You’ll help our DPO/InfoSec team strengthen TDG’s security posture across cloud, endpoints, data, and processes—supporting ISO 27001 controls and PDPA compliance while learning real-world incident response, risk assessment, and secure operations.
- Assist with endpoint and M365/Google Workspace security checks, patch status, and baseline hardening (CIS-aligned).
- Run basic network and asset discovery; maintain the IT & Data Asset Register.
- Perform guided scans (e.g., OpenVAS/Nessus/Wazuh) on approved assets, triage findings, and document remediation plans.
- Contribute to the Risk Register (likelihood × impact) and track mitigations.
- Draft/update SOPs, policies, and evidence logs for ISO 27001 Annex A controls and PDPA obligations (consent, retention, access).
- Help with security awareness content (phishing drills, micro-training).
- Support triage, timeline building, and post-incident RCA & CAPA documentation for minor incidents.
- Assist vendor/security due diligence checklists, access reviews, and join change-management walk-throughs.
- Keep clean records: control evidence, change logs, exception registers, and audit-ready folders.