
Head of Security
- Shanghai
- RMB¥1,200,000 per year
- Permanent
- Full-time
- Leadership & Governance: Lead the Security and Security Operations Center (SOC) teams to ensure robust defense mechanisms.
- IT System Compliance: Ensure IT systems and applications in the organization meet business needs while adhering to security best practices, compliance requirements, and BSP regulations.
- Risk Management: Present risk assessments and recommend actionable security policies to management.
- Expert Involvement: Actively engage in high-complexity projects requiring expert-level knowledge in cybersecurity across technical areas and business segments.
- Protocol Review: Regularly review existing security measures and update protocols as needed.
- Cybersecurity Strategy: Drive security strategies and implement solutions that minimize cybersecurity risks and maintain business continuity.
- Operational Oversight: Oversee daily operations to identify security risks and improve protocols.
- Threat Assessment: Identify cybersecurity risks from internal systems and vendors, perform threat assessments, and develop solutions to enhance the security posture.
- Security Awareness: Foster a culture of security awareness through training and frequent communication within the organization.
- Regulatory Compliance: Ensure adherence to security policies that comply with federal laws and regulations in all countries of operation.
- Judgment & Decisiveness: Exercise sound judgment to protect confidential corporate information and ensure security resilience.
- Budget Management: Work with management to develop and implement budgets for security programs.
- Minimum of 8 years of experience in cybersecurity with at least 5 years of leadership and managerial experience.
- Expertise in security industry standards, data protection regulations, and ISO 27001.
- Proven knowledge of BSP regulations.
- Familiarity with blockchain technology and the cryptocurrency market (highly preferred).
- Operational risk and/or technology risk certifications such as CISA, CISM, CISSP, CCSP, CIPP, CIPM, etc., are advantageous.
- Strong collaboration experience across business units, balancing business growth with security.
- Up-to-date knowledge of current trends and best practices in security.