Information System Security Senior Manager
Working in the IT Governance Department of the Information Management Center, which employes over 100 IT engineers.• Developed and continuously improved the information security management system, encompassing policies, standards, procedures, and processes in line with ISO 27001:2013 standards and industry best practices, specifically tailored for the vehicle production, research, and development sectors.• As a Project Manager, led the Information System Risk Assessment Program, focusing 80% on information security risk and 20% on IT project management risk. Specialized in information systems supporting automobile manufacturing, research, and development, including MES, PDM, PLM, BOM, and TPMS application systems, as well as networks, databases, operating systems, and operational processes. Additionally, evaluated the effectiveness of security products in protecting the automotive production and R&D environment, ensuring a balance between security effectiveness and the impact on business operations.• Design information security technical framework: Application Security, Network Security, System Security, Virtualization Security, and Data Security.• Conduct regular penetration testing with a focus on black box techniques, following the Penetration Testing Execution Standard (PTES) framework alongside Open Web Application Security Project (OWASP) methodologies. • Contribute to the development and implementation of IT project Management systems in alignment with Project Management Professional (PMP) standards, support the day-to-day operations of the Project Management Office, and assist in project risk management to ensure programs and projects align with organizational goals and requirements. Manage IT government roles, including IT budgeting, IT annual performance management, and assisted the General Manager of the Information Management Center.