Business Security Manager

AirAsia

Tangerang

On-site

IDR 900,000,000 - 1,500,000,000

Full time

45 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flight benefits
Medical insurance
Career development

Job summary

AirAsia Indonesia is seeking a Business Security Manager to lead cybersecurity across the business, reporting to the Group CISO. You will coordinate governance, risk, and compliance programs and ensure local systems meet ISO 27001, PCI DSS, and other standards.

You will collaborate with technical teams and business units, drive security into projects, manage incidents, and support business continuity. This is a demanding role requiring strong communication and leadership in a fast-paced aviation

Qualifications

  • Bachelor's degree in IT, IT-business, CS or equivalent.
  • 8–10 years in information security governance, risk, or compliance.
  • Certs like ISO 27001, CISSP are advantageous.

Responsibilities

  • Lead cybersecurity across the business in Indonesia, aligning strategy with objectives.
  • Oversee governance, risk, and compliance; ensure regulatory requirements are met.
  • Manage incident response and post-incident actions.
  • Engage with local regulators and audits; coordinate training and awareness.

Skills

Cybersecurity leadership
Stakeholder management
Strategic risk assessment
Communication skills
Change management

Education

Bachelor's Degree in Information Technology or related field

Job description

As a Business Security Manager at Indonesia AirAsia, you will report directly to the Group CISO to provide advice, consultation, and awareness of the Group Information Security requirements to technical teams and other employees, and ensure their implementation. You will be responsible for ensuring internal systems and processes in Indonesia are compliant with information security standards (e, g, ISO 27001, PCI DSS, CIS, NIST CSF, etc); monitoring, managing, and closing information security compliance issues. Other responsibilities include identification, evaluation, and interpretation of standards, regulatory, statutory, and member security requirements, control deficiencies, and information security risks. You are the primary point of contact during information security incidents and are responsible for managing the incident.

WHAT YOU'LL CHAMPION:
Stakeholder Collaboration and Management
  • Acts as the primary cybersecurity leader across the business for Indonesia, aligning enterprise cybersecurity strategy and roadmap with business objectives.
  • Drive and prioritise implementation and integration/adoption of security capabilities within the BU, including embedding security into business digital projects and operations.
  • Ensure the business-specific threat landscape, risks, and regulatory drivers are clearly articulated to the CISO teams and validate cyber architecture decisions that meet the business’s operational and compliance needs.
  • Provide Strategic Threat Briefings to Business Leadership.
Cyber Governance Risk Compliance(In-Country)
  • Operationalise Cyber Security Risk Management capabilities such as Business Impact Assessment of the Business unit’s digital portfolio of services and applications to identify Crown jewels to be protected in line with Risk appetite.
  • Deployment of relevant cybersecurity controls, including required local regulatory compliance, to ensure digital solutions, both applications and services, are developed with a secure-by-design principle.
  • Drives Cyber Risk acceptance, risk mitigation, finding management processes, and risk reporting consistently to ensure Cyber Risks are managed and residual risks understood by the leadership.
  • Represent cybersecurity in external audits, customer security reviews, and regulatory submissions.
  • Actively involved and drive preparations in Business Continuity and Disaster Recovery drills for critical business processes and crown jewels.
  • Work with the in-country Data Protection Officer(s) of AirAsia Aviation on data security requirements.
Cyber Defence (In-Country)
  • Work with Enterprise Cyber Defence to ensure business assets (e.g., endpoints, network devices, applications, business users, etc.)are updated for purposes of security monitoring and vulnerability management
  • Coordinate business communication, impact analysis, business post-incident review, and remediation with the business teams and in compliance with local regulations
Change Management
  • Champion Cyber Security Change program activities to drive awareness, behaviours among the business unit, and increase the Cyber Resilience
  • Drive implementation and integration/adoption of security capabilities and change management to ensure business alignment and effectiveness.
  • Business-level security KPIs/KRIs (e.g., patch compliance, phishing click rates, third-party risk ratings) dashboards, reports to business leaders, and the enterprise CISO.
WHO YOU ARE:
  • Bachelor's Degree in Information Technology, or Business with IT, Computer Science, or equivalent
  • Minimum 8-10 years of experience in managing Information Security Governance, Risk Management, and Compliance, Projects/Change Management or related fields
  • Relevant industry certification is an advantage (ISO 27001, CISA, CISSP, CGEIT, etc.)
  • Working knowledge of common IT/information security-related regulations or standards, especially ISO 27001 and PCI-DSS
  • Working knowledge of local information and cybersecurity-related regulations and requirements is a huge advantage
  • Ability to develop, review, and maintain documentation in a timely manner
  • Strong communication (spoken and written), interpersonal, and conflict resolution skills. The ability to establish and maintain rapport with stakeholders is highly desired.
  • Strong analytical and critical thinking skills
  • Result-oriented, high level of attention to detail, self-starter and motivator, ability to multitask and adjust to shifting priorities.
WHERE YOU'LL GO:

