Senior Manager, APAC IT GRC
beigene · 大连市, 辽宁, 中国
About The Role
General Description: BeOne is seeking a Senior Manager of GTS GRC to build, enable and transform its risk management, compliance and security capabilities and resources in APAC region. The GTS GRC Senior Manager is a critical position within the organization and has GRC responsibilities from a technology and security perspective across the organization. Working closely with the Director of Global GTS GRC, this position will be responsible for building and enhancing the GRC portfolio of efforts to raise the overall security and compliance posture for BeOne. This position will also be directly responsible for implementing, maintaining and improving policies, procedures and internal controls to assure compliance with applicable regulatory and legal requirements as well as best practices. The GTS GRC Senior Manager will drive and enforce third party risk management through streamlined third-party risk assessments and third party threat intelligence by designing controls and implementing industry best practice processes across the organization. The role will lead an end-to-end risk management process to drive in-time risk mitigation and resolution within the region. The role will work across multiple frameworks and regulatory standards including, but not limited to SOX, GxP, ISO, NIST CSF, CSL/DSL/PIPL, and other relevant data security & privacy laws and regulations in APAC region. This position will liaise with all business groups including but not limited to Finance, Internal Control, Internal Audit, Legal, Compliance, TechOps, R&D, HR, Quality and other stakeholders in APAC region to implement new solutions and processes as well as document and remediate outstanding issues. This role will drive the establishment of policy, standard and procedures for specific functional domains as well as regional SOPs under global Information Security Management System. Lead and manage training and awareness enhancement through policy and cyber hygiene training. This role will also have responsibility for the implementation and ownership of a GRC system that will be used to further automation of the program. Essential Functions of the job : Responsible for implementation of controls to build and enhance the GRC program. Responsible for monitoring, remediation, and reporting of controls gaps in the IT and Cybersecurity program areas. Provide management level status update and risk profile dashboards including current and desired future state of control maturity. Responsible for leading internal IT, Cybersecurity, and third-party information security risk management activities for various information services systems and processes. Collaborate with IT and business stakeholders to understand risks to critical infrastructure by defining potential business impacts. Assess, report and mature the compliance posture for internal policies and guidelines as well as regulatory requirements based on frameworks including SOX, GxP, ISO, NIST CSF, CSL/DSL/PIPL, and other relevant oriented data security & privacy laws and regulations in APAC region. Maintain, improve, and enforce BeOne security policies and IT security standards along with security exception processes. Effectively engage IT, stakeholders, business partners, and vendors to maintain an understanding of current risks, new systems, and changes to the environment. Lead efforts including but not limited to: IT Policy Management, IT Compliance Management, Training & Awareness Management, IT Risk Management and Third Party Security Risk Management.. Responsible for establishing and managing regional GRC shared service center for operationalized service pipeline, such as third party risk assessment, GRC tool operation. Qualifications: 12+ years experience of GRC implementation, processes, and practices Experience working with and implementing GRC tools and processes, e.g. OneTrust. Experience building and developing successful risk management programs. Experience with third party risk management and conducting third-party risk assessments. Experience creating and maintaining security policy, standard, guideline and procedure documents Experience leading GRC functions and playing role of people manager with effective people coaching capabilities. Extensive knowledge and experience in security and compliance frameworks such as SOX, GxP, NIST, ISO, etc. Experience leading GRC or relevant service domain in a shared service center. Preferred: Strong leadership, accountability and ownership of responsibilities Strong soft skills of communication with different business functions and stakeholder functions (e.g. Internal Audit, Internal Control, Legal & Compliance, External Audit, etc). Strong experience leading regulatory compliance effort for SOX, CSL/DSL/PIPL, and other cyber/data laws and regulations in APAC region. Experience in facilitating and performing third-party vendor risk assessments with the ability to provide guidance on secure design and operation. Advanced understanding of information security concepts including: cloud security and compliance, encryption, access controls, intrusion detection and prevention, disaster recovery, network security, security operations, security architect. Experience working in a global enterprise environment. Experience working with AI driven proactive, automated mindset and solution in cybersecurity and GRC domain. Relevant and current industry certification(s): CRISC, CISSP, CISM, CISA 百济神州全球胜任力 当我们通过以下十二项全球胜任力,展现出 "患者为先"、"无界协作"、"锐意创新 "和 "追求卓越 "的价值观时,我们就能帮助全世界更多患者获得更多负担得起的药品。 ●团队协作 ●提供并征求坦诚及可行的反馈 ●自我认知 ●兼容并蓄 ●积极主动 ●开拓精神 ●持续学习 ●拥抱变化 ●结果导向 ●分析性思维/数据分析 ●卓越财务 ●清晰沟通 BeOne Global Competencies When we exhibit our values of Patients First, Collaborative Spirit, Bold Ingenuity and Driving Excellence, through our twelve global competencies below, we help get more affordable medicines to more patients around the world. ●Fosters Teamwork ●Provides and Solicits Honest and Actionable Feedback ●Self-Awareness ●Acts Inclusively ●Demonstrates Initiative ●Entrepreneurial Mindset ●Continuous Learning ●Embraces Change ●Results-Oriented ●Analytical Thinking/Data Analysis ●Financial Excellence ●Communicates with Clarity 求职者隐私申明: 百济神州致力于尊重和保护您的个人信息权利,并承诺依据合法、正当、必要和诚信的原则处理您的个人信息(包括个人敏感信息 )。 由于百济神州在全球范围内开展业务,我们可能需要基于人力资源管理等合理业务目的而将您的个人信息发送和/或存储在位于您所在国家以外其他国家(例如:美国)的服务器和数据库中,详情参见百济神州《求职者隐私政策》(百济神州官网 - 隐私政策 - 求职者隐私政策)。 如您主动向我们提供您的简历信息或其他个人信息,则视为您已经充分理解并确认接受百济神州《求职者隐私政策》内容。如您对此有任何疑问的,请勿提交简历信息或其他个人信息。 BeOne is committed to respect and protect your personal information rights, and will process your personal information, including your sensitive personal information, based on the principles of legality, legitimacy, necessity, and integrity. Due to the reasonable business need for human resource management as a result of BeOne’s global operation, your personal information may be transferred and/ or stored in a server/database located in a third country (e.g., the United States) other than your own country. For further details, please refer to BeOne Job Applicant Privacy Policy (BeOne official website - Privacy Policy - Job Applicant Privacy Policy). If you voluntarily provide your resume or other personal information to us, it is deemed as you have thoroughly acknowledged and accepted BeOne Job Applicant Privacy Policy. If you have any concern, please DO NOT submit your resume or any other personal information.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring