Senior Privacy Manager

4 weeks ago


Shanghai, Shanghai, China Johnson & Johnson Full time

Main responsibilities

The Senior Privacy manager of Johnson & Johnson (J&J) in China is responsible for providing practical, timely, strategic, and high-quality counseling on applicable cybersecurity, data security and other related laws, regulations & guidelines with a focus on cybersecurity and data security as it impacts Company Business, cross border operations as well as new commercial models.

The Individual, as a core member of the J&J China Privacy team, shall be primarily responsible for providing robust regulatory and operational support related to the implementation and monitoring of the Company's specific data security and cybersecurity compliance programs across J&J sectors in China, identifying cyber and data security risks and working closely with the J&J DPO, J&J Data Security officer (DSO), Information security team (ISRM) and global Data Protection Legal Team (DPLT) to develop controls, policies & procedures, and trainings to ensure the Company is operating in compliance with applicable Cybersecurity, data security laws and related security regulations and national standards, including cross border data transfer measures, as well as J&J policies and data security framework.

In this role, the Individual shall have opportunity to actively support, shape and help implement all projects and participate in assessment and remediations measures across J&J organization in China that involve specific cybersecurity, data security considerations and risks, working closely with other J&J sectors' senior privacy managers as the need arises.

The individual shall advise on potential liability and other legal aspects related to privacy, cybersecurity and data security incidents and support the Company's data security and cybersecurity incident response programs, including supporting the investigation of potential incidents, identifying applicable legal obligations, supporting timely incident response efforts and notification to regulatory authorities, and addressing any visits, controls and follow up requests from Chinese regulatory authorities.


The position will report to the China Privacy Director /Data Privacy officer of J&J China.

Core responsibilities include:


1. Provide practical, timely, strategic, and high-quality counseling on cybersecurity, data security and related matters across the Company.

  • Monitor closely any new developments in China cybersecurity, data security laws and impact on other related regulations/standards/programs, ensure timely reporting to China DPO, DPLT, ISRM and other J&J functional teams.
  • Provide legal support to interpret any new cybersecurity and data security laws & regulations and analyze the impact to JNJ's business in China, including on cross border operations and specific privacy programs. Work in close coordination with external counsels where need be.
  • Partner closely with DSO/ISRM team and DPLT to develop controls, policies & procedures to ensure Company's compliance with China applicable cybersecurity and data security laws, as well as all applicable Johnson and Johnson data security and cybersecurity policies and procedures, including reporting of incidents and conducting investigations.
  • In close alignment with China DPO and privacy team , support related stakeholders at Company and Sector level on cybersecurity and data security matters , as well as partner closely with ISRM, DPLT, BU legal and other functions to proactively address data security and cybersecurity matters in China.
  • Act as the primary point of contact in China in the event of data security or cybersecurity incident in liaison with

DPLT:

  • Review and help to develop and implement timely incident response plans in the event of a data security or cybersecurity incident.
  • Coordinate the response to data security/cybersecurity incidents, including reporting obligations as per Chinese regulations, in close alignment with DPLT.
  • Attend any inspection, down raid and address follow up requests from regulatory authorities, in close alignment with DPO, DPLT, BU legal and ISRM.
  • Where applicable, provide data security and cybersecurity input on corporate projects including any acquisitions, divestitures, licensing and development terms that involve data security requirements.

2.

Support the strategic implementation of data security and cybersecurity programs in China:


Ã
Support China Data Security Officer and Information security partners for successful continuous implementation and advise on any change in regulation impacting Company cybersecurity program (CSL) and related national security standards (including for new systems) in China


Ã
Support China Data Security Officer and Information security partners in implementing strategic DSL Compliance Program to meet China DSL regulations and other related measures.



