Cybersecurity Strategy, Frameworks, Policies & Standards
• Adapt and contextualize strategies for deploying information security technologies.
• Contribute to the design and implementation of an information security management framework.
• Develop architecture maps (functional, application, technical views).
• Establish cybersecurity standards and processes, including those related to AI.
• Define regional cybersecurity rules and local information security charters.
• Support the development of global strategies for managing security incidents and initiating investigations.
Data Protection
• Ensure compliance with regional data protection laws and regulations (e.g., China Cybersecurity Law, Data Security Law, Personal Information Protection Law, CBDT Policy, and chemical industry standards).
• Support data protection activities at plant level, adhering to national standards for Industrial Control Systems.
Day-to-Day Responsibilities
Prevention & Communication
• Raise awareness among regional users about IT security threats and risks.
• Conduct cybersecurity risk assessments and report findings with KPIs.
• Implement effective processes for reporting security incidents.
Risk & Incident Management
• Ensure regional execution of Arkema’s Business Continuity Strategy.
• Monitor vulnerabilities and hacking threats across networks and host systems.
• Lead investigations into reported breaches and incidents.
• Analyze incidents to prevent recurrence.
Governance
• Manage the regional cybersecurity budget and communicate with relevant stakeholders.
• Oversee the regional cybersecurity department, supporting and developing IT security teams and advisors.
• Review, analyze, and deliver data insights to management.
Continuous Improvement
• Stay updated on cybersecurity innovations, technologies, and regulatory changes.
• Optimize costs related to cybersecurity.
• Enhance end-user awareness of cybersecurity laws and regulations.
• Conduct audits, tests, and risk assessments.
• Continuously evaluate IT security practices and systems, identifying areas for improvement.
• Lead enterprise-wide AI cybersecurity strategies to safeguard AI systems and data.
• Assess and mitigate risks in AI technologies (model security, data privacy, algorithmic transparency).
• Develop incident response plans tailored to AI-driven platforms.
• Act as primary liaison with Chinese regulators on cybersecurity and AI compliance.