職位描述
WEB安全網(wǎng)站安全云安全JavaPythonCISPCISSPCISA網(wǎng)絡(luò)/信息安全
Purpose of the Role:
The planning, execution and governance of the Company’s cyber security and compliance initiatives and readiness. Achieved through managing the various aspects of IT Security, Cyber security, IT General Controls and coordination of local, regulatory compliance across business units. Develop an internal team and skillsets combined with third-party cybersecurity technology partners and operational services.
Leads the team in the operations, management and planning of the Company’s network infrastructure and operations. Enterprise and market components including hardware, software, hosting services, network architecture and related standards. Accountable for operational excellence and delivery of operational service levels.
Performance management and talent planning for team members.
Key Job Responsibilities
Specific duties include, but are not limited to:
1. Security & Compliance
?Develop and maintain the Company’s Information Security Program including policies, standards and procedures to ensure information assets, applications, network systems and infrastructure are protected and compliant.
?Annual review and updates of the Company policies and procedures according to industry best practices and standards, supporting technologies and addressing regulatory requirements.
?Act as the responsible party to drive and align policy compliance across Toys R Us Asia and local markets.
?Identification of information technology risks. Propose and implement technology solutions and mitigating process & controls. Partner with Internal Audit in Company risk management processes from IT perspective. Business Continuity and Disaster Recovery programs.
?Develop and maintain Company IT security awareness program in partnership with HR team to raise awareness of security risks. Monitor, assess and audit behavior practice and compliance across the Company.
?Ensure all IT assets and applications are configured, security patched, scanned for vulnerabilities and operating per Company standards. Includes mobile devices, desktops, servers and networks.
?Manage external security operation center (SOC) service providers and deliverables. Coordinate with Regional IT Director as internal escalation point for incidents and response coordination.
?Develop annual cyber-hardening improvement and compliance plans to improve Company cyber-maturity position. Prepare recommendations and budgeting guidance to management.
?Support recurring internal and external audit of IT General Controls (ITGC).
?Supports IT leadership with security standards and compliance review tollgate for proposed projects prior to approval.
2. Network Operations
?Provides technical oversight and guidance to team in maintenance and day to day operations of the Company’s network and infrastructure services.
?DNS administration and managed service.
?Regional HQ office network services, desktop support and service requests.
?Governance and implementation of network and infrastructure policies and change management standards. Network and application backup processes, configurations, third party monitoring and related managed services.
?Works with Regional IT Director on HQ budgeting guidance and enterprise contract management and administrative services to Asia markets (software licensing, maintenance renewals, etc.).
?Lead the Network team to manage and support infrastructure requirements for projects.
?Review of core network architecture, service level/cost optimization and capacity planning.
*The above tasks and responsibilities are a summary of the typical functions of the job and may not be exhaustive of all possible responsibilities, tasks and duties of the role.
Requirements:
?Bachelor’s or master’s degree in Computer Science, Information.
?A minimum of 8 years of combined experience with in-depth technical knowledge and experience in information security, security operations, security program and project management Security or a related field or discipline.
?Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate information security and risk-related concepts to technical and business audiences.
?Certified CISSP, CISM, CISA, CRISC or other similar credentials – favorable.
?In-depth knowledge of information security risk management, cybersecurity technologies and managed SOC services.
?Proficiencies in both English and Chinese