Job Description
Responsible to support Regional Information Security Risk Governance fthe Asia zone to ensure the Security posture of business units are properly measured, monitored managed Assist in the development promotion of of Information Security policies, standards, procedures according to the industry best practices standards (e.g. NIST800-53, , NIST Cyber Security Framework, ISO27000, CIS, ISA/IEC62443, etc.), technologies, relevant regulatory group requirements Evaluate manage capabilities that enable theganization to reliably achieve objectives, address uncertainty act with integrity, as a whole more responsive efficient in a consistent manner Act as the main responsible party to drive align the policy compliance across Group, business units business lines toward the same direction. Perform manage regular Information Security Control assessment to ensure that business units are compliant with the Group Information Security Policies Standards Manage remediation activities from Security assessments audit findings to mitigate the risks Identify address cyber risks requirements inder to protect theganization from adversity, surprise weakness MonitInformation Security Risk control, test to determine the control performance effectiveness with continuous improvement of KPIs. Support the Cyber Security project implementation daily activities with respect to Information Security best practices risk assessments Qualification (Public fHiring) At least 5 years hands-on experience in IT Security, Governance Risk Management, with 2 years in managerial team position Extensive knowledge understanding of Information Security framework, such as ISF, ISO27001, NIST Cyber Security Framework. Sound knowledge of Information System, IT Operation IT Audit Knowledge on OT Security. Good stakeholder engagement management skills Great sense of ownership servicing mindset Strong liaison skill, teamwork, passion commitment mentality Strong self-motivation, with good leadership, interpersonal analytical skills, lead through influence, communicate effectively to stakeholders on risk management cyber security governance Strong problem solving project execution skills; able to handle changing priorities drive difficult decisions; highly dependable team player with ongoing commitment to excellence Relevant professional certification, such as CISSP, CISA, CISM, CRISC CGEIT is desired Good communication in English Mandarin,