更新于 今天

China Security Engineer

2.5-3万
  • 大连甘井子区
  • 5-10年
  • 本科
  • 全职
  • 招1人

雇员点评标签

  • 同事很nice
  • 团队执行强
  • 工作环境好
  • 人际关系好
  • 氛围活跃
  • 实力大公司

职位描述

药企
Security & Compliance (PIPL, DSL, CSL)
● Requires exceptional knowledge of Security standards and advanced knowledge of others and applies these skills to ensure the Business Units in China meets its goals
● Creates an environment where innovation is standard taking appropriate risks to advance innovative processes
● Interpret and apply China regulatory requirements into actionable IT controls.
● Ensure personal data of Chinese citizens is localized within Mainland China.
● Establish and maintain security policies, compliance documentation, and audit evidence.
● Provide guidance on cross-border data transfer approvals, security assessments, and contractual obligations.
Cloud Infrastructure Security
● Manage cloud accounts in AWS China, Azure China, or equivalent providers.
● Implement and maintain IAM, KMS, encryption, VPC security, logging, and monitoring.
● Conduct regular vulnerability assessments, patch management, and threat detection.
● Ensure secure backup, recovery, and disaster recovery solutions are in place.
Separation of Duties & Access Control
● Enforce strict RBAC policies between global and local teams.
● Review and audit privileged access accounts.
● Ensure compliance with least privilege principles and monitor access logs.
● Drive remediation of any separation of duties violations.
Collaboration with Local Application Teams
● Work with China application and infrastructure teams to ensure compliance controls are built into solutions.
● Review application architectures for data residency and PIPL compliance.
● Support secure IDLC and cloud-native security practices.
Audit & Risk Management
● Act as the primary point of contact for internal and external auditors in China.
● Conduct and support periodic compliance reviews and penetration tests.
● Track findings and ensure timely remediation.
● Develop and maintain compliance dashboards and risk registers.
Global Collaboration
● Align China-specific compliance requirements with global security policies (ISO 27001, NIST, GDPR).
● Share regular updates, risks, and compliance status with global leadership.
● Support global security projects while ensuring China regulatory requirements are not compromised.
BASIC QUALIFICATIONS
● Education: Bachelor’s degree in Computer Science, Information Security, or related field.
● Experience: 4+ years in cloud security, compliance, or audit roles.
● Technical Skills:
● Hands-on with AWS China / Azure China security features.
● Strong knowledge of IAM, encryption, SIEM, CSPM, DLP, vulnerability management.
● Familiar with DevSecOps practices.
● Compliance Knowledge:
● Deep understanding of China PIPL, DSL, CSL.
PREFERRED QUALIFICATIONS
● Experience with ISO 27001, GDPR, SOC2, or equivalent frameworks is a plus.
● Soft Skills:
● Strong stakeholder management and communication skills.
● Ability to work with both local Chinese teams and global counterparts.
● Fluent in Mandarin and English.
Work Location Assignment: On Premise
Pfizer is an equal opportunity employer and complies with all applicable equal employment opportunity legislation in each jurisdiction in which it operates.
Information & Business Tech

工作地点

大连甘井子区海创国际产业大厦

职位发布者

王先生/区域招聘及入职交付

当前在线
立即沟通
公司Logo辉瑞投资有限公司
辉瑞公司(Pfizer Inc.)创建于1849年,总部位于美国纽约,是一家以科学为基础的、创新的、以患者为先的生物制药公司。辉瑞的使命是“为患者带来改变其生活的突破创新”。在辉瑞,我们通过科学和全球资源为人们提供治疗方案,以延长其生命,显著改善其生活。在医疗卫生产品的探索、研发和生产过程中,辉瑞始终致力于奉行严格的质量、安全和价值标准。我们在全球的产品组合包括创新药品和疫苗。每天,辉瑞在发达和新兴市场的员工都在推进人类健康,推动疾病的预防、治疗和治愈,以应对挑战我们这个时代的顽疾。辉瑞还与医疗卫生服务方、政府和社区合作,支持并促进世界各地的人们能够获得更为可靠和可承付的医疗卫生服务。这与辉瑞作为一家全球卓越的创新生物制药公司的责任是一致的。170余年来,辉瑞一直致力于为所有依赖我们的人带来改变。辉瑞于1989年进入中国市场。扎根中国30余年,辉瑞已成为在华主要的外资制药公司之一。2021年是辉瑞新征程的开始。迄今已有170余年历史的辉瑞正在迈入全新时代,成为一家以科学为基础的、创新的、以患者为先的生物制药公司。目前辉瑞在中国业务覆盖全国300余个城市,累计投资超过15亿美元,并设立了1家先进的生产设施,2个研发中心(分别位于上海张江高科技园区和武汉光谷),在华有近7,000名员工分布于业务、研发和生产等领域。辉瑞在华上市了五大领域的高品质创新产品,包括肿瘤、疫苗、抗感染、炎症与免疫、罕见病等多个领域的处方药和疫苗,强大完善的产品线旨在满足生命各阶段的健康需求。
公司主页