Mercedes-Benz Group China Ltd.

Information Security Consultant

Mercedes-Benz Group China Ltd.

Mercedes-Benz Group China Ltd., Beijing (Hybrid)

Job Type Full-time
Experience Senior
Posted 4 weeks ago
Hybrid Senior Level

Objective of the job

Ensure that the organization and IT assets follow security standards and governance. Monitor and identify vulnerabilities, threats, and issues, document findings, track remediation, and develop and implement cloud security strategies.

Responsibilities

  • Govern compliance with policies and processes protecting the confidentiality, integrity, and availability of IT assets.
  • Own organizational and technical controls, support risk assessment and analysis, and monitor risk mitigation measures.
  • Identify vulnerabilities in services and applications; order and monitor penetration and assessment services; document results and ensure remediation.
  • Assess threats, develop appropriate security measures, and evaluate their effectiveness.
  • Assist business partners with information classification.
  • Coordinate security incidents and participate in incident response, including mitigation and remediation.
  • Maintain disaster and application recovery plans.
  • Develop and conduct target-group-oriented security awareness campaigns.
  • Define security controls derived from policies.

Job designation

  • Develop, maintain, and enforce information security policies, standards, and procedures aligned with legal, regulatory, and contractual requirements.
  • Ensure compliance with relevant laws, regulations, and standards such as ISO 27001 and NIST.
  • Plan and conduct internal security audits and coordinate external audits and assessments.
  • Identify, assess, and manage information security risks and contribute to the information security governance framework.
  • Prepare compliance reports, track security metrics, document compliance activities, and communicate risks and issues.
  • Monitor policy compliance, investigate violations, and take corrective action.
  • Assess third-party suppliers' security practices, review vendor contracts, conduct security assessments, and monitor compliance.
  • Collaborate with IT teams, developers, and business stakeholders; provide security training and awareness; and communicate recommendations to management.

Qualifications

  • Deep understanding and experience in IT security, risk management, compliance and security standards, operating systems, and data protection.
  • Knowledge of cloud security, networks, web technologies, databases, and IT operations including ITIL.
  • Experience with security frameworks such as NIST and ISO 27001.
  • Relevant certifications such as CISA or CISSP.
  • More than 5 years of experience focused on security governance and security operations.
  • Bachelor's degree or higher in Computer Science encompassing Information Security.

Benefits

Benefits include flextime, possible hybrid work, health benefits, mobility offers, employee discounts, possible parking, an in-house doctor, good public transport, a barrier-free workplace, and a canteen or café.

Similar Job Openings