  • Partner with and assist DSO/ISRM and DPLT to self-identify the Important Data for J&J once the applicable Important Data Catalog is officially released, create an inventory list of the Important Data, and complete the governmental filing of the Important Data inventory list.
  • Provide legal support to internal regular security assessment for processing of the Important Data, assist the governmental filing of the risk assessment report for processing of the Important Data, and advise on risk mitigation strategies.
  • Work closely with China DPO, ISRM, JJT and DPLT to draft and file for CBDT CAC security assessment of the Important Data and other related obligations.
  • Support DSO/ISRM and JJT to complete data categorization and data classification for J&J China.
  • Partner with DSO/ISRM and DPLT to establish internal control policies, systems & technical measures that prevent leakage, abuse, misuse of J&J data and protects the confidentiality of J&J files.
  • Collaborate with the ISRM team to identify and address potential security vulnerabilities.
  • Act as the legal partner of the DSO of J&J China towards the government authorities, provide legal support to DSO during government regulatory bodies' visits and down raids inspections, assist DSO in implementing, maintaining and monitoring the data security and cybersecurity compliance program for J&J China.
Ã
Collaborate with China DPO and privacy team to address and comply with PI audit regulations and any government filing requests related to data security or cybersecurity matters

3. Provide day to day base business data security and cybersecurity support for global and local projects involving China market.

  • Support the DPLT in Review of global projects involving specific data security/cybersecurity considerations in China
  • Advising the local teams on strategic security requirements needed at project level when data localization is foreseen or requested by government regulatory authorities in China (e.g., CaC)
  • Support J&J China Privacy team and review of specific data security or cybersecurity concerns or escalation related to J&J China third parties: this includes supporting data classification, compliance analysis, participate in internal compliance review processes with copy review of necessary stakeholders before digital asset launch, e.g. BPRA, CA, etc.
  • Support Contract review to manage risks with third parties processing JNJ data: review and negotiation of Data Safeguards Exhibit (DSE), Supplier Information Security Requirements (SISR), and related contractual data security provisions.

4. Develop local Training and Communication plan focused on data security and cybersecurity risks

  • Support the development and conducting of data security and cybersecurity training materials and other communications to increase employee understanding of Company data security policies, data protection handling practices and procedures.
  • Support GA &P, Participate in industry association groups to shape the external environment, benchmark, review and influence strategies in relation to data security and cybersecurity matters.

In this role, the Senior Privacy manager liaises with:

  • China, APAC and Global Privacy Team, mainly DPLT
  • Law Department, to assess risks related to new laws and regulations, assess responsibilities and obligations of partners, third parties, Heath Care professionals when conducting contract review
  • DSO/ISRM, to support DSL compliance program and ensure to develop and implement data security policies and procedures
  • Company's responsible person for Records and Information Management, on issues pertaining to data retention and purging of records
  • Healthcare Compliance, to ensure a data security program that fits into the overall compliance program roll out for the company
  • Corporate internal audit function to support the engagement and regularly assess the data security environment and make improvements
  • Government Affairs & Policy, to support in monitoring and shaping new privacy regulations in alignment with J&J position

  • Privacy Consultant

    2 weeks ago


    Shanghai, Shanghai, China Sony UK Technology Centre Full time

    Job Responsibilities Privacy Advice : Provide privacy input and advice on personal information handling activities focusing on human resource data for Sony group companies in China, identify areas for improvement, and make recommendations from Sony group privacy policies and applicable Chinese laws and regulations, in particular PIPL. Contract...


  • Shanghai, Shanghai, China VF Corporation Full time

    Let's Talk about the Role The Cyber Security Senior Manager will support VF's Global Cyber Security Team by ensuring that information security risks associated with complex business operations are within acceptable tolerances. You will perform information security risk assessments, provide direction and guidance to stakeholders concerning the handling...


  • Shanghai, Shanghai, China Wayfair Full time

    We're seeking highly analytical, passionate, and self-motivated individuals to join our Partner Desk team. "The Desk" drives critical components of Wayfair's supplier support strategy - our team members serve as the external ambassadors who support the supplier-partners that feed Wayfair's vast assortment, and leverage internal partners to execute our...


  • Shanghai, Shanghai, China HSBC Full time

    This role involves managing HSBC's risk, business, and regulatory priorities, aiming to enhance the organization's risk culture by implementing policies on a global scale. Key areas include data governance, management, protection, controls, and strategy for Pinnacle.We are currently looking for a skilled professional to join our team.In this position, you...

  • Category Manager

    2 weeks ago


    Shanghai, Shanghai, China Wayfair Full time

    Who We Are:Wayfair is reinventing the way people shop for their homes and our team is tasked with building a best-in-class eCommerce business across our Asia market. Externally, we manage supplier relationships, partnering to build e-commerce strategies with industry leading manufacturers and supporting them in their execution. Internally, we work closely...

