Jobless Developer
Lalamove logo

Posted Today

Open

Lead, Risk Operations (Infomation Security)

Hong KongOn-siteFull-time

AI Summary

Lead Risk Operations (Information Security) at Lalamove oversees office security strategies, conducts audits, and handles violations to safeguard employee data globally, collaborating with Legal, HR, IT, and business teams.

About this role

At Lalamove, we believe in the power of community. Millions of drivers and customers use our technology every day to connect with one another and move things that matter. Delivery is what we do best and we ensure it is always fast and simple. Since 2013, we have tackled the logistics industry head on to find the most innovative solutions for the world’s delivery needs. We are full steam ahead to make Lalamove synonymous with delivery and on a mission to impact as many local communities we can. We have massively scaled our efforts across Asia and now have our sights on taking our best in class technology to the rest of the world. And we are looking for talented professionals to join us in this journey!

We are seeking an experienced Lead, Rsk Operations (Information Security)- to oversee the formulation, implementation of office security strategies, conducting audits, monitoring, and violation handling around employee data security risks to safeguard the company's data assets globally. This role requires close collaboration with Legal, HR, IT, and overseas business teams to drive continuous optimization of the security operations system.

What you will do:

Office Security Strategy Operations
  • Lead daily policy configuration, operations monitoring, and alert handling for office security software (DLP, IM, encryption software, etc.);
  • Drive implementation of data classification and grading policies in office scenarios to ensure sensitive data is manageable, controllable, and traceable;

  • Employee Risk Audit
    • Establish and operate an employee data security risk monitoring system, identifying insider threat risks through multi-source data such as DLP alerts, UEBA behavior analysis, and business audit logs;
    • Through high-risk scenario operations and audit analysis, complete business risk assessments and deliver governance, risk mitigation, and control solutions to business lines; responsible for onboarding, acceptance, and quality control of business system audit logs to ensure log integrity and compliance;
    • Conduct traceability analysis and impact assessment for security incidents such as data leakage, unauthorized outbound transmission, and unauthorized access, and lead or assist in emergency response and remediation;
    • Conduct preliminary verification, evidence collection, interviews, risk assessment, and grading based on violation leads, and form professional investigation opinions to ensure handling is standardized, efficient, and traceable;
    • Establish tiered and categorized violation handling standards and SOPs, and drive closed-loop management of violation handling.
    -
    Cross-functional Collaboration and System Development
    • Work closely with Legal, Compliance, HR, IT, GRC, and other teams to coordinate the establishment of security-related frameworks;
    • Participate in drafting and revising overseas trade secret management policies and operating procedures to ensure compliance with global data protection regulations such as GDPR, CCPA, and PDPA;
    • Organize and deliver employee information security awareness training and communications.

What you will need:

  • Full-time bachelor's degree or above, preferably in Information Security, Cybersecurity, Computer Science, Audit, or related fields;
  • 5+ years of experience in data security, information security, or related fields; background in Internet or foreign-invested enterprises preferred.
  • Familiar with office network security architecture, with experience in developing and operating data security policies for office endpoints, networks, email, and other scenarios.
  • Excellent English and Mandarin, with proficiency in cross-border team communication, English document writing, and overseas business reporting;
  • Excellent cross-functional communication and coordination skills, with the ability to effectively overcome cross-cultural collaboration challenges;
  • Holding information security-related certifications such as CISA or CISSP;
  • Security operations experience in overseas/going-global business;
  • Skills

    Audit Log IntegrityCCPACISACISSPData ClassificationDLPGDPRIncident TraceabilityInformation SecurityOffice Network SecurityPDPARisk AssessmentSecurity OperationsUEBA

    Explore related jobs

    Browse these categories

    Market data for this role

    All reports →