Makro PRO logo

GRC and Supplier Assurance

Makro PRO

Hybrid
Bangkok, Thailand
Full-time
Mid Level
5+ yrs
Salary not listedPosted 1h ago

Real job — pulled straight from Makro PRO’s careers page · Verified September 28, 2026 · No reposts.

Job description

Makro PRO is hiring a GRC and Supplier Assurance — a full-time, based in Bangkok, Thailand role. Apply directly on Makro PRO's careers page below.

GRC and Supplier Assurance

Location: Nawamin, Bangkok, Thailand

Department: Technology

Workplace: hybrid

Description

We are looking for a professional who can balance exceptional delivery for customers on what matters, engaging teams and colleagues, with the needs of the business. This role is often the first layer of management of people or projects.

Responsibilities:

•Understand and interpret requirements across relevant IT Risk, Cybersecurity, Regulatory and map requirements against the organization’s technology and security policies, standards and control

•Develop, establish, maintain, and continuously improve the organization’s Information Security Policies, Standards and Guidelines ensuring alignment with business requirements, regulatory obligations, and industry best practices.

•Conduct Technology Risk Assessments across applications, infrastructure, products, projects, and operations. Identify risks and control gaps, recommend appropriate remediation or mitigating controls, and track risks through closure or formal risk acceptance.

•Manage the Risk Acceptance process, ensuring exceptions have appropriate business justification, compensating controls, accountable risk owners, defined expiry dates, and periodic review.

•Coordinate with internal audit, external audit and other stakeholders to support audit and assessment, provide the information as audit request and regular report status to IT and Security management.

•Define and monitor Security KPIs, KRIs, compliance metrics, and management dashboards to measure control effectiveness, risk exposure, remediation progress, and overall security governance maturity.

•Perform other related duties as assigned

Requirements

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • 5+ years working in IT filed with a focus on information security or IT audit.
  • Knowledge of ISO27001, PCIDSS and IT security control
  • Exceptional communication, problem solving and cross-group collaboration skills
  • Good command of written and spoken English
  • Ability to present ideas in business-friendly and user-friendly language
  • Extensive experience in implementing and managing enterprise-level Identity and Access Management solutions, ensuring compliance with regulatory requirements and leading cross-functional teams to maintain a secure IAM environment.

Operational skills relevant to this role:

• IT Risk & Compliance Frameworks: ISO 27001, PCI DSS, NIST CSF and PDPA/PDPL – mapping overlapping requirements into one policy and standard set.

• Third-Party & Supplier Assurance: Vendor risk assessment, due-diligence questionnaires, contractual security requirements and ongoing monitoring.

• Governance & Policy Management: Policies, standards and procedures; security steering committees, charters and approval flows.

• Audit & Evidence Management: Internal, external and certification audits; control testing, evidence collection and remediation tracking to closure.

• Risk Reporting & Metrics: KPI/KRI design, risk registers, and vulnerability/pen-test reporting with prioritized remediation.

Get GRC and Supplier Assurance jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Samsara logo

Senior Security Operations Engineer (Remote)

$135k–$228kRemote · US-eligible
✓ From careers page· 20h ago
WeTravel logo

Senior Security Engineer

Bulgaria
✓ From careers page· 21h ago
Guzman y Gomez logo

Information Security Manager

Surry Hills, NSW
✓ From careers page· 22h ago

Frequently asked questions

What skills are required for GRC and Supplier Assurance at Makro PRO?

The required skills for GRC and Supplier Assurance at Makro PRO include: ISO 27001, PCI DSS, Cybersecurity, IAM.

What is the seniority level for GRC and Supplier Assurance at Makro PRO?

GRC and Supplier Assurance at Makro PRO is a Mid Level level position.

How do I apply for GRC and Supplier Assurance at Makro PRO?

You can view the full description and apply for GRC and Supplier Assurance at Makro PRO on EchoJobs: https://echojobs.io/job/makro-pro-grc-and-supplier-assurance-s8vbh.