Dispatcher to captain, ramp agent to data analyst, brand executive to CEO - these are some Dare To Dream stories of our Allstars.

Based on your performance and contribution in this role, you'll grow into becoming a Sr Business Security Leader / Regional Cyber Security Manager. In this role, you'll drive cybersecurity strategy across multiple markets, influence enterprise-level security decisions, and shape the future of cyber resilience within Capital A.

WHAT YOU'LL ENJOY:
  • Physical Wellbeing: Key medical and insurance benefits, maternity expenses, flexible work arrangements, and health and fitness amenities.
  • Emotional Wellbeing: Paid time off, wellness programmes, and childcare amenities.
  • Financial Wellbeing: Resources relating to financial, personal skills and career growth programmes.
  • Allstars Specials: Free flights, unlimited discounted flights, and exclusive discounts with partners.
  • A unique Allstar culture like no other
OUR HIRING PROCESS:
  • Application received
  • Interview(s) and assessment(s)
  • Background check and/or other assessments
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Security Manager - Indonesia
Business Security Manager - Indonesia

AirAsia Indonesia • Tangerang

On-site
IDR 1,500,000,000 - 2,300,000,000
Medical & insurance benefits
Paid time off
Career development & training
+1
Senior Cybersecurity Governance & Risk Leader
Senior Cybersecurity Governance & Risk Leader

AirAsia • Tangerang

On-site
IDR 900,000,000 - 1,500,000,000
Flight benefits
Medical insurance
Career development
Cyber Risk & Compliance Leader (In-Country)
Cyber Risk & Compliance Leader (In-Country)

AirAsia Indonesia • Tangerang

On-site
IDR 1,500,000,000 - 2,300,000,000
Medical & insurance benefits
Paid time off
Career development & training
+1
Information Security Specialist
Information Security Specialist

AIA Indonesia • Jakarta Pusat

On-site
IDR 90,000,000 - 130,000,000
Regional Protective Services Manager ASEAN
Regional Protective Services Manager ASEAN

Accenture Southeast Asia • Jakarta Pusat

On-site
IDR 600,000,000 - 900,000,000
Regional Protective Services Manager ASEAN
Regional Protective Services Manager ASEAN

Accenture • Jakarta Pusat

On-site
IDR 800,000,000 - 1,200,000,000
Cybersecurity & Compliance Analyst
Cybersecurity & Compliance Analyst

MixWork Pte. Ltd. • Jakarta Selatan

On-site
IDR 360,000,000 - 600,000,000
Flexible Medical Benefit
Daily Allowances
Workstation Provisioning
+1
Material Manager
Material Manager

AirAsia Indonesia • Tangerang

On-site
IDR 156,240,000 - 256,680,000
Inspector, Quality Assurance
Inspector, Quality Assurance

AirAsia Indonesia • Tangerang

On-site
IDR 167,400,000 - 334,800,000
Admin & Support Officer
Admin & Support Officer

AirAsia Indonesia • Tangerang

On-site
IDR 180,000,000 - 300,000,000