IT Security Manager-GRC, APAC
柯锐世(上海)企业管理有限公司
- 公司规模:500-1000人
- 公司性质:外资(欧美)
- 公司行业:汽车零配件
职位信息
- 发布日期:2019-10-21
- 工作地点:上海
- 招聘人数:1人
- 工作经验:5-7年经验
- 学历要求:本科
- 职位月薪:4-5万/月
- 职位类别:其他 网络信息安全工程师
职位描述
RESPONSIBILITY LEVEL:
The Security Manager, GRC, will drive IT projects related to implementation of governance, risk and compliance (GRC) capabilities, primarily as it pertains to Chinese Cybersecurity Law (CSL) in the APAC region. The focus of the Security Manager will be to work with the selected external consulting firm to ensure the proper implementation of CSL and its ongoing operational effectiveness. This role will proactively communicate status and escalations, and solicit assistance as required, of GIS leadership, IT leadership, as well non-IT leadership. This role will be involved in external-facing communications, related to security incidents, as required by law.
Support of global GRC initiatives will be required as needed, including:
- Sarbanes Oxley
- Payment Card Industry
- Internal and External Audit
- Global Risk Management Framework
- Global Policy and Standard Lifecycle
- Global Information Security Training
DUTIES:
· Responsible and accountable for the proper implementation of CSL, including day to day tasks such as planning and coordination between various internal and external parties, preparing status reports, ensuring key performance indicators (KPI’s) are achieved, and escalating concerns that may lead to non-compliance.
· Responsible for implementation of tools and processes that support CSL globally, as determined by the CSL assessment project.
· Coordinates closely with other IT towers and the business to ensure alignment of GIS expectations especially as it relates to CSL and the APAC region’s security.
· Acts as a go-to person within IT to provide guidance, clarity and direction on GRC-related expectations and requirements.
· Communicates clearly and effectively to diverse technical staff with varying backgrounds to discuss complex problems and resolve appropriately.
· Performs research, validation and evaluation of governance risk and compliance best practices and assist in defining strategy and deployment planning. Responsible for maintaining a close working relationship with the information technology organization and business representatives in order to properly implement a program that meets business needs.
· Stays current on all enterprise and regional application development and implementation projects to help ensure global policies and standards are proactively and properly considered.
· Provides management with accurate and complete status information.
· Maintains an understanding of key business initiatives to provide effective consulting services, both solicited and unsolicited.
·
REQUIREMENTS/QUALIFICATIONS:
· Bachelor’s degree or related experience in IT, MIS, computer science, or related technology discipline.
· Strong working capability with PowerPoint, MS Word and MS Excel.
· Experience with manufacturing ERP systems, including SAP and QAD (Mfg Pro).
· Must have working knowledge and experience with the requirements and implementation of Chinese Cybersecurity Law or extensive experience in security architecture.
· Must have appropriate executive presence, professionalism, and communication skills to coordinate with various levels of IT and operational leaders.
· Minimum 8 years’ experience in IT, with direct involvement one or more of the following: security operations, security architecture, IT risk management and/or compliance programs, such as SOX, and/or IT Internal/External Audit.
· Professional certification of CISA, CISM, CISSP, or related certification, or willingness to work toward this within one year.
· Experience and understanding of manufacturing industry, including how IT supports and enables the success of the business and how security and compliance can positively and negatively impact business operations.
· Strong project management skills and global experience.
· Ability to establish high levels of trust and confidence by internal customers within IT, business and audit functions.
公司介绍
柯锐世是全球***的汽车电池回收者,每小时在全球回收8000块电池,通过使用可回收的原料降低90%能源消耗和温室气体排放量。
柯锐世的56个制造、回收和配送中心遍布全球,为超过150个国家的客户提供服务,是宝马、奔驰、奥迪、保时捷等诸多原厂原配电池。
柯锐世2018年销售1.54亿块电池。