Cyber Security Analyst
7 days ago
Skills and Knowledge
- Communication verbal and non-verbal, English speaking, deductive reasoning, be able to translate business requirements into technical concepts
- Understand China legal Regulations
- Have Knowledge of ISO 27001
- Documentation and policy development
- Process Enhancement
- Organized
- Nice to have: CISSP Certification
- ISACA Certifications such as CISM, CISA, CRISK etc
- 1 to 3 years of experience in the cyber security area.
- Experience with manufacturing and global organizations
- Ability to work in global environment, flexibility in reaching out to global teams to get things done
Security Risk Management Support
- Maintain timely communication with the global ServiceNow team and Cyber Team regarding unexpected security risks or demands, providing necessary local support as required.
- Participate in incident response and risk management activities, effectively addressing emerging security needs.
- Security alerts monitoring and events, and proactively help react to incidents related to China and APAC as needed
- Collaborate with multiple business departments and assist them in conducting VSA audits for suppliers when introducing their IT systems. The main responsibilities include coordinating with suppliers to complete the VSA questionnaire, submitting IT system qualification documents, and working with the global cyberteam to prepare the review report based on the preliminary findings. Ensure that security assessments are completed within the specified time frame.
- Work with project teams and cyber stakeholders to review and reduce vulnerabilities identified in Gitlab / ServiceNow for the projects
- Identify and address security risks, ensuring all assigned tasks are completed within agreed timelines and aligned with established security policies and procedures.
Cybersecurity Training
- Support APAC training for security awareness training, shop floor, and role-based training
- Track training completion and help stakeholders if needed
Ensure Local Business Security Compliance
- Ensure that local business requirements comply with corporate security standards by supporting the implementation of security regulations, device usage guidelines internal
- Document-sharing policies and security policy baselines. Such as assisting in updating the IT policies in the employee handbook to align with global and local policies and regulations.
- Assist in any audit involving Chinese law and regulations
Business-Cybersecurity Coordination Support
- Ensure all special security requests are accurately documented and submitted to the global cybersecurity team.
- Provide timely follow-up to ensure requests are processed efficiently.
- Effectively communicate cybersecurity team decisions and guidance to the business to ensure alignment with security policies.
Cybersecurity Process Communication and Approval Support
- Ensure cybersecurity processes are effectively communicated to local teams, providing support to help them complete security approvals accurately and on time.
Responsibilities
In this role, you will make an impact in the following ways:
- Responds to moderately complex computer security incidents according to the Information Security Policies and Industry Best Practices.
- Coordinate efforts to provide timely updates and recommendations to multiple business units during incident response.
- Contributes to a team of cybersecurity professionals working with threat data, writing reports, briefing event details to leadership, and coordinating remediation with personnel.
- Analyzes / participate in potential impact of new threats and exploits and communicates risks to Cyber Security Engineering.
- Monitors information security-related websites (e.g., SANS Internet Storm Center) and mailing lists (e.g., BugTraq) to stay up to date on current attacks and trends.
- Ensures technology employed by the Intrusion Analyst team complements operational processes.
- Performs in-depth analysis in support of moderately complex intrusion detection operations.
- Finds anomalous or malicious activity on Cummins networks using analytical methods and tools in an operational environment.
- Takes the initiative to understand and master new operating systems, security applications, and open-source tools.
- Performs root cause analysis and makes recommendations on changes for review by others.
- Collects intrusion artifacts (e.g., source code, malware, trojans) and uses discovered data to enable mitigation of potential incidents within the enterprise.
- Troubleshoots complex, cross-business issues within existing security and privacy protections.
- Performs root cause analysis and makes recommendations on changes.
- Analyzes identified malicious activity and determines appropriate course of action in response to identified and analyzed anomalous network activity.
- Performs event correlation using information gathered from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
To be successful in the role you will need the following
College, University or equivalent degree in Cyber Security, Computer Science or Information Technolgy, or related subject, or relevant equivalent experience required, this position may require licensing for compliance with export controls or sanctions regulations.