  • Relationship Manager

    4 weeks ago


    Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's Degree Travel Percentage : 5 - 10%Are you ready to unleash your full potential? We're looking for people who are passionate about payments to chart Worldpay's path to being the largest and most-loved payments company in the world.About...

  • Relationship Manager

    2 months ago


    Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's Degree Travel Percentage : 25 - 50%Are you ready to unleash your full potential? We're looking for people who are passionate about payments to chart Worldpay's path to being the largest and most-loved payments company in the world.What...

  • Relationship Manager

    4 weeks ago


    Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's Degree Travel Percentage : 25 - 50%Are you ready to unleash your full potential? We're looking for people who are passionate about payments to chart Worldpay's path to being the largest and most-loved payments company in the world.What...

  • Relationship Manager

    3 months ago


    Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's Degree Travel Percentage : 5 - 10%Are you ready to unleash your full potential? We're looking for people who are passionate about payments to chart Worldpay's path to being the largest and most-loved payments company in the world.About...

  • Relationship Manager

    2 weeks ago


    Shanghai, Shanghai, China Jobs for Humanity Full time

    Job Description Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's Degree Travel Percentage : 25 - 50%Are you ready to unleash your full potential? We're looking for people who are passionate about payments to chart Worldpay's path to being the largest and most-loved payments company in...


  • Shanghai, Shanghai, China Wayfair Full time

    This position will be based in our Shanghai office. All Shanghai based employees work in the office in a hybrid capacity. Employees will work in the office at least 4 days per week and have the option to work remotely 1 day per week.Wayfair's Global Financial Operations team is seeking a Senior Analyst to join our Supplier Financial Operations Supplier team...


  • Shanghai, Shanghai, China AMEX Full time

    We're seeking highly analytical, passionate, and self-motivated individuals to join our Partner Desk team. "The Desk" drives critical components of Wayfair's supplier support strategy - our team members serve as the external ambassadors who support the supplier-partners that feed Wayfair's vast assortment, and leverage internal partners to execute our...


  • Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Travel Percentage : 10 - 15%Are you curious, motivated, and forward-thinking? At FIS you'll have the opportunity to work on some of the most challenging and relevant issues in financial and technology. Our talented people empower us, and we believe in being part of a...


  • Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Travel Percentage : 10 - 15%Are you curious, motivated, and forward-thinking? At FIS you'll have the opportunity to work on some of the most challenging and relevant issues in financial and technology. Our talented people empower us, and we believe in being part of a...

  • Senior Sales Manager

    4 weeks ago


    Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's DegreeAre you curious, motivated, and forward-thinking? At FIS you'll have the opportunity to work on some of the most challenging and relevant issues in financial and technology. Our talented people empower us, and we believe in being...

  • Senior Sales Manager

    2 months ago


    Shanghai, Shanghai, China FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's DegreeAre you curious, motivated, and forward-thinking? At FIS you'll have the opportunity to work on some of the most challenging and relevant issues in financial and technology. Our talented people empower us, and we believe in being...

  • Engineering Manager

    2 weeks ago


    Shanghai, Shanghai, China Jensen Hughes Full time

    Company OverviewSince 1939, we have been leaders in safety, security, and risk-based engineering and consulting for global projects. We drive code and standard development worldwide and across industries. Our commitment is to earn trust and protect lives, property, and reputation. At present, our focus remains on safety, security, and risk-based science,...


  • Shanghai, Shanghai, China 489 FIL Fund Management (China) Company Limited Full time

    Description Title: Manager/Senior Manager - Risk Management Department: Risk / General Counsel Location: Shanghai - China Reports To: AD, Risk Management Level : 6 We're proud to have been helping our clients build better financial futures for over 50 years. How have we achieved this? By working together - and supporting each other - all...

  • Category Manager, EU

    2 weeks ago


    Shanghai, Shanghai, China AMEX Full time

    Who We Are:Wayfair is reinventing the way people shop for their homes and our team is tasked with building a best-in-class eCommerce business across our Asia market. Externally, we manage supplier relationships, partnering to build e-commerce strategies with industry leading manufacturers and supporting them in their execution. Internally, we work closely...


  • Shanghai, Shanghai, China Wayfair Full time

    At Wayfair Planning and Inventory Management, we thrive to partner with thousands of suppliers to maximize customers' experience. This means driving speed and availability through inventory and position strategies with suppliers leveraging Wayfair's fulfillment services (CastleGate) as well as suppliers' own supply chain capacities. Availability strategy is...