
赫力昂
Senior InfoSec Advisor, China
Senior InfoSec Advisor, China
发布于 大约 13 小时前中层管理(经理/总监)
上海市
专家级经验
全职员工
仅现场办公
学历未注明
信息安全
Cissp
Iso27001
Mlps
Pipl
云安全
数据隐私
网络安全
风险管理
AI 估算 · 50k–90k
资深安全负责人,跨国企业,上海,技能稀缺,薪资处于市场高水平。
职位详情
关于这个职位
该职位是赫力昂中国区的信息安全和网络安全负责人,负责制定和执行网络与数据安全战略,确保符合中国网络安全法、数据安全法和个人信息保护法等法规
领导安全治理、风险管理和合规项目,并作为监管检查的主要对接人
需要具备深厚的技术背景和团队管理经验,推动整体安全文化建设
最低要求
Basic Requirements:
Computer Science or Business Administration with additional IT education
Laws and regulations on data security and privacy (CSL, GDPR, etc.), COBIT, SOX
Leadership and stakeholder management, have had experience in delivering large scale security initiatives where various stakeholders (internal & external) are involved
Innovative thinking with an ability to lead and motivate cross-functional, interdisciplinary teams
Related Working Experience:
>10 years of demonstrated working experience in Information Security and/or related functions (e.g. Information Technology, Data Protection)
>5 years of leadership experience and good managerial skills in managing a diverse workforce. Strong Project Management skills.
Relevant experience in a multi-cultural work environment fostering a climate of team work and collaboration
Excellent in-depth knowledge in Network Security, Cloud Security, Endpoint Security, Identity and Access Management
Excellent in-depth knowledge of ISO27001/2, COBIT, ITIL , MLPS and NIST Cyber Security frameworks
Ability to develop cooperative and constructive working relationships, to handle complaints, settle disputes and resolve conflicts and negotiate with others
Collaborative team player orientation towards work relationships, strong culture awareness. Effectiveness in building trust, respect and cooperation among teams
工作职责
Serve as Haleon China's cybersecurity and information security accountable leader, responsible for cybersecurity governance, privacy protection, data security compliance, regulatory engagement, and cyber risk management across all China operations.
Main Task
Security Strategy:
Drive, implement and continuously monitor Cybersecurity and Data Privacy policies to be in line with group regulatory security framework and applicable law.
Manage and lead technology risk function to ensure business initiatives and operation changes are deployed in a secure manner.
Create security metrics to keep top management up with transparency over the state of Cybersecurity and Data Privacy.
Cybersecurity Compliance:
Act as the primary point of contact for cybersecurity, data protection and regulatory matters in China.
Ensure Haleon China's business operations, application development and network infrastructure comply with all applicable local laws and regulations.
System Security:
Manage system security throughout Digital China system development lifecycle, including define security requirement, perform threat modelling and conduct penetration testing.
Lead the cybersecurity assessment on local applications based on Cyber Security Law (CSL) and related requirements, including Multi-Level Protection Scheme (MLPS) requirements, digital license, etc. and be responsible for MLPS assessment and certification.
ISMS:
Provide Information Security and Data Protection trainings to ensure an adequate security awareness and maturity level in all business departments.
Establish the framework of document management in respect of the manner, location and time frame for retaining and destroying documents according to the regularity and cost-effectiveness.
Establish data and security incident management procedure. Investigate data breach incident and report to top management in a timely manner.
Vendor Security Management:
Safeguard company data in vendor in partnership with legal and procurement function by reviewing contract and performing vendor security audit.
优先资格
Professional certifications a plus (CISSP, CRISC, CISA, CISM or equivalent)
Data Protection and/or Privacy certification such as, CIPP, CIPT, ISEB, etc., is a plus.