Nice to have: CISSP Certification
ISACA Certifications such as CISM, CISA, CRISK etc
1 to 3 years of experience in the cyber security area.
-
Cyber Security manager
7 days ago
Shanghai, Shanghai, China Michael Page Full time CN¥120,000 - CN¥200,000 per year* Participate in several projects of reputable FMCG enterprises* Corperate with BU in different regions to obtain rapid growth opportunitiesAbout Our ClientThis is a well-established organisation within the Media & Agency industry. With a significant presence in the market, it offers opportunities to work on impactful projects in the technology sector.Job...
-
Cyber Security Project Manager
7 days ago
Shanghai, Shanghai, China JonDavidson Full time CN¥120,000 - CN¥240,000 per yearCompany Description Our client is one of the world's leading professional services companies, listed on NASDAQ. Headquartered in the U.S., is consistently listed among the most admired companies in the world. Job Description The Cyber Security Project Manager will coordinate penetration testing, advise on cyber security engineering, and serve as the...
-
Senior Cyber Defense Analyst, Insider Threat, GC
24 hours ago
Shanghai, Shanghai, China Nike Full timeWho You'll Work WithThis role is part of the Insider Threat Operations (ITO) team within Corporate Information Security, and reports to the Director of Greater China Corporate Information Security (CIS) based out of GC HQ (Shanghai, China), providing subject matter expertise to support ITO Analysts, working across peer groups and engagement with other...
-
Cyber Security GRC Consultant
24 hours ago
Shanghai, Shanghai, China RINA Full timeRINA is currently recruiting for aCyber Security GRC Consultantto join its office in Shanghai, China within theDigital Technology and CybersecurityDivision.MissionThe Cyber Security GRC Consultant focuses on contributing to the development, implementation, and maintenance of governance, risk, and compliance programs, ensuring that our organization and...
-
Security Analyst
5 days ago
Shanghai, Shanghai, China 北京伯凯科技有限公司 Full time该职位来源于猎聘 ResponsibilitiesLead the development of threat modeling methodologies and frameworks.Regularly conduct threat hunting activities in customer environments, identifying potential threats and producing detailed reports.Stay current with the latest cyber threats, attack vectors, and security trends.Develop and fine-tune use cases for...
-
VP, Information Security
7 days ago
Shanghai, Shanghai, China BlackRock Full time CN¥900,000 - CN¥1,200,000 per yearAbout This RoleAbout BlackRock:BlackRock's purpose is to help more and more people experience financial well-being and the firm has a long history of investing in and serving investors in China. BlackRock aspires to become the leading global asset management firm operating in China and is committed to contributing to the long-term development of the local...
-
Shanghai, Shanghai, China SPOTLIGHT AUTOMOTIVE LTD. Full time该职位来源于猎聘 职责描述:Coordinate the implementation of vehicle related data and cyber security requirements within the organization such as ICV (Intelligent Connected Vehicle) data and cyber security management requirements, data classification and grading, cross-border transfer, customer complaints handling, security incidents...
-
Global Security China Analyst
5 days ago
Shanghai, Shanghai, China Johnson & Johnson Innovative Medicine Full timeAt Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to...
-
Security Engineer
7 days ago
Shanghai, Shanghai, China LifeByte Systems Full time CN¥900,000 - CN¥1,200,000 per yearWe are seeking a highly skilledSecurity Engineerto build andoptimise the company's security infrastructure. You will partner with security analysts, incident responders, and IT/DevOps to enhancethreat detection, prevention and response, enabling faster, risk‑informed decision making. The role focuses onscalable security telemetry pipelines,SIEM/EDR...
-
Technical Delivery Manager
7 days ago
Shanghai, Shanghai, China 北京伯凯科技有限公司 Full time CN¥120,000 - CN¥240,000 per year该职位来源于猎聘 Technical Delivery Manager As a Managed Security Service Provider (MSSP), we are seeking an experienced and dynamic Technical Delivery Manager in our Cyber Security Operations Center (CyberSOC) team. The ideal candidate will possess a deep understanding of cybersecurity, incident response, and threat detection methodologies. The...