Cyber Security GRC Consultant
13 hours ago
RINA is currently recruiting for a
Cyber Security GRC Consultant
to join its office in Shanghai, China within the
Digital Technology and Cybersecurity
Division.
Mission
The Cyber Security GRC Consultant focuses on contributing to the development, implementation, and maintenance of governance, risk, and compliance programs, ensuring that our organization and clients maintain robust information security and regulatory compliance.
Key Accountabilities
Consultancy and Advisory:
- Provide consultancy in governance, risk, compliance, and privacy to internal teams and clients.
- Contribute in developing and implementing GRC policies, procedures, and frameworks tailored to organizational needs.
Risk Analysis and Assessment:
- Conduct risk analyses and vulnerability assessments to identify potential threats and compliance gaps.
- Contribute to developing mitigation strategies and recommend solutions to address identified risks and vulnerabilities.
Compliance Implementation and Maintenance:
- Support the implementation and ongoing maintenance of compliance frameworks such as ISO 27001, GDPR, NIST Cybersecurity Framework, and CMMC requirements.
- Monitor regulatory changes and contribute to updating internal processes to ensure continuous compliance.
Collaboration and Training:
- Collaborate with cross-functional teams to ensure compliance with all relevant regulatory requirements.
- Provide advice, guidance, and training to employees on compliance best practices and the importance of adhering to security protocols.
Internal Audits and Corrective Actions:
- Conduct internal audits to evaluate the organization's level of compliance with established policies and frameworks.
- Recommend and contribute in the implementation of corrective actions to address any identified compliance issues.
Certification Support:
- Assist the organization in achieving and maintaining industry certifications by providing necessary support and documentation.
- Ensure ongoing adherence to certification requirements.
Pre-Sales and Project Scaling:
- Support pre-sales activities by providing technical expertise and developing proposals that meet client requirements.
- Assist in scaling projects, ensuring that compliance and security requirements are met throughout the project lifecycle.
Education
Bachelor's Degree in Information Systems or Cyber Security
Qualifications
- Professional certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer, or equivalent are highly desirable.
- 3 to 5 years of experience in governance, risk management, and compliance within the cybersecurity domain.
- Knowledge of relevant regulatory frameworks and standards (ISO 27001, GDPR, NIST Cybersecurity Framework, CMMC).
- Strong analytical skills and the ability to conduct thorough risk assessments and audits.
- Excellent communication and interpersonal skills, with the ability to provide clear guidance and training.
- Proven experience in collaborating with cross-functional teams and managing compliance projects.
- Ability to stay updated on the latest regulatory changes and industry trends.
Competencies
- ADDRESS THE WAY - Have a big picture of different situations and reinterpret it in a perspective way
- BUILD NETWORK - Forge trust relationships, across departments, and outside the organization
- CLIENT INTIMACY - Embrace internal and external client needs, expectations, and requirements to ensure maximum satisfaction
- EARN TRUST - Take everyone's opinion into account and remain open to diversity
- MAKE EFFECTIVE DECISIONS - Structure activities according to priorities, actions, resources and constraint
- PIONEER CHANGE - Actively embrace change and benefit from the new circumstances
- MANAGE EMOTIONS - Recognise one's and other's emotions and express and regulate one's reactions
- PROMOTE SUSTAINABLE DEVELOPMENT - Promote commitment by keeping promises as a Role Model
- THINK FORWARD - Capitalise on experiences and translate them into action plans for the future
RINA is a multinational company providing a wide range of services in the energy, marine, certification, infrastructure & mobility, industry, research & development sectors. Our business model covers the full process of project development, from concept to completion.
At RINA, we endeavor to create a work environment where every single person is valued and encouraged to develop new ideas. We provide equal employment opportunities and are committed to creating a workplace where everyone feels respected and safe from discrimination or harassment of any kind. We are also compliant to the Italian Law n. 68/99.
