Sr.Manager, IT Security & Risk
Beijing, Beijing, CN
Key responsibilities 重要职责
- Develop and enhance up-to-date application security, risk & quality framework, determine governance approach and operating model , enable DHT (Digital Health & Technology) team to follow application security, risk & quality framework and operating model
- Responsible to monitor and maintain IT security control requirements from GIS (Global Information Security), lead gap analysis and design best-fit security solutions
- Conduct regular security, risk & quality assessment to identify early discovery of vulnerabilities and identify gaps for improvement. Enforce DHT to optimize and report result to NNRC security committee or even senior leaders on the improved maturity
- Ensure fulfilment of IT Risk Manager responsibilities for IT systems/services/projects, advise on information security execution quality matters, and assistance in closing gaps found in risk assessment review and IT audit.
- Responsible to continuously improve information risk assessment process execution efficiency.
- Form Security awareness culture and accountability and provide training to stakeholders, ensure security are built in by design.
Education 教育背景
- Bachelor's degree in information system, computer science, or equivalent
- Degree in technology consulting related field, or equivalent work- or education-related experience is desire
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials
- Minimum 7 years of experience on information security in IT
- Minimum 5 years of IT risk and security SME related work (security, audit and regulations)
- Minimum 5 years of IT operation or IT project experience
- Security & risk auditing experience is highly preferred
We commit to an inclusive recruitment process and equality of opportunity for all our job applicants.
At Novo Nordisk we recognize that it is no longer good enough to aspire to be the best company in the world. We need to aspire to be the best company for the world and we know that this is only possible with talented employees with diverse perspectives, backgrounds and cultures. We are therefore committed to creating an inclusive culture that celebrates the diversity of our employees, the patients we serve and communities we operate in. Together, we’re life changing.