Global Information Security Senior Manager – Incident Response

3 weeks ago


Xuhui Qu, China Boston Consulting Group Full time
WHAT YOU'LL DO
Under the general direction of the Information Security Director – Incident Response or delegate and working with other Risk, IT, BST, etc. colleagues across the firm, the roles will perform the following functions:

Participate as an integral part of the Security Team and IT in general
  • Work closely with CSIRT team people & technology to detect, assess, and communicate cyber threats
  • Update the Security Team and other groups on industry trends and recommend initiatives to help lower risk
  • Define SIEM use cases to collect, monitor and analyze data to discover and discern trends, threats, and security risks associated with BCG assets and information.
  • Recommend and create SIEM rules to protect BCG and BCG client confidential information
  • Proactively monitoring and analyze logs via the SIEM for indicators of attack
  • Mentoring more junior team members
  • With the Information management team, follow-up on incidents, issues, and concerns related to data loss
  • Manage incidents related to data loss, producing alerts and escalating issues to appropriate management
  • Provide SIEM solutions and support for specific case team and/or project needs and requirements
  • Develop and produce operational metrics that demonstrate the effectiveness of controls, quantifies security risks and issues, confirms service levels, tracks incident type and volume
  • Apply industry and BCG security knowledge, policy, standards, practices to incident response
  • Respond to inquiries related to data loss and inappropriate sharing
  • Develop standard materials in support of BCG Information Security
  • Respond to, and to the extent possible, accommodate special requests and requirements
  • Track and report on security issues
  • All other tasks and responsibilities as requested by manager
Maintain up-to-date knowledge of the cyber security industry as it relates to BCG including:
  • Attacker methods and TTPs
  • Standards, regulations and legislation.
  • Threats and vulnerabilities
  • Technologies and solutions
  • Industry best practices
  • Client requirements and concerns
Provide input and represent BCG and client interests in the areas of:
  • Incident response and investigation
  • Incident response management for client security incidents
  • Work with IT Directors, Managers, Architects and staff to implement, monitor and maintain Confidentiality, Availability and Integrity of BCG information assets.
  • Track and manage materials provided to external providers and clients.
  • Maintain information security credentials and certifications as required to present a credible presence to internal and external audiences.

YOU'RE GOOD AT
  • Technical and functional expertise
    • Requires an advanced level of professional knowledge in information technology and security developed through a combination of advanced degrees in information technology and hands on experience.
    • Must have previous career development experience which has provided management skills, motivational skills, interpersonal skills, and outstanding organizational effectiveness.
    • Knowledge of the legal and regulatory landscape related to security and privacy in an international environment.
    • Very strong business sense with ability to relate technology issues to business.
  • Problem solving, analytical skills and decision making
    • Requires strong analytical skills and abilities including an extensive knowledge of software, database, operating systems, client server architecture and voice and data communication services and facilities, security and privacy, in an international setting.
    • Collect, review, and analyze various metrics, which help to measure and monitor systems, departmental performance, and quality. Discern and analyze trends.
    • Review and prepare monthly status reports and statistics.
    • Manage group and project budgets.
  • Communication, interpersonal and teaming skills
    • Outstanding verbal and written communications skills are a must because of the requirement to represent BCG in communications with clients.
    • Calm demeanor, grace under fire, outstanding listening skills.
  • Leadership, impact and change
    • High level of initiative and self-motivation, resourceful, and patient with an iterative process.
    • Ability to gain trust and commitment of others at different levels of the organization.
    • Proven ability to challenge traditional way of operating and moving beyond the obvious.
    • Translates BCG’s broader strategic objectives and cascades these into own work plans, metrics and team work plans.
    • Works effectively with significant ambiguity and fluctuating priorities and constrains.
  • Work management, organization and planning
    • Ability to evaluate and prepare detailed project plans for technology projects that will be implemented across the business. Manage local and global technology problems and direct staff in resolution of such problems. Evaluate and advise on the technology and systems components associated with projects adopted by BCG corporate and offices.
    • Ability to monitor projects and direct staffs to ensure projects are aligned with the strategic objectives of the business.
  • Customer and business focus
    • Focuses on the most critical issues that have the highest impact on the organization and business needs.
    • Working mode: “enabling”, “value adding” and “expanding”.
    • Treats all others with respect; generate trust.
  • People management
    • This position requires interaction with BCG Partners, BCG Case Team staff, client legal and security staff, Administrative Management, vendors, IT Management and Staff, Legal Department, Finance, Vendors, etc. Very strong relationship skills are essential. Excellent Leadership and teaming skills are required.
  • Values and ethics
    • Strong sense of confidentiality and integrity.
    • Treats others with respect and generates trust.
    • Establish relationships based on respect, trust and integrity.

