招聘公告 · 职位检索 · 央国企/事业单位/名企

Deputy manager of Information Security

单位:中海壳牌类型:社招地点:惠州市更新:2026-09-24

岗位信息

招聘单位中海壳牌
工作地点惠州市
官方更新时间2026-09-22T17:07:34

职位描述

工作目的

• As the CSPC Information Security leader and the key deputy to the Chief Information Security Officer (CISO), responsible for establishing and continuously enhancing the information security governance framework, overseeing IT security, OT cybersecurity, data security, and information/content security management, and ensuring that information security strategies are aligned with the CSPC business objectives, digital transformation roadmap, and compliance requirements.

作为公司信息安全负责人及CISO核心副手,负责建立并持续优化信息安全治理体系,统筹IT安全、OT工业网络安全、数据安全及内容安全管理,确保信息安全战略与公司业务发展、数智化转型及合规要求保持一致

• Through effective security governance, risk management, security operations, and incident response mechanisms, safeguard business continuity, production reliability, information asset protection, and corporate reputation, while providing security assurance for smart factory initiatives and the convergence of IT and OT environments.

通过完善安全治理、风险控制、安全运营和应急管理机制,保障业务连续性、生产运行可靠性、信息资产安全及企业声誉,为智慧工厂建设和IT/OT融合发展提供安全保障

工作维度

1. Management Scope

• Development and governance of the CSPC information security strategy and security management framework.

• Management of IT security, OT industrial cybersecurity, data security, and information/content security.

• Enterprise-wide security risk management, compliance oversight, and business assurance.

• Security operations, incident response, business continuity, and disaster recovery management.

• Security governance for emerging technologies, including Artificial Intelligence (AI), Industrial Internet, and digital platforms.

• Security culture development and organizational capability building.

1. 管理范围

• 公司信息安全战略与治理体系建设

• IT、OT、数据及内容安全管理

• 企业级安全风险、合规监督与业务保障

• 安全运营、应急响应与灾难恢复

• 新兴技术(AI、工业互联网、数字化平台等)安全治理

• 安全文化培育与组织能力建设

2. Managed Environment

• Govern and oversee Information Technology (IT) security and cybersecurity for more than 100 IT applications system, networks, file-sharing platforms (e.g., T-Drive , One-drive, Share-point, and related IT infrastructure and digital assets.

• Govern and oversee cybersecurity for the CSPC Operational Technology (OT) environment, including 24 process units in 2 plants and more than 34 process units in 3 plants in the future, covering Industrial Control Systems (ICS) such as DCS, PIMS, PLC, SCADA, and related industrial networks.

2.管理对象

• 100+IT应用系统、T盘/云盘等信息技术安全和网络安全

• 现有两个工厂24套装置,未来三个工厂34+套装置的工业控制系统(DCS/PIMS/PLC/SCADA等)网络安全

3. Key Stakeholders

• Chief Information Security Officer (CISO)

• Digitalization Department

• Engineering Services Department

• Administration & Security Department

• Business Functions

• Production Department OT security-related technical teams (e.g., Equipment Management, Rotating Equipment, Electrical, Instrumentation, and other engineering disciplines)

• Internal Audit Department

• Legal and Compliance Department

• Human Resources Department

• Shareholders and External Audit Organizations

.3. 主要协作对象

•首席信息安全官、数智化部、工程服务部、后勤安保部、各业务职能部门、生产部OT安全相关专业团队(如设备管理、动设备、电气、仪表等专业)、内部审计部门法务与合规部门、人力资源部、股东及外部审计机构.

工作职责

1. Information Security Strategy & Governance

• Develop and drive the CSPC information security strategy, roadmap, and annual security plans.

• Establish and maintain an integrated security governance framework covering IT security, OT industrial cybersecurity, data security, and information/content security.

• Promote IT/OT converged security governance and ensure the effective implementation of security responsibilities across the organization.

1.信息安全战略与治理

• 制定并推动公司信息安全战略、发展路线图及年度计划

• 建立覆盖IT、OT、数据及内容安全的统一治理体系

• 推动IT/OT融合安全治理及安全责任落实

2. Risk & Compliance Management

• Establish and maintain the enterprise information security risk management framework, including risk identification, assessment, mitigation, and remediation programs.

• Drive compliance with applicable laws, regulations, industry standards, and shareholder requirements.

• Lead security audits, assessments, and compliance reviews to continually enhance security maturity and management effectiveness.

2.风险与合规管理

• 建立企业信息安全风险管理体系,组织风险识别、评估及整改

• 推进法律法规、行业标准及股东要求的合规落实

• 组织审计检查,持续提升安全成熟度和管理水平

3. Security Operations & Incident Management

• Establish and continuously improve the security operations framework and security monitoring capabilities.

• Lead Security Operations Center (SOC) development and enhance