基本信息

职位编号:
WD00078854
工作领域:
Information Technology
国家/地区:
中国
省:
北京
市:
北京(Beijing)
日期:
星期二, 2 月 25, 2025
工作性质:
Full-time
其他工作城市
* China - Beijing - 北京(Beijing)

为什么选择联想

联想文化,我们称之为 “We Are Lenovo”(我们,就是联想),其核心是:“说到做到,尽心尽力,成就客户”。

联想集团是一家年收入569亿美元的全球化科技巨头,位列《财富》世界500强第248名,服务遍布全球180个市场数以百万计的客户。为实现“智能,为每一个可能” 的公司愿景,联想在不断夯实全球个人电脑市场冠军地位的基础上,积极构建全栈式的计算能力,现已拥有包括人工智能赋能、人工智能导向和人工智能优化的终端、基础设施、软件、解决方案和服务在内的完整产品路线图,包括个人电脑、工作站、智能手机、平板电脑等终端产品,服务器、存储、边缘计算、高性能计算以及软件定义等基础设施产品。这一变革与联想改变世界的创新一起,共同为世界各地的人们成就一个更加包容、值得信赖的智慧未来。联想集团有限公司在香港交易所上市(港交所:992)(美国预托证券代号:LNVGY)。

欢迎访问联想官方网站 https://www.lenovo.com,并关注“联想集团”微博及微信公众号等社交媒体官方账号,或关注“联想招聘”公众号,获取联想最新动态。

职位描述和要求:

Job Responsibilities:

·       Working cross-functionally to develop strategies to identify, mitigate and manage current and emerging cyber threats.

·       Providing constructive advice and challenge on the management of cyber risks throughout the organisation.

·       Working closely with IT and other stakeholders to ensure a multi-layered approach to cyber security is adopted, ensuring the confidentiality, integrity and availability of IT services.

·       Creating, developing and maintaining security policies and practices.

·       Coordinating advanced technical engagements ranging from, but not limited to, risk assessments, penetration testing, application security, business continuity, third parties and compliance reviews.

·       Analysing technical vulnerabilities and providing impact assessments and managing the vulnerability management process.

·       Integrating into the software development security lifecycle (SDL) and DevSecOps, directing and advising design, service, operations teams on security requirements coding standards, and implementation, configuration good practice and hardening techniques.

·       Helping analyse and mitigate incidents raised to the information security team

·       Providing a Risk Management approach to ensure information security solutions and controls are commensurate to the business risks.

·       Providing support and mentoring to other members of the security management team.

Job Requirements:

·       CISSP/CISM/CISA/CEH or similar level qualification.

·       A high level of technical knowledge of architectural techniques, such as threat modelling to prevent, mitigate and manage security threat.

·       Have a deep understanding of cloud computing and possess knowledge and experience related to cloud computing security compliance and operations.

·       Strong experience with SDL and DevSecOps methodology & Continuous Improvement/Continuous Development, driving development teams to implement security left shift in the development process.

·       Operational Cyber security management experience gained in, or working as part of a Managed Service provider.

·       Knowledge of ISO27001, NIST, CIS and other similar standards/frameworks

·       Strong operational experience of managing cyber security and risk within fast-paced technology environments.

·       Familiar with penetration testing theory and commonly used tools, able to perform source code scanning, basic penetration testing and provide improvement suggestions.

·       Experience of SIEM solutions, incident management and reporting

·       Excellent communications skills and stakeholder management experience

·       Ability to think of long-term strategic solutions as well as quick resolutions to problems.

·       The ability to create, develop and maintain security policies and practices.

·       Excellent problem solving, critical thinking, analytical and decision-making skills.

·       Good English, written and spoken.


其他工作城市
* China - Beijing - 北京(Beijing)
* China - Beijing - 北京(Beijing)
* China - Beijing
* China