Securing Central Group

We are team of talented security engineers, delivering advance security solutions across the entire Central Group enterprise.

About

Central Group CISO Team

Central CISO is a subsidiary of Central Retail Corporation (CRC) - Central Group, Thailand's largest retailer and one of its most well-known brands. Our mission is to assemble the best security team possible to ensure that Central Group is a leading player in online e-tailing worldwide. Our focus is not just e-commerce as we also enable an omni-channel experience for our customers where we provide the products that they need, no matter where they are.

  • World Class Security Architecture
  • State of the Art Security Operations Center
  • Elite Team of Pentration Testing Ninjas

We recruit globally and search for top-tier talent to help us develop our infrastructure and platforms to create an excellent customer experience by allowing access to quality products and services from Central Group anywhere and anytime.

Read More

Services

Cyber security, IT Governance and Privacy services from leading experts to provide excellence to Central Group

Managed Detection & Response

The solution combines expert-driven EDR for proactive device protection, SIEM for behavior-based threat detection, SOAR for automated response, and open-source tools for threat investigation. A talented team of dedicated CISO security experts monitors, detects, and mitigates attacks. Additionally, this expert team delivers tailored threat analysis and response strategies, handling the impacts and challenges of any potential cybersecurity incidents for your organization.

VAPT Services

Vulnerability Assessment and Penetration Testing (VAPT) services provide a comprehensive evaluation of security weaknesses in an organization’s IT infrastructure. Vulnerability Assessment identifies potential flaws, while Penetration Testing simulates real-world attacks to exploit those weaknesses. Together, VAPT ensures robust protection by detecting, analyzing, and mitigating security risks.​

VCISO

Advisory, assessment, strategic and solution generation in a wide range of expert domains, including but not limited to: security and privacy roadmap planning, board and ac management advisory, policy and standards advisory, both regulatory and non-regulatory compliance advisory, risk advisory, new project consultation, privacy management, PDPA consultation, security risk assessment, security architecture review, third-party due diligence, penetration testing & wider vulnerability management program advisory, security operations management, incident management, business crisis management advisory

DPO as a Service

Provide Personal Data Protection Act (“PDPA”) consultation and PDPA documentation review (e.g., Record of Processing Activity (ROPA), Privacy Notice, and consent wording, etc.). Conduct gap analysis and provide remedial action plan to ensure PDPA compliance. Advice on handling Data Subject Right Request (DSR) and acting as an official point of contact with authority and data subject on all data protection matters. Conduct a data breach assessment and notify Personal Data Protection Committee (PDPC) within 72 hours of becoming aware of the breach (if needed), including notifying data subject without undue delay (if needed). Registration as DPO with PDPC and monitor/update related laws and regulations

PDPA Inventory & ROPA

Provide and maintain PDPA inventory and ROPA management tool to assist all BUs in PDPA compliance.

DSR Fulfilment

Provide and maintain DSR management tool to assist BUs in DSR handling to comply with PDPA.

Security Risk & Compliance

A comprehensive governance practice to manage security risks and compliance, ensuring the organization stays secure and aligned with industry standards. This service focuses on three key areas:


Compliance Program: Develop and update security policies to meet industry best practices and regulations. Lead awareness campaigns, facilitate security control assessments, and provide compliance dashboards for easy tracking.

Proactive Risk Management: Implement IT security frameworks to identify and mitigate risks, leveraging lesson learn from incidents to improve security controls. Maintain risk dashboards to keep executives informed.

Security Expert Advisory: Offer guidance on secure IT implementations, architecture, and audit findings. Provide ad-hoc security expertise to address specific concerns.

Learning Management System

Combining interactive security awareness training, informative webinars, and eye-catching e-posters with key security messages to keep employees informed, vigilant, and proactive in protecting valuable data and systems from evolving security threats. Furthermore, the program incorporates engaging phishing simulations to test their ability to identify and report suspicious emails. This comprehensive approach empowers employees to become active participants in protecting our valuable data and systems from cyber-attacks.

Developer Security Training

Comprehensive training program and platform tailored to developers' needs, covering industry best practices for secure coding, vulnerability identification, and secure application design. This training equips your developers to build secure applications from the ground up, reducing the risk of security breaches and protecting your valuable data.

Zero Trust Network

Solution designed to ensure that users are fully identified and authorized to access web applications. This solution will provide robust security even to legacy applications that were not designed to comply with modern requirements, significantly reducing the risk of unauthorized access, data breaches, and other security incidents related to privileged accounts.

Standard Email Protection

A cost-effective solution named SpamTitan to provide an Email security baseline. This gateway is specifically designed to work with mailboxes using Office365 to screen out Phishing and other malicious emails before they get in your mailboxes.

Advanced Email Protection

Powerful solution integrated in Office 365 and designed to provide advanced protection against sophisticated email attacks which supports organization throughout the attack cycle. not just screen and prevent but also investigate and stop the spreading.

We Are Hiring!

The CISO Group is immediately staffing the following postions:

 Senior Penetration Tester
 Vulnerability Manager
 Principle Security Architect

Workstation

Your choice of a Windows or Macbook Pro laptop

Working Hours

The CISO Group has flexible working hours. Typically we start work between 9 and 10 AM and work until about 6 PM. Monday through Friday only!

Location

Our office is located at Central Rama 9, conviently located next to the Rama 9 MRT station

Perks

Two days Work From Home and free paper towels in the toilets!

Our Office

Our state of the art office and CSOC (Cyber Security Operations Center) is a high-tech command hub equipped with advanced monitoring tools, real-time threat detection systems, and teams of analysts working to safeguard digital assets and respond to security incidents 24/7.

  • All
  • CSOC
  • Office
  • Team

CSOC

State of the Art CSOC

CSOC

State of the Art CSOC

Product 1

Lorem ipsum, dolor sit

Branding 1

Lorem ipsum, dolor sit

App 2

Lorem ipsum, dolor sit

Product 2

Lorem ipsum, dolor sit

Team 1

Our team having a great time

App 3

Our team having a great time

Product 3

Our team having a great time

Team 4

Our team having a great time

What we have achieved so far

CISO team makes a difference.

Clients

Projects

Hours Of Support

Team Members

Contact

Do you have questions or think you have what it takes to be part of our team?

Address

9/9 Rama IX Rd, Huai Khwang, Bangkok 10320

Call Us

+1 5589 55488 55

By clicking "Send Message" below, you acknowledge that you and read and understood our Privacy Policy