetite. Design and manage an organization-wide security awareness training program, including onboarding induction, phishing simulation exercises, and targeted training for high-risk roles. Track completion rates and use results to improve controls. Plan and manage security testing activities — vulnerability assessments, penetration tests, and configuration audits — across systems, applications, and cloud environments. Track findings to closure and report risk ratings and timelines to management. Run IT governance operations including user account lifecycle management (provisioning, access reviews, deprovisioning), IT asset and license inventory, hardware procurement, and core system maintenance. Develop and maintain security and IT governance metrics and reporting to provide clear visibility into security posture, control effectiveness, and operational health for senior management. Key Qualifications & Skills: Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field. 8+ years of hands-on experience in information security and IT governance, with a proven track record of implementation — not only oversight. Deep understanding of enterprise security controls, covering both logical controls (IAM, endpoint, DLP, email security) and physical controls (access card systems, CCTV governance). Practical experience designing and implementing cloud security on AWS or Azure/M365, including identity governance, CSPM, and compliance configurations. Experience managing third-party risk throughout the vendor lifecycle, including security assessments, contract requirements, and periodic reviews. Experience building security awareness programs, running phishing simulations, and planning security testing (vulnerability assessments, penetration tests). Hands-on experience with Microsoft 365 compliance tools (Purview, DLP, sensitivity labels, retention policies). Ability to write clear policies, translate them into actionable controls, and communicate security risk to both technical and non-technical audiences. Strong problem-solving, project management, and stakeholder management skills. Preferred Qualifications Experience in a fast-growing, multi-brand, or retail/healthcare environment. Familiarity with Thai PDPA, ISO 27001, NIST CSF, CIS Benchmarks, or CSA CCM. Experience supporting or leading an ISO 27001 implementation or certification project. Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, ISO 27001 Lead Implementer/Auditor, CompTIA Security+, or Microsoft SC-series. Work arrangement Please note that all interview stages and this role are fully onsite. Remote or hybrid arrangements are not available for this position. If you’re excited to build a category-defining wellness platform with real-world scale, direct access to live clinics, and CEO-level sponsorship, apply with your resume and a short note on the most operationally complex product you’ve shipped. Unlike many startups, this platform is backed by a profitable, scaled operator (Aura Bangkok Clinic) —so we can move with startup speed, invest for the long term, and build the right foundations without being forced into quarter-by-quarter fundraising decisions. Life at Aura Semi-flexible Office hour: 9.30-18.30 Smart Casual Dress Code 2-min walk from BTS Chongnonsi (Sathorn) Positive-energetic teammates Free lunch (Select Days) Premium Health and Life insurance High yield, high pop up Provident Fund plan Child Education Benefits Complimentary or discounted services across Aura Wellness, including Aura Bangkok Clinic, Aura Xpress, and AURASOL Wellness & Spa. Extra Benefits to keep your Professional Look and Feel Fit Entertainment zone; Nintendo switch, PS, Board games etc. Shower room with hotel amenities. Luxury massage chair to keep office syndrome away Sleep box, take a rest and get up with fresher energy and much more! Explore us at IG: life.at.aura