Information Security Officer
CN
What you do
1. 信息安全体系建立与维护:
建立并维护公司信息安全管理体系框架,确保制定相应的信息安全政策、标准及操作流程,并完成文档化记录;支持信息安全管理流程的设计与落地。
2. 治理层汇报与专业建议:
定期向董事会、集团信息安全官(ISO)汇报信息安全工作状况;向公司董事会、员工及管理人员提供信息安全专业建议,推动安全决策。
3. 培训与文化建设:
落实信息安全相关培训,确保员工及管理人员充分理解并遵守信息安全要求,提升全员信息安全意识。
4. 合规监控与报告:
实施并监控信息安全控制措施,确保满足中国法律法规及安联集团安全政策要求。一旦发现不符合项,立即向集团信息安全官报告。
5. 事件管理与调查:
管理信息安全相关的事件、问询及合规诉求,组织调查并跟进处理,根据事件严重程度向集团信息安全官汇报,并推动整改措施落实。
6. 主管分配的其他工作任务。
What you bring
1. 全日制大学本科及以上学历,信息技术、信息安全、计算机科学等相关专业优先;
2. 5年以上工作经验,其中至少3年以上信息安全专业经验;
3. 具备跨国集团型公司或金融/保险行业信息安全管理实践经验;
4. 熟悉中国网络安全法、数据安全法及相关监管要求,有应对监管检查或外部审计的经验;
5. 具备信息安全管理体系(ISO 27001)建设和维护、信息安全事件应急响应、调查取证实操、以及有向董事会或高级管理层汇报的经验;
6. 持有CISSP认证优先,持有CISM、CISA等安全认证者优先;
7. 熟悉常见信息安全技术(防火墙、IDS/IPS、DLP、EDR、加密、身份认证等);
8. 了解人工智能相关的安全风险(如AI模型对抗攻击、模型投毒等),具备AI安全技能者优先。
What we offer
Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us.
We at Allianz believe in a diverse and inclusive workforce and are proud to be an equal opportunity employer. We encourage you to bring your whole self to work, no matter where you are from, what you look like, who you love or what you believe in.
We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, disability or sexual orientation. Join us. Let's care for tomorrow.