Cyber Security Manager – Risk Management and Data Security
面议
Risk Management & Lifecycle:
Lead the end-to-end risk lifecycle management, including identification, assessment, mitigation, monitoring, and reporting of cybersecurity risks.
Develop and implement risk management frameworks and policies aligned with industry standards such as NIST, ISO 27001, and COBIT.
Provide expert security recommendations and define requirements for projects, initiatives, and technologies to embed security by design.
Advise on best practices for threat modeling, vulnerability management, and incident response planning.
IT System Risk Assessment:
Conduct thorough risk assessments of IT systems, including infrastructure, applications, and cloud environments, to identify vulnerabilities and recommend remediation strategies.
Collaborate with IT teams to integrate risk assessments into system design, deployment, and maintenance processes.
Vendor Risk Assessment:
Oversee third-party vendor risk assessments, evaluating security postures, compliance, and contractual obligations to mitigate supply chain risks.
Manage vendor onboarding, ongoing monitoring, and offboarding processes with a focus on cybersecurity due diligence.
Data Security Risks:
Assess and manage risks related to data security, including data classification, encryption, access controls, and breach prevention.
Develop strategies to protect sensitive data across on-premises, cloud, and hybrid environments, ensuring compliance with regulations like CSL, PIPL, DSL, MLPS, etc.
Cybersecurity Performance Measurement:
Establish and monitor key performance indicators (KPIs) and metrics for cybersecurity governance, such as risk exposure levels, compliance rates, and maturity assessments.
Conduct regular governance reviews to measure the effectiveness of cybersecurity controls and programs.
Internal Portfolio Management and Leadership Reporting
Support the cybersecurity team's internal portfolio management, including prioritization of initiatives, expense management, project tracking to align with organizational goals.
Facilitate agile practices within the team to ensure efficient delivery of cybersecurity projects and programs.
Prepare comprehensive reports to executive leadership and boards, highlighting risk profiles, performance metrics, and strategic recommendations.
Translate complex technical risks into business-oriented insights to support informed decision-making.