-
Cyber Security Analyst
6 days ago
Shanghai, Shanghai, China Atmus Full time CN¥120,000 - CN¥240,000 per yearDescriptionSkills and Knowledge Communication verbal and non-verbal, English speaking, deductive reasoning, be able to translate business requirements into technical conceptsUnderstand China legal RegulationsHave Knowledge of ISO 27001Documentation and policy development Process Enhancement Organized Nice to have: CISSP Certification ISACA...
-
Cyber Security manager
7 days ago
Shanghai, Shanghai, China Michael Page Full time CN¥120,000 - CN¥200,000 per year* Participate in several projects of reputable FMCG enterprises* Corperate with BU in different regions to obtain rapid growth opportunitiesAbout Our ClientThis is a well-established organisation within the Media & Agency industry. With a significant presence in the market, it offers opportunities to work on impactful projects in the technology sector.Job...
-
Cyber Security Project Manager
7 days ago
Shanghai, Shanghai, China JonDavidson Full time CN¥120,000 - CN¥240,000 per yearCompany Description Our client is one of the world's leading professional services companies, listed on NASDAQ. Headquartered in the U.S., is consistently listed among the most admired companies in the world. Job Description The Cyber Security Project Manager will coordinate penetration testing, advise on cyber security engineering, and serve as the...
-
SAP Security
7 days ago
Shanghai, Shanghai, China Solventum Full time CN¥80,000 - CN¥200,000 per yearThank you for your interest in joining Solventum. Solventum is a new healthcare company with a long legacy of solving big challenges that improve lives and help healthcare professionals perform at their best. At Solventum, people are at the heart of every innovation we pursue. Guided by empathy, insight, and clinical intelligence, we collaborate with the...
-
VP, Information Security
7 days ago
Shanghai, Shanghai, China BlackRock Full time CN¥900,000 - CN¥1,200,000 per yearAbout This RoleAbout BlackRock:BlackRock's purpose is to help more and more people experience financial well-being and the firm has a long history of investing in and serving investors in China. BlackRock aspires to become the leading global asset management firm operating in China and is committed to contributing to the long-term development of the local...
-
Shanghai, Shanghai, China SPOTLIGHT AUTOMOTIVE LTD. Full time该职位来源于猎聘 职责描述:Coordinate the implementation of vehicle related data and cyber security requirements within the organization such as ICV (Intelligent Connected Vehicle) data and cyber security management requirements, data classification and grading, cross-border transfer, customer complaints handling, security incidents...
-
Crisis and Security Consulting
6 days ago
Shanghai, Shanghai, China 化险咨询(上海)有限公司 Full time CN¥200,000 - CN¥400,000 per year该职位来源于猎聘 Role purpose Under the direction of their manager, the intern will assist the Crisis and Security Consulting team in carrying out targeted public domain research on a range of topics and developing materials related to: 1. supply chain risk management 2. crisis management and business continuity 3. labour unrest 4. anti-bribery and...
-
Security Analyst
5 days ago
Shanghai, Shanghai, China 北京伯凯科技有限公司 Full time该职位来源于猎聘 ResponsibilitiesLead the development of threat modeling methodologies and frameworks.Regularly conduct threat hunting activities in customer environments, identifying potential threats and producing detailed reports.Stay current with the latest cyber threats, attack vectors, and security trends.Develop and fine-tune use cases for...
-
Senior Cyber Defense Analyst, Insider Threat, GC
13 hours ago
Shanghai, Shanghai, China Nike Full timeWho You'll Work WithThis role is part of the Insider Threat Operations (ITO) team within Corporate Information Security, and reports to the Director of Greater China Corporate Information Security (CIS) based out of GC HQ (Shanghai, China), providing subject matter expertise to support ITO Analysts, working across peer groups and engagement with other...
-
Manager, CyberSecurity
3 days ago
Shanghai, Shanghai, China GE HealthCare Full time CN¥80,000 - CN¥120,000 per yearJob Description SummaryThe Manager –Cyber Securityis accountable for coordinating and leading cyber security teams during a time of crisis or incident support. This leader will also be responsible for establishing, testing and continuously improving cyber crisis and incident playbooks, standards and processes.Job DescriptionRoles and ResponsibilitiesIn...