Key ResponsibilitiesDefine and review system security architecture, conduct threat modeling, and map risks to controls.Ensure compliance with IM8, WOG security policies, and PDPA; maintain SRAs, VAs, PTs, and hardening reports.Oversee secure development and DevSecOps practices, including SAST/DAST and container scanning.Guide API security, token/secret management, and secure service-to-service communication.Plan, manage, and track vulnerability assessments, penetration tests, and security certif