logo
更新:2024-04-11
(Senior) IT Compliance Engineer
2-3.5万
深圳福田区  | 3-5年  | 本科  | 社招
去申请
收藏
举报
职位详情
年终奖金
五险一金
通讯津贴
餐费补贴
领导好
发展空间大
扁平管理
岗位晋升
弹性工作
带薪年假
Job summary
The (Senior) IT Compliance Engineer is responsible for enhancing the IT compliance of the company’s business and IT operation. In the long term, this position would be heavily involved with Dezan Shira’s external clients for providing IT compliance services as well, once the internal IT compliance situation has reached a high enough standard. Consistent customer care, quality standards, strong communication skill, and knowledge of IT compliance requirements and practices are core competencies for the position. Ability to quickly adapt to changing priorities and fluctuations in workflow are also requirements of the IT Compliance Engineer role.

Principal Responsibilities: (Essential Function)
• Internal compliance management
o Follow the changes and trends in security compliance field and deliver the knowledge and experience through trainings and sharing sessions to internal and external stakeholders
o Coordinating with legal and operational teams to identify compliance gaps and perform improvement actions
o Building internal compliance management process, policy, procedure

• External compliance service to clients
o Identifying the applicable compliance requirements to the company under the context of existing business and IT operation / environment
o Conducting gap analysis against the security and compliance standard requirements and identifying the potential security and compliance of existing practice
o Evaluating the potential risks and locating the solutions for improvement
o Communicating with related stakeholders on the findings and corrective actions needed

• Compliance awareness training
o Conducting and implementing compliance awareness campaigns to all staff and external clients
o Arranging the compliance related training to internal IT / IS team and other key operation teams which involving large size of personal information processing

• IT Audit
o Deeply involving in annual review of ISO27001 and other potential accreditation work
o Taking part in external IT audit project when needed

• Other Information Security related work
o Auditing IT security level of all global offices and managing the information security threats associated with the operational environment
o Reviewing existing IT infrastructure, locating weaknesses on security and developing improvement plans
o Coordinating internal IT / IS team to implement security enhancement and mitigating security risk
o Developing security policies, procedures, and guides
o Developing & reviewing Business Continuity Plan and Disaster Recovery Plan

Job Requirements

Skills
• Be familiar with regulatory environment of China with hands-on compliance experience such as MLPS, privacy management or personal information protection
• Relevant experience in security and privacy law compliance including PIPL, CSL, DSL, GDPR and other IT-related laws, regulations, and national standards
• Experience of IT governance, risk management and control with knowledge of ISO27001, ISO27701. Experience of IT audit will be a plus
• Experience and knowledge of information security management will be a plus
• Good verbal and written communication skills, must be able to use English as working language
• Problem solving skills, organizational skills, and the ability to exercise sound judgment in any customer service scenario
• The selected candidate must be good team player with self-motivation and have the ability to work independently with minimal direction
• Willingness to travel and work beyond office hours in case of any urgent and important incidents

Education
• Bachelor in IT or related discipline
• Any certificate of CIPT / CDPSE / DPO / CISA / CISSP / ISO27001 will be a plus

Experience
• 3-5 years of experience in IT, with at least 2 years focus on compliance or information security
• Working experience in multi-national company will be a plus

其他信息
语言要求:英语

所属部门:GIT&IS
工作地址
深圳-福田区现代国际大厦2503-2504室
公司介绍
协力管理咨询(深圳)有限公司是一家在亚洲范围内,为中国及国际企业投资者提供境外投资法律、税务、人力资源、信息技术和投资咨询业务的多领域专业咨询公司。我们的业务遍及中国、印度和东盟各个地区,在亚洲拥有28个办公室,同时在欧美及一带一路沿线国家设有11个办事处。我们的目标是在亚洲地区复杂的法律环境监管下, 帮助和引导投资公司顺利建立、维护和发展其在该地区的相关业务。拥有超过26年的丰富经验以及一支庞大的专业商务咨询、税务、会计、审计、人力资源、信息技术以及研究和业务分析人员队伍的我们将是您在亚洲地区最值得信赖的合作伙伴。
若用人单位提供虚假招聘信息,以担保或其他任何名义收取财物,扣押或以保管为名索要证件,都属于违法行为,应当提高警惕。
发布于猎聘网