Manager, Cybersecurity & Information Protection (APAC&EMEA)-Base SH or BJ
On-siteShanghai, Shanghai, China or Beijing, Beijing, China
Job Summary
Lead the enterprise information protection program and serve as the primary Technology & Cyber Privacy Advisor for APAC and EMEA. Assess and manage cybersecurity risks for business initiatives, applications, and third-party engagements while ensuring compliance with regulations including GDPR, CSL, DSL, PIPL, NIS2, and DPDPA. Partner with stakeholders to define information protection controls, develop data protection policies, and support regulatory inspections, audits, and remediation planning. Monitor emerging threats and drive security awareness initiatives across the organization. This role requires flexibility to collaborate across multiple time zones and supports Business Units in navigating privacy obligations within a complex, regulated pharmaceutical environment.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, Information Systems, Risk Management, or a related field
- 7+ years of experience in cybersecurity, information security, data protection, privacy, regulatory compliance, risk management, or related disciplines
- at least 2 years in a supervisory or project leadership capacity
- Strong knowledge of cybersecurity governance, risk management, compliance frameworks, and applicable regulatory requirements
- Strong understanding of cybersecurity and data protection regulations, including CSL, DSL, PIPL, GDPR, DPDPA, NIS2, and related requirements
- Experience supporting cybersecurity assessments, audits, regulatory inspections, compliance programs, or risk management initiatives
- Experience and hands on familiarity with DLP and data discovery tools, as well as data labeling and tagging solutions, including deployment and ongoing support
- Working knowledge of data encryption concepts and approaches across different environments
- Strong stakeholder management, communication, and influencing skills, with the ability to work effectively across business and technology functions in a global environment
- Strong project coordination across business and technical teams
- Professional proficiency in English
Desired Qualifications
- Professional certifications such as CISSP, CISA, CISM, CRISC, CIPP/E, CIPM, or equivalent
- Experience supporting cybersecurity, information protection, data privacy, or regulatory compliance programs within the pharmaceutical, healthcare, or life sciences industry
- Hands‐on experience with GRC platforms (e.g., Archer)
- Familiarity with privacy, intellectual property protection, and regulated data environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.