AI 洞察
优缺点分析
优点
- 职位级别高,直接向集团汇报,拥有较大的决策权和影响力
- 在跨国消费品公司工作,平台大、资源丰富,能接触到前沿的安全技术和全球最佳实践
- 行业法规持续更新,专业价值空间大,职业稳定性高
- 工作内容综合性强,兼具技术与管理,利于个人综合能力提升
- 需要平衡业务需求与安全管控,协调多方利益,沟通成本高
- 网络安全领域技术迭代快,需要持续学习以保持专业竞争力
- 适合具备深厚信息安全背景、拥有领导经验、并希望在跨国企业中承担战略性安全职责的专业人士
缺点 / 挑战
- 岗位责任重大,需应对复杂的合规要求和监管检查,工作压力较高
角色解读
- 可以从中国区安全负责人向亚太区或全球安全领导岗位发展,承担更大范围的安全战略职责
- 也可以向CISO(首席信息安全官)或安全总监方向晋升,深入到企业高层决策层面
- 随着数据安全与隐私保护的重要性日益提升,该领域的专业价值将持续增长
- 全面负责赫力昂中国的网络安全和信息安全战略,包括治理、风险管理和合规项目
- 作为中国区网络安全官,代表公司与监管机构沟通,确保符合网络安全法、数据安全法和PIPL等法规
- 领导安全运营、事件响应和危机管理,并管理第三方安全风险
- 推进安全文化建设,提升全员安全意识,同时负责MLPS等安全认证和评估工作
- 年以上信息安全或相关经验,5年以上团队管理经验
- 熟练掌握网络安全、云安全、端点安全和身份管理等领域的技术知识
- 熟悉ISO27001、COBIT、ITIL、MLPS和NIST等安全框架及相关法律法规
- 具备优秀的沟通能力和跨部门协作能力,能有效管理利益相关方
申请策略
- 了解赫力昂的业务和品牌,在面试中展现对消费者健康行业安全挑战的思考
- 准备好表述自己如何将安全战略与业务目标结合,体现商业思维
- 突出10年以上信息安全经验,特别是大型跨国企业的安全治理和合规项目经历
- 强调领导和管理团队的经验,展示如何推动跨部门协作及影响高层决策
- 列出相关认证(如CISSP、CISM等)和对中国网络安全法规的深入理解
- 体现处理安全事故和监管审查的具体案例
- 可以补充或更新对最新法规(如PIPL、DSL)和MLPS 2.0的理解
- 学习和掌握云安全(如AWS/Azure)及零信任架构等新兴技术
面试指南
- 采用STAR法则(情景、任务、行动、结果)来回答行为问题,突出你的领导力和决策过程
- 对于合规问题,先表明对法规的理解,再结合实际操作经验,强调风险管理和业务影响的平衡
- 对于沟通协问题,强调你如何建立信任和利益相关者管理,举例说明成功案例
- 请介绍一下你在跨国企业中和中国网络安全法规合规方面的经验
- 在你的职业生涯中,遇到过最具挑战的安全事件是什么?你是如何应对的?
- 如何推动业务部门参与信息安全管理,而不仅仅是技术部门的事?
- 对MLPS 2.0和等级保护评估的流程有什么深入理解?
- 如果发现一项重大数据泄露,你会如何向管理层和监管机构沟通?
职位点评
61
综合评分
跨国企业中国区信息安全负责人岗位,薪资优厚但未披露,技术与管理并重,WLB未知。
从薪资福利、成长空间、工作节奏和岗位方向综合评估,方便横向比较。
更适合这类人
该职位最适合高度重视职业发展和技能提升、能够接受一定工作压力的资深信息安全专业人士。
表现最好
成长发展
相对薄弱
工作生活
薪资福利55
成长发展75
工作生活50
使命价值60
薪资福利
55较低
职位为跨国公司高管岗位,薪资水平预计较高,但JD未披露具体福利和薪资细节,稳定性良好。
薪资信号未披露(AI估算:50K-90K/月)
成长发展
75中等
岗位技术和管理要求高,能积累大型跨国企业安全战略经验,但JD未明确提及晋升和培训机制。
技术前沿主流现代技术
技术栈网络安全、云安全、端点安全、身份与访问管理、ISO27001、COBIT、ITIL、MLPS、NIST、CISSP
业务类型cost_center
工作生活
50较低
JD未说明远程或弹性工作安排,工作地点在上海,作为高级管理人员可能需要应对较高强度的工作。
工作模式仅现场办公
办公地点未明确
加班情况未提及(无法判断)
使命价值
60中等
赫力昂以改善日常健康为使命,岗位对保障数据安全有社会价值,但行业成熟稳定,创新性一般。
行业发展稳定成熟行业
社会影响中性/一般
使命信号deliver better everyday health with humanity、purpose-driven
创新程度稳健跟随主流
赫力昂 的其他在招职位
相似职位推荐
Watch Jobs