YOU BRING (EXPERIENCE & QUALIFICATIONS)
  • Bachelor’s degree (or equivalent);
  • Minimum 9 years of information security experience, with a very strong technical background
  • Significant information security and risk management experience in a multinational enterprise
  • Demonstrated Threat Hunting and Incident Response experience (from a Consultancy or SOC environment)
  • Experience with Security Information and Event Management (SIEM) monitoring tools and their use (Splunk, Arcsight, QRadar or similar)
  • Security certification like GIAC Cyber Threat Intelligence (GCTI), GIAC Certified Intrusion Analyst (GCIA) or GIAC Certified Incident Handler (GCIH) or equivalent a plus.
  • Fluent in both oral and written English.

YOU'LL WORK WITH
BCG’s information technology group collaboratively delivers the latest digital technologies that enable our consultants to lead and our business to grow. For our IT jobs, we seek individuals with expertise in the areas of IT infrastructure, application development, business systems, collaborative and social technologies, information security, and project leadership.


  • Xuhui Qu, China Boston Consulting Group Full time

    WHAT YOU'LL DOParticipate as an integral part of the Cyber Security Incident Response Team Support cyber incident response actions to ensure proper assessment, containment, mitigation and documentation Support cyber investigations and contribution to large and small scale computer security incidents Review and analyze cyber threats and provide support,...


  • Xuhui Qu, China Boston Consulting Group Full time

    WHAT YOU'LL DOUnder the general direction of GC BISO or delegate and working with other IT, BST, etc. throughout the firm, the roles will perform the following functions: Participate as an integral part of the Security Team in general: Responsible for conducting internal IT, Cybersecurity, and third-party information security risk management activities for...


  • Xuhui Qu, China Boston Consulting Group Full time

    WHAT YOU'LL DOAs a Senior Knowledge Analyst (SKA) In a Client Focused role within BCG's Healthcare Practice Area, you will work in a growing global team, delivering value to clients via individual expertise and/or institutionalized knowledge assets (products, tools, data, workshops, frameworks, surveys, domain-specific data and related expertise, etc.). You...

  • Saas Architect

    3 weeks ago


    Chaoyang Qu, China Nityo Infotech Full time

    What you will do Thorough understanding of the SaaS framework (architecture and technical configuration of the SaaS Platform and software program) your main missions will be to •Study and apply the market’s SaaS and security best practices on the platform•Communicate with the Hosting Providers and with internal teams to ensure proper service...

  • Senior Manager ASID

    3 weeks ago


    Pu Dong Xin Qu, China Air Products Full time

    Senior Manager ASID AS-CN-Shanghai Zhangjiang Job Description and Qualifications Job Description TBD Req No. 49841BR Employment Status Full Time Organization Global Industrial Gases Business Sector / Division Industrial Gases Asia Region Asia Country China Senior Manager ASID | Air Products


  • Xuhui, China Terex Full time

    Description The Sales Manager will drive equipment/parts sales in Terex Fuchs China market. Key responsibilities will include the development of a sales plan, analysis of selling, expansion of sales channels, mining of potential customers, feedback on aftersales support requirements, and input on specific product requirements for the region. The...

  • Senior OOH Manager

    3 weeks ago


    Xu Hui Qu, China dentsu Full time

    The purpose of this role is to support the Trading Directors within the business, tasked with assisting Directors in managing day to day relationships with media partners and to work with account teams to support the delivery of best-in-class campaigns. Job Title: Senior OOH Manager Job Description: Key responsibilities: Builds strong relationships with...


