职位详情
Regional CSO
2.5-3.5万·14薪
银捷尼科(福建)科技有限公司
福州
10年以上
本科
10-31
工作地址

福州软件园E区1座

职位描述
Role overview
The Regional Chief Security O;icer (R-CSO) is responsible for implementing, controlling, and continuously improving the Group’s global security strategy within his designated region. Acting as the senior security leader locally, the R-CSO ensures alignment with global policies while addressing regional needs, regulatory requirements, and customer expectations. With cybersecurity as the primary focus, this role also encompasses operational and industrial security as well as physical protection of people and assets, business continuity and crisis management. This role is both operational and strategic, requiring strong leadership, communication, and influence skills.
As part of the Group’s second line of defense, the R-CSO ensures independent oversight, control, and challenge of security practices implemented by the business and operations teams.
Key Responsibilities:
1. Governance, Risk & Compliance
o Apply, deploy, and monitor the Group’s security policies and standards within the region, ensuring alignment with global frameworks.
o Evangelizing on cybersecurity, addressing Executives, Senior leaders and Representing Ingenico in external Information Security communities.
o Organize and manage risk security committees for the Region, providing regular risk reports and key metrics to the Group CSO and regional leadership team.
2. Incident, Crisis Management and Business Continuity
o Own all security incidents in the region, ensuring e;ective response, escalation, and communication.
o Act as regional crisis leader, coordinating with Incident management
organization, Group CSO, local management, and authorities.
o Control the e;ectiveness of incident, crisis, and business continuity response plans through testing, drills, and independent reviews.
3. Customer & Partner Engagement
o Act as the primary security point of contact for regional customer questionnaires and audits , RFPs, and due diligence activities.
o Support business development by demonstrating the Group’s security posture
o Build trusted relationships with partners and external stakeholders on security matters.
o Provide independent oversight of third-party and supply chain security in the region.
o Coordinate with internal stakeholders for such matters
4. Communication, Awareness & Culture
o Serve as a trusted advisor and business partner to regional executive management, translating technical risks into business impacts.
o Lead cultural change and regional awareness campaigns across cybersecurity, industrial, and physical domains.
o Represent the Group at regional industry events, regulatory forums, and standardization bodies to influence and anticipate evolving requirements.
o Liaise with local and regional authorities (e.g., regulators, law enforcement, CSIRTs) on security topics.
5. Physical & People Security
o Oversee the security of facilities, assets, and employees in the region.
o Control and monitor programs for access control, surveillance, executive protection, and insider risk management.
Key Requirements:
• Education:
o Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field.
o Advanced certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Implementer/Lead Auditor are highly preferred.
• Experience:
o Minimum of 10 years of experience in information security, with at least 5 years in senior leadership roles (e.g., CISO, Director of Information Security).
o Proven experience in managing information security for regulated industries, particularly in the payment solutions or financial services sectors.
o In-depth knowledge of global security frameworks and standards such as PCIDSS, ISO 27001, NISv2, and DORA.
o Strong experience in drecting cross-functional teams to design, develop, and implement secure payment terminals and related systems.
o Hands-on experience with security certifications, audits, and assessments related to ISO 27001, PCI-DSS, and other applicable regulatory frameworks.
• Skills:
o Expertise in information security management, including risk assessment, vulnerability management, security architecture, and secure coding practices.
o Strong leadership and team-building abilities, with a proven track record of directing security teams and projects.
o Exceptional communication skills, with the ability to communicate complex security concepts to both technical and non-technical stakeholders.
o Deep understanding of incident response and crisis management, particularly related to payment systems and customer data protection.
o Proficiency in cybersecurity technologies, such as firewalls, encryption,
intrusion detection/prevention, SIEM, and other tools relevant to securing
payment terminals.
Desirable Skills:
• Experience with cloud security, network security, and endpoint security technologies in the context of payment systems.
• Familiarity with digital resilience, business continuity planning, and disaster recovery processes in alignment with DORA.
• Good Knowledge on Cloud solutions and O365 security
• Experience in third-party risk management and ensuring compliance across the supply chain for third-party vendors, particularly in the context of hardware and software used in payment terminals.

以担保或任何理由索取财物,扣押证照,均涉嫌违法,请提高警惕

立即申请