職位描述
Objective: Lead the implementation and oversight of Danone's cybersecurity operational tasks across CNAO region (Greater China, Japan, Oceania). Ensure the confidentiality, integrity, and availability of critical business assets by driving compliance with local regulations (including China PIPL, MLPS), managing cyber risks, and fostering a robust security culture. Bridge global security mandates with regional execution to protect Danone's operations, reputation, and data.
Responsibility:
1. Manage Identity & Access Governance (Incl. Reviews & PAM)
- Work with global cyber team to perform user access reviews at least every 3 months for personal accounts and every month for administrative/service accounts.
- Ensure reviews identify terminated users (confirmed leavers by HR) and inactive users
- Review privileged accounts monthly to ensure compliance with least privileged principles
- Verify privileged users have separate non-privileged accounts for routine activities
2. Oversee Endpoint Security Compliance
- Monitor corporate devices (laptops, desktops, mobile devices) for compliance with Danone's cybersecurity policies.
- Track deployment status of Sentinel One antivirus agents and VPN agents
- Identify and document non-compliant devices, investigating reasons for non-compliance and working with local IT service desk team / global cyber security team to fix
3. Drive Cybersecurity Awareness & Training
- Develop monthly cyber security awareness communications to all employees in alignment with Danone's Cyber safe Policy
- Create engaging content to promote cybersecurity best practices and company policies
- Conduct cyber safe annual training to Danoners an Danone external employees
4. Local Business Collaboration
- Support that the 'Risk based design' principle is integrated into business processes via tasks / Projects
- Coordinating IT Audits & Risk Governance
- Collaborating on IT Security Integration for Local Projects
5. China Local Laws and Regulations compliance
- Support Personal Information and other critical assets, with coordinating to IT&DATA team to encrypt and fulfill CN PI CBDT scenario.
- Support compliance with China's Cybersecurity Law (CSL), Multi-Level Protection Scheme (MLPS) certifications for local applications, and the Personal Information Protection Law (PIPL), specifically addressing CBDT requirements through technical controls
Experience & Education:
- Bachelor's degree or above in Computer Science, Information Security, or related fields.
- Hold certifications such as CISSP, CISM, CISA, or similar are a plus.
- Extensive expertise: Minimum 5+ years of progressive experience in information security and/or related functions (e.g. Information Technology, data protection)
- Leadership: Minimum 3+ years of experience in China cybersecurity-related fields management position within multinational manufacturing or fast-moving consumer goods (FMCG) industries.
- Global team leadership: Experienced in orchestrating cross-border collaboration across geographically dispersed teams, with proficiency in managing multicultural work environments and interdepartmental workflows.
- Experience in incident response management
- Regulatory compliance: Understanding of China’s cybersecurity regulatory landscape, including Cybersecurity Classified Protection 2.0 (MLPS 2.0) to FMCG operational contexts.
Skills
- Excellent in-depth knowledge of IT security architecture and risk management frameworks (e.g. ISO 27001, NIST).
- Proven ability to make risk-based decisions balancing security and business objectives
- Understanding of cybersecurity risks specific to manufacturing, supply chain, and FMCG operations.
- Strong knowledge of cloud security principles (Alicloud, AWS, Azure, ...) and securing SaaS applications
- Fluent in English and Mandarin with proven aptitude for bridging cultural and operational gaps between multinational teams, capable of efficiently coordinating global and local teams.