  • Xu Hui Qu, China dentsu Full time

    The purpose of this role is to work with strategy lead to craft strategic outputs including creative briefs, research reports and analyses, selling narratives, strategic POVS and go-to market plans Job Title: Senior Strategy Manager Job Description: Key responsibilities:Has the overall responsibility for writing briefs and conducting briefings on several...


  • Haidian Qu, China Marsh McLennan Companies Full time

    Description: Responsibili ty: The position will be leading the Global Mobility Business in China Career team. He or she needs to Develop and lead global mobility related business. Responsible for the delivery of high quality products on schedule with necessary direction. Design and enhance products and deliverables for China market by...


  • Huang Pu Qu, China 1215 GlaxoSmithKline (China) Investment Co Ltd Full time

    Role Purpose: The Ethics and Compliance Governance Manager will provide governance on corporate risk management over ABAC risk including 3rd party due diligence, ensuring controls and processes are well designed to mitigate ABAC risk and are effectively embedded into business operation, and producing key metrics including monitoring results,...

  • Product Specialist

    3 weeks ago


    Xuhui, China Allnex Full time

    Position overview Are you interested in managing products with market trend, company strategies and business optimization, offer innovative products that meet the needs and wants of customers? allnex invites you to join us as a Product Specialist , and we are happy to share this position is open either in China, Thailand or Malaysia . With this great...


  • Xuhui Qu, China Boston Consulting Group Full time

    Who We AreBoston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we work closely with clients to embrace a transformational approach aimed at benefiting all stakeholders—empowering...


  • Xu Hui Qu, China dentsu Full time

    The purpose of this role is to provide support and assistance in managing the client’s business and to keep day to day activities running smoothly. May supervise a graduate Job Title: Senior Account Executive Job Description: Senior Account Executive


  • Haidian Qu, China airbus Full time

    Job Description: A. AccountabilitiesThe job holder is accountable for leading, within and in collaboration with suppliers, complex projects/missions aiming in sustainably improving the industrial performance of a supplier or a supplier’s site and/or restoring and securing supplier performancesIn his role the Supplier Development manager is accountable...

  • Planning Manager

    2 weeks ago


    Xu Hui Qu, China dentsu Full time

    The purpose of this role is to provide support to the senior team, taking responsibility for all administrative tasks within the team to ensure campaigns run smoothly and to plan. Job Title: Planning Manager Job Description: Key responsibilities:Effectively runs the day to day planning on key accountsBuilds and develops media owner relationships in order...


  • Pu Dong Xin Qu, China Marsh McLennan Companies Full time

    Description: Marsh is seeking a (Senior) Account Manager located in Marsh Shanghai Lin-Gang (临港) Reinsurance Branch Office. We will count on you to: Be familiar with property insurance/reinsurance placement process Handles various internal Marsh systems which related to recording, billing, account handling and claims administration etc. ...

  • Blow Molding Engineer

    3 weeks ago


    Feng Xian Qu, China Greif Full time

    Greif offers a great working environment and the opportunity to make an immediate impact at a company where your ideas are always welcome.Job Requisition #:027110 Blow Molding Engineer (Open)Job Description:Key Responsibilities Evaluates facility technical quality requirements and recommends solutions, changes, and modifications as required to ensure...


  • Bin Hai Xin Qu, China 1844 GlaxoSmithKline (Tianjin) Co. Ltd Full time

    Job Purpose 岗位目的: To effectively manage all the materials and goods in company. To support product manufacturing and supply to market on time. Employee behaviors comply with GMP, EHS and SOP...


  • Haidian Qu, China airbus Full time

    Job Description: The Satair Quality team is looking for a new Quality Operational Manager for the Satair Beijing warehouse. You will be a key actor driving the success of the local quality operations: on-time and on-quality closure of related customer and supplier claims, on-time and on-quality certification of parts (via Hua-Ou interface), audit planning...


  • Huang Pu Qu, China 1215 GlaxoSmithKline (China) Investment Co Ltd Full time

    Role Purpose 职位目标: Engage internal and external customers to ensure Nucala brand strategy cascade effectively and to achieve targeted sales growth and market share growth. Key Accountabilities/Responsibilities 主要工作职责: 1.To achieve targets within the allocated budget by region Achievement of sales target Achievement of market...