Duties include:
1. Establish and continuously improve the company's risk management system, including information security and IT risk management system, implement risk management policies, procedures, processes and standards.
2. Identify, analyze and evaluate the security risks of key systems, business processes, and data assets, and regularly conduct IT security risk assessments and reevaluations.
4. Establish and implement an operation risk event follow-up and network and information security event management process, organize event analysis, emergency response and root cause analysis.
5. Responsible for third-party/supplier safety risk management, including safety clause review, safety assessment, continuous monitoring and regular re-evaluation.
6. Monthly follow-up on the company's key risk indicators
7. Participate or lead IT and information security-related internal control checks, compliance assessments, and external audit support work, and follow up on the improvement of audit issues.
8. Organize and conduct company-level safety awareness training and propaganda, enhance employees’ safety risk awareness and compliance awareness.
9. Organize and coordinate the holding of the company's risk management committee
Job Requirements
1. Bachelor's degree or above, majoring in Computer Science, Information Security, Information Systems, Network Engineering or related fields.
2.3 years of experience in information security, technical risk management, IT audit or related fields, with preference for those with experience in large or medium-sized enterprises or financial institutions.
3. Familiar with risk management theory, understand IT risk management methodology and process, understand common information security and risk management frameworks such as ISO 27001/27005, NIST, CIS, COSO ERM, etc.
4. Familiar with the basic principles, common threats and defense technologies in the fields of network security, host security, application security and data security, and have actual risk assessment or security testing experience.
5. Candidates with experience in third-party/supplier risk management are preferred, familiar with software supply chain security and outsourcing service security control requirements.
6. Have good cross-departmental communication and coordination skills, be able to convert technical risks into business language and clearly express them to management and non-technical teams.
7. Have good Chinese written expression and English reading and writing abilities, be able to read and understand relevant technical documents and regulatory requirements.
Have experience in security risk management in rapidly developing or highly regulated industries (finance, Internet, payment, virtual assets, etc.).