English summary for screening — check the original posting before applying.
This role is central to promoting company-wide information security, supporting business units to operate safely and stably. You will act as the second line of defense, establishing and enhancing security systems, maintaining certifications, and reporting to management. Initially focused on information security, the role is expected to expand to overall governance, including company-wide risk management and compliance.
Must-haves
- Experience in information security systems and operations
- Experience in acquiring and maintaining certifications like ISMS (ISO/IEC 27001) and Privacy Mark
- Experience in developing/revising information security policies and regulations
- Experience in security reviews for businesses (BPO/SaaS) and third-party risk assessments
- Experience in responding to information security incidents
- Experience in planning and executing security education and awareness activities
Nice-to-haves
- Experience in establishing, operating, and improving company-wide risk management systems
- Experience in establishing and controlling compliance systems
- Experience in strengthening company-wide crisis management systems (BCP/BCM)