美团Business Security Manager
任职要求
1. Bachelor degree or above, with more than 3 years of experience in offline Internet security management or public security work. 2. Have good communication and coordination skills, be good at communicating and collaborating with relevant resources 3. Have good risk identification, conflict management, negotiation and security training capabilities
工作职责
The main work of handling security accidents, preventing safety accidents, and building and maintaining security resources in the jurisdiction includes: 1. Accident handling: responsible for the handling of safety accidents within the jurisdiction. 2. Security risk prevention: Responsible for understanding the policy information of traffic and public security , putting forward guidance and safety risk suggestions for operation, and coordinating the business in the region to do a good job in the prevention of various security incidents. 3. Support business development: Responsible for deploying local resources, communicating with local transportation, public security, union, criminal investigation, safety supervision and other departments in advance, assisting the business team to implement business actions, and ensuring the safety of business in the region 4. Safety culture promotion: Responsible for the safety culture promotion of each business in the jurisdiction, and coordinate the implementation and verification. 5. Establishment and maintenance of resources: cooperate with local public security, union, traffic police and other government departments to maintain good relations 6. Review and analysis: summarize the accident data , review and analyse the causes of the incident, and formulate a prevention plan, implement and feedback the effect. 7. Safety inspection: Responsible for regular and irregular safety inspections
• Monitor transactional data to identify suspicious patterns, emerging fraud trends and anomalies. • Design and maintain fraud detection dashboards, models, and rules using statistical and machine learning techniques. • Collaborate with product, engineering, and compliance teams to implement and fine-tune fraud detection. • Conduct root cause analyses on fraud incidents and provide actionable insights. • Develop reporting frameworks to communicate fraud trends, risk metrics, and investigation outcomes to stakeholders. • Continuously refine detection logic based on feedback and fraud evolution. • Support incident response teams in investigating and responding to fraud alerts. • Stay current with industry best practices and evolving fraud tactics.
1. Physical Security:• Develop and maintain physical security standards and procedures for all facilities.• Manage access control systems, surveillance technologies (CCTV), detection, and perimeter security.• Coordinate site risk assessments and implement corrective measures.• Oversee security contractors and ensure compliance with service-level agreements. 2. Security Operations Center (SOC):• Lead 24/7 monitoring of incidents, threats, and emergencies affecting personnel, facilities, and operations.• Manage incident reporting, escalation protocols, and real-time response coordination.• Ensure SOC integration with emergency services, crisis response, and business continuity teams.• Maintain incident tracking systems and dashboards with KPIs and performance reports. 3. EHS (Environment, Health & Safety):• Implement EHS programs aligned with local regulations and global standards.• Conduct safety audits, risk assessments, and compliance inspections.• Promote a safety culture through training, awareness campaigns, and best practice sharing.• Lead investigations of EHS-related incidents and ensure timely reporting and corrective actions. 4. Risk Management & Compliance:• Identify and assess security and safety risks across operations.• Ensure adherence to applicable laws, regulations, and industry best practices.• Develop and test emergency response plans, including fire drills, evacuation procedures, and crisis simulations. 5. Stakeholder Engagement & Reporting:• Prepare regular reports and presentations for senior leadership on security performance, incident trends, and risk posture.• Support cross-functional projects requiring security and safety input.
KEY PURPOSE OF ROLE The Country Security Lead (CSL) for ASML China acts as the local representative of the ASML CISO and protects and secures ASML’s Intellectual property, digital assets and technologies in China, in line with ASML’s Security strategy. The CSL for China develops and implements comprehensive security roadmaps for China, in close alignment with the local sector 1st line Security Risk Managers and the central 2nd line security team, to protect sensitive data against cyber and physical threats and ensures compliance with relevant regulations. ASML manages 1st line security via the sectors which creates a challenge on country level where multiple sectors can be represented. To manage security from a country point of view with local security risk managers reporting into the central sector SRM’s, ASML set up a Virtual Security Team (VST) to bring all relevant (security) representatives together in one virtual team to manage jointly security for China. The CSL forms and drives the Virtual Security Team (VST) in China, consisting of China’s first and second line security representatives and other relevant stakeholders, to improve the level of security maturity in China and report progress to the country’s Management Team. KEY RESPONSIBILITIES Overall: responsible for managing the China security organization on behalf of the CISO of ASML, driving the development and delivery of security services in China. Challenge and verify the adequate performance of security controls in China, against ASML and China risk appetite and as executed by the first line of responsibility in the sectors in China. Strategy: execute the central security strategy as determined by the CISO and adding country specific aspects to it to improve security maturity. Risk management: Collaboration with the 1st line sector SRMs to identify, assess and mitigate security risks, overseeing and reporting via the China Virtual Security Team (VST). Identify improvement opportunities together with the 1st line sector SRMs’ and the 2nd line team in terms of processes and activities. The CSL provides necessary support for improvements and will act in a pivotal role to bring (security) teams together where needed Incident response: overseeing the development of country specific response plans, assuring the timely and thorough handling of security indents under coordination of the central Security Operations Centre Compliance oversight: ensuring adherence to centrally determined or country specific laws and regulations related to information security. Team leadership & capability building: act on behalf of the CISO of ASML and work closely together with the 1st line country SRM’s to define and execute a joined security roadmap for China. Assure the capabilities as required by the central Second Line Security, Intelligence Fusion Centre and Security Operations Center teams are developed and maintained, as well as organizing Security activities related to risk culture and awareness initiatives. Will drive the preparation of a uniform reporting out to the China Country Management Team and align with the CISO and the VST team the agenda for these meetings. Stakeholder engagement: Providing regular updates, in alignment with the local first line sector Security Risk Managers of the VST, to senior management in China on the status of information security in China and the central information security program. Considering the given governance, this will always be in alignment with the respective 1st line SRM. Providing the general security training to all China staff to improve their awareness Some travel will be required to other ASML offices in China, and abroad (+/- 15%) KEY WORKING RELATIONSHIPS External: Security Vendors, Customers, Suppliers, (always in alignment with local account management and procurement teams, Industry Peers and Forums) Internal: ASML China IT, local ASML Sector Security Functions, RBA&S, Legal, Sectors
Serve as the key business partner working directly with service business partners and internal stakeholders (primarily infrastructure, physical security and operations teams). Interact with engineers, technicians, project managers, and Sr. Leaders to develop your programs. Drive process change and improvement across multiple business and program teams. Report ad hoc, weekly, and monthly program and operating metrics. Run meetings, create and maintain timelines, and keep large, diverse groups informed of progress and obstacles. Manage security system integration vendor contracts to deliver projects. Communicate the status of programs with customers, stakeholders and conduct program reviews. A day in the life You will be involved in the security design process across many AWS sites. Preparing a build of materials to secure funding for your projects. You will plan in advance to meet critical milestones that if missed will impact other functions of the wider project. You will execute and monitor the risks of your project closely as you work towards the handover to the operations teams. Keeping accurate records are all part of the role and form the final phase of the project.