Senior Manager, Information Security

2 weeks ago


Shanghai, Shanghai, China VF Corporation Full time

Let's Talk about the Role

The Cyber Security Senior Manager will support VF's Global Cyber Security Team by ensuring that information security risks associated with complex business operations are within acceptable tolerances.

You will perform information security risk assessments, provide direction and guidance to stakeholders concerning the handling of security risks associated with assessment findings, assist with the design of appropriate risk mitigation strategies, and serve as an audit quality assurance gate for internal and external auditors while driving compliance and audit work related to data privacy.

How You Will Make a Difference

You will achieve this by:

· Conduct the annual MLPS audit for 6 critical applications in VF China;

· Work together with vendor and internal team to review the existing system settings against MLPS standards, take remediation prior to/after onsite audit, make sure VF China pass the audit with increased audit scores.

· Work together with legal/compliance team to follow up on related updates of regulatory requirements regarding CBDT and data privacy, and make sure necessary actions are taken to address the changes

· Support global team to conduct the PCI audit project in APAC region, including store sampling, interview arrangement (translation), supporting preparation, clarification, etc.

· Work together with retail operation team to ensure the remediation actions are taken properly, i.e. updating of SOP, training enhancement, etc.

· Prisma China license purchase

· Follow up on the findings from Cloud Security Assessment project

· Monitor the active tickets on ServiceNow to make sure they are followed up timely by responsible personnel.

· Make sure the PO contact list is up to date.

· If needed, work together with vendors/in-house developers to make sure the remediation is well implemented.

· Conduct the vendor assessment with RSAM and Idea portal

· Besides the RSAM/idea portal review, enforce ""security by design"" by being part of the application development and sprint to ensure that security is in all phases of the application development lifecycle

· Arrange prior go live scanning and ensure all critical/high issues are fixed system launch

· Participate in the various milestones of project implementation to support the remediation of gaps

· Review RPA/AI related features according to VF standards

· Support the usage of MIP in APAC

· Collect the user feedback and support the continuous improvement

· Support the phishing simulation in APAC

· Based on the result of simulation, work together with SETA team to improve the reporting rate

· Support global SETA team on the CSAM related activities.

· Support the roll out of security training in APAC

· Support the completion of security awareness training and make sure the coverage

· Work together with legal team to hold the Data Privacy and InfoSec SteerCo Meeting on a regular base

Skills for Success

A formal education and subsequent University Bachelor or Master's degree in information systems, computer science, or related field are preferred, but we are most interested in your total experience and professional achievements. That's why:

· You rely on 5+ years of information security risk management, IT audit, and/or IT controls design and implementation experience.

· You possess a Certified Information Systems Security Professional (CISSP) certification, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or similar credentials.

· You are familiar with industry best practices related to security and data privacy in Cloud environments.

· You have functional understanding of industry frameworks, regulations, legislation, and audit methodologies, including SOC 1, SOC 2, ISO 27001, SIG, NIST Cybersecurity Framework, Sarbanes-Oxley (SOX), PCI-DSS, MLPS and various other privacy laws.

· You are apt to broker complex discussions to achieve the proper balance between business needs and cybersecurity best practices.

· You possess the ability to influence others through persuasion to arrive at desired outcomes.

· You communicate effectively with a broad range of people and roles, including vendors, information technology professionals, and other business personnel.

· You desire to seize the initiative, operate proactively, and work in a highly independent manner.

· You are fluent in English and Mandarin, any other Asian languages are a plus.

R

  • Shanghai, Shanghai, China Smith+Nephew Full time

    Smith + Nephew is seeking an experienced Information Security professional to take on a role as primary Security Lead for China operations. The successful candidate will provide in-country support and guidance to the local IT and Business teams, applying Global Information Security Strategy and Governance, and manage compliance with China Cybersecurity Law...

  • Security Manager

    2 weeks ago


    Shanghai, Shanghai, China ASML Full time

    Description Collaborate and support our business stakeholders on information security inquiries and embedding information security in the 1st line; Translate security requirements from our security policies delivered by the 2nd line of responsibility (RBA), into practical guidance and balance this with business needs; Coordinate and execute security...


  • Shanghai, Shanghai, China FedEx Full time

    Education: Bachelor's degree in Engineering, Computer Science, Electronics and Mathematics orrelated disciplineExperience: Five (5) years of work experience in information security, including two (2) years with appropriate operating systems/softwareEducation: Bachelor's degree in Engineering, Computer Science, Electronics and Mathematics orrelated...


  • Shanghai, Shanghai, China Philips Full time

    Job TitleSenior Cyber Security AnalystJob DescriptionSenior Cyber Security AnalystWe are seeking a highly skilled and experienced Senior Cyber Security Analyst to join our Group Security organization in China. The ideal candidate will be responsible for participating in daily Security Operations Center (SOC) incidents, as well as longer term activities...


  • Shanghai, Shanghai, China Philips Full time

    Job TitleSenior Cyber Security AnalystJob DescriptionSenior Cyber Security AnalystWe are seeking a highly skilled and experienced Senior Cyber Security Analyst to join our Group Security organization in China. The ideal candidate will be responsible for participating in daily Security Operations Center (SOC) incidents, as well as longer term activities...


