about the company.
We are a top global retail enterprise with worldwide business coverage and mature digital & security governance systems. Committed to global cloud infrastructure transformation and standardized information security management, the company strictly follows international compliance frameworks and industry best practices to ensure stable, secure and reliable global IT operations. We offer international working exposure, systematic career development and clear promotion paths for security professionals.
about the team.
We are a top global retail enterprise with worldwide business coverage and mature digital & security governance systems. Committed to global cloud infrastructure transformation and standardized information security management, the company strictly follows international compliance frameworks and industry best practices to ensure stable, secure and reliable global IT operations. We offer international working exposure, systematic career development and clear promotion paths for security professionals.
...
about the job.
- Develop and maintain security architectures for cloud platforms (e.g., Tencent Cloud, Azure, Azure, GCP), ensuring protections against cyber threats and compliance with best practices and regulatory standards.
- Conduct risk assessments and security reviews of infrastructure components, including Cloud IaaS and PaaS services, physical data center, OS, network, storage, etc.
- Lead the adoption of defense-in-depth strategies, integrating multiple layers of security controls across networks, systems, and endpoints.
- Design and implement IAM solutions, including role-based access control, privilege management, and identity federation.
- Evaluate and deploy infrastructure security tools and technologies.
- Provide training and guidance on infrastructure security best practices.
- Collaborate with IT, security operation, security governance teams to remediate vulnerabilities and respond to incidents.
- Stay current with emerging threats, technologies, and regulatory changes affecting infrastructure security.
skills and experience required.
- 任职资格
- Language Must:
- Fluency in Chinese and English, be able to speak and utilize it in daily work. *Nice to have in Japanese (English: CET6 / TOEIC 700 or above level.)
- Experience Technical skills:
- At least 8 years of experience in infrastructure security, cloud security, or IAM.
- Excellent knowledge and experience with cloud security architectures, IAM design, and defense-in-depth implementations.
- Hands-on experience of designing, implementing and operating security solutions (e.g. EDR, CSPM, WAF, PAM, SIEM, SOAR).
- Knowledge and Experience in information security frameworks (e.g. ISO27001, ISO27701, NIST CSF, etc.) and cloud security standards (e.g., CSA, CIS Benchmarks).
- Security certifications (e.g., CCSP, CISSP, AWS/Azure Security) are preferred.
- Cloud and infrastructure certifications (e.g. AWS, Azure, Linux, Windows, VMware, Cisco) are preferred.
- Education, skills, and abilities:
- Educational Background: IT, Information Security, Computer Science, Software Engineering or other related majors.
- A proactive and adaptable mindset, with a willingness to stay updated on emerging threats and technologies.
- Excellent communication skills to convey complex security concepts to technical and non-technical stakeholders.
- Ability to multitask, prioritize work effectively, and manage tasks/projects to completion.
- Ability to work independently and within a team environment.
- Highly motivated and strong sense of responsibility and ownership.
- Other Career Path: Personal growth within the Information Security Office in China and other foreign locations and broadening career to a wide range of opportunities depending on the candidates’ ability, aptitude, and motivation.