岗位职责:
1.Assist establishing and maintaining the information security management system, technical system and operation system, so as to meet various compliance requirements and achieve the company's information security risk management goals.
协助完成信息安全管理体系、技术体系和运营体系的建设与维护,满足各项合规要求,实现公司信息安全风险管理目标。
2.Assist to identify the relevant laws and regulations, shareholder requirements, business needs, complete compliance interpretation and gap analysis, update the information security policies and coordinate relevant departments to formulate rectification plans, track the implementation of rectification, and ensure information security compliance.
协助识别相关法律法规、监管要求、股东方要求,完成合规解读、差距分析和安全策略更新,并协调相关部门制定整改计划,跟踪整改落地,确保信息安全合规性
3.Assist to develop and maintain the information security management system, including establish policies, process, standards and work instructions for the information security management system, and complete the dissemination, training and supervision and inspection of the management system to ensure that the system meets regulations and is effectively implemented.
协助建设维护信息安全管理体系,包括相关政策、程序、标准和工作指引文件,并完成管理体系的宣贯、培训和监督检查,确保管理体系有效执行满足合规要求
4.Assist to develop and maintain information security technology architecture and SOC to achieve company business continuity and information security management objectives.
协助建设和维护信息安全技术架构和安全运营中心,实现公司业务连续性和信息安全管理目标
5.Assist to plan and carry out employee information security awareness training and activities, ensuring that all employees complete the relevant course studies, enhancing their information security awareness.
协助规划和执行员工信息安全意识教育活动,确保所有员工完成相关课程学习,提高信息安全意识
6.Use professional methodology and tools to manage supplier behavior and performance, ensuring that their delivery content and delivery quality meet the IT requirements.
使用专业的方法论工具对供应商的行为和绩效进行管理,保证供应商的交付内容和交付质量符合IT要求
7.Monitor the project progress, control the deviation and risk, escalate to higher level supervisor in case it's needed.
监控项目进度,控制偏差和风险,并在必要的时候升级至更高层级的管理人员
任职要求:
1. Knowledge of latest regulatory and legal requirements on information security, PIPL, CSL, DSL, GDPR, etc
了解最新的法律法规和监管要求,包括网络安全法、数据安全法、个人信息保护法、GDPR等
2. Knowledge of ISO27001, TSAX, MLPS, SOX or other information security standards.
了解ISO27001、TISAX、网络安全等级保护、SOX等相关信息安全标准
3. Knowledge of key issues regarding IT Security and Information Risk Management (Data Security, Endpoint Security, Security operations, Data Privacy, security development, Incident emergency response, ICV cyber security etc.)
了解信息安全风险管理关键领域(数据安全,终端安全,安全运营,漏洞管理,数据隐私,安全开发,应急响应,ICV网络安全等)
4. Typically a background in technical security roles or operations, with a clear and abiding interest in security;
具有安全技术的背景,对安全有明确和持久的兴趣