  • Shanghai, Shanghai, China Logicalis Full time

    Why choose Logicalis? As Architects of Change, Logicalis' focus is to design, support and execute clients' digital transformation by uniting their vision with their technology expertise and industry insights. The company, through its deep understanding of key IT industry drivers such as security, cloud, data management and IoT, can address customer...


  • Shanghai, Shanghai, China Logicalis Full time

    Why choose Logicalis? As Architects of Change, Logicalis' focus is to design, support and execute clients' digital transformation by uniting their vision with their technology expertise and industry insights. The company, through its deep understanding of key IT industry drivers such as security, cloud, data management and IoT, can address customer...


  • Shanghai, Shanghai, China Logicalis Full time

    Why choose Logicalis? As Architects of Change, Logicalis' focus is to design, support and execute clients' digital transformation by uniting their vision with their technology expertise and industry insights. The company, through its deep understanding of key IT industry drivers such as security, cloud, data management and IoT, can address customer...


  • Shanghai, Shanghai, China Riot Games Full time

    Responsibilities: Manage and maintain the measurement to monitor and report on the control effectiveness in all information security area in China Ensure the local security governance fulfillment, e.g. MLPS Conduct security risk management tasks and collaborate with teams of different functions to encourage the security concept across the business...


  • Shanghai, Shanghai, China Thermo Fisher Scientific Full time

    By enabling our product development and sustainment teams, you will help ensure that Thermo Fisher products are developed and tested against security standards, further helping our customers to make the world healthier, cleaner and safer. The Role The shares the responsibility for security associated with the company's Product Security program. They...


  • Shanghai, Shanghai, China PUMA Full time

    YOUR MISSIONThreat Assessment and Management: Continuously monitor and evaluate the IT environment for potential security threats and vulnerabilities. Implement measures to prevent, detect, and respond to cyber incidents.Policy Development and Enforcement: Develop, implement, and maintain company-wide IT security policies and procedures. Ensure these are in...


  • Shanghai, Shanghai, China Thermo Fisher Scientific Full time

    Work ScheduleOtherEnvironmental ConditionsOfficeJob DescriptionWhen you're part of the team at Thermo Fisher Scientific, you'll do important work, like helping customers in finding cures for cancer, protecting the environment or making sure our food is safe. Your work will have real-world impact, and you'll be supported in achieving your career goals.This...


  • Shanghai, Shanghai, China Thermo Fisher Scientific Full time

    Work ScheduleOtherEnvironmental ConditionsOfficeJob DescriptionWhen you're part of the team at Thermo Fisher Scientific, you'll do important work, like helping customers in finding cures for cancer, protecting the environment or making sure our food is safe. Your work will have real-world impact, and you'll be supported in achieving your career goals.This...


  • Shanghai, Shanghai, China Thermo Fisher Scientific Full time

    Work ScheduleOtherEnvironmental ConditionsOfficeJob DescriptionWhen you're part of the team at Thermo Fisher Scientific, you'll do important work, like helping customers in finding cures for cancer, protecting the environment or making sure our food is safe. Your work will have real-world impact, and you'll be supported in achieving your career goals.This...


  • Shanghai, Shanghai, China Marriott International Full time

    JOB DESCRIPTIONLead and oversee the security architecture and engineering team for the Greater China region. Certification of Security Control attestations and assessment of control implementation to grant Approval for new infrastructure, services, applications, and processes in Marriott's Production Environments. Utilize Security Engagement processes,...


  • Shanghai, Shanghai, China Johnson & Johnson Full time

    Main responsibilities The Senior Privacy manager of Johnson & Johnson (J&J) in China is responsible for providing practical, timely, strategic, and high-quality counseling on applicable cybersecurity, data security and other related laws, regulations & guidelines with a focus on cybersecurity and data security as it impacts Company Business, cross border...

  • Senior Privacy Manager

    2 months ago


    Shanghai, Shanghai, China Johnson & Johnson Full time

    Main responsibilities The Senior Privacy manager of Johnson & Johnson (J&J) in China is responsible for providing practical, timely, strategic, and high-quality counseling on applicable cybersecurity, data security and other related laws, regulations & guidelines with a focus on cybersecurity and data security as it impacts Company Business, cross border...


  • Shanghai, Shanghai, China Continental Full time

    Continental is a leading technology company that focuses on creating innovative solutions for sustainable and connected mobility. With a rich history dating back to 1871, Continental is dedicated to providing safe, efficient, and affordable products for vehicles, machines, traffic, and transportation. The company generated sales of €33.8 billion in 2021...


  • Shanghai, Shanghai, China Continental Full time

    Continental is a leading technology company that focuses on creating innovative solutions for sustainable and connected mobility. With a rich history dating back to 1871, Continental is dedicated to providing safe, efficient, and affordable products for vehicles, machines, traffic, and transportation. The company generated sales of €33.8 billion in 2021...


  • Shanghai, Shanghai, China Bureau Veritas Group Full time

    Responsibilities: In charge of overseeing the entire Industrial Cyber Security service development process and responsible for yearly service revenue Ensure BV China Operations' compliance with product accreditation and related regulations, and contribute to international accreditations management Aid in crafting the marketing and sales strategy for...