信息安全专员(J10903)
上海药明康德新药开发有限公司
- 公司规模:10000人以上
- 公司性质:外资(欧美)
- 公司行业:制药/生物工程
职位信息
- 发布日期:2019-11-16
- 工作地点:上海-浦东新区
- 招聘人数:1人
- 工作经验:无工作经验
- 学历要求:招1人
- 语言要求:不限
- 职位类别:信息技术专员 其他
职位描述
工作职责:
1. 负责根据集团总部信息安全与合规政策,结合各个业务实际情况,起草和落实部门级别政策与执行标准;
Responsible for drafting and implementing departmental policies and operation standards on the basis of integrating the corporate information security and compliance policies and the actual conditions of each business unit;
2. 负责根据部门级别的信息安全政策,规划和落实部门内部的信息安全评审。
Responsible for planning and implementing the information security reviews according to the information security policies at the division level.
3. 负责根据各项评审偏差,推进规划和落地部门内部各项整改措施;
Responsible for promoting the schedules and implementation of internal correction measures according to the review deviations;
4. 负责参与部门内部各项信息系统建设项目的各个阶段,确保项目从需求到运营的各项流程符合信息安全政策要求;
Responsible for participating in all phases of the construction projects in respect of information systems at the division level, ensuring that the processes from requirements to operation of the projects conform to the requirements of information security policies;
5. 负责支持和协调部门内部的外部客户审计;
Responsible for supporting and coordinating external customer audits within the division;
6. 负责部门管理人员安全合规意识培训和宣传,推动部门数据安全、信息系统运行规范、人员入离职流程等安全管理体系建设;
Responsible for the training and publicity on the safety and compliance awareness of the managers within the division, and promote the constructions of the safety management systems with regard to the data security, the operation standards of the information systems, and the processes of personnel’s on-boarding and departure;
7. 负责部门基层员工安全合规意识培训,确保员工对公司集团计算机设备、账号、网络和信息系统的使用合规,支持集团或者在业务部门内部自主开展的员工信息安全意识培训和考试;
Responsible for the training on the security and compliance awareness of the grassroots employees, ensure the compliance on the use of the computer equipment, account numbers, networks and information systems, and support the training and examinations on the employee information security awareness conducted by the corporate or within the division;
8. 配合集团总部的信息安全审计与评审,收集和准备相关内部审计材料,落实集团各项审计发现;
Cooperate with the audits and reviews on the corporate information security, collect and prepare relevant internal audit materials, and follow the audit findings;
9. 协助参与部门IT、集团IT的边界定义,确保各项信息安全要求包含在对应服务标准中;
Assist in defining the boundaries of division IT and Corp IT to ensure that all requirements on information security are included in the corresponding service level agreement;
10. 参与集团总部的信息安全合规定期会议;
Participate in regular meetings on the information security and compliance with Corp IT;
11. 负责参与业务部门应用系统运营流程中的关键节点,包含账号权限审核、审计日志的审核、灾备计划演练、系统的安全补丁和系统升级等;
Responsible for participating in the key nodes in the operation processes of the application systems of business units, including account authority reviews, audit log reviews, disaster plan rehearsals, system security patches and system upgrades, etc.;
12. 负责支持集团的其他安全相关工作。
Responsible for supporting other corporate work related to security.
任职资格:
1. 全日制本科及以上学历,计算机、信息技术、通信等相关专业毕业;
Full-time bachelor degree or above, major in computer, information technologies, communications, etc.
2. 2年以上相关工作经验,品德优秀,勤奋踏实,积极上进,拥有良好的职业道德素养;
At least 2 years’ of relevant work experience, excellent moral character, diligent and steadfast, positive and motivated, with good professional moral quality;
3. 具备较强的书面文档功底和表达能力,英语熟练;
Strong written and spoken abilities, a good command of English;
4. 在安全管理体系、审计方面有深入研究,具备相应从业资质者优先。
In-depth research in respect of safety management system and audits, and those have relevant qualifications are preferred.
5. 工作态度认真负责,积极主动,并可以承受较强的工作压力;
Serious and responsible, proactive and able to work under strong pressure;
公司介绍
联系方式
- Email:zhuyun@wuxiapptec.com
- 公司地址:江北新区华康路122号南京生物医药谷加速器四期07栋
- 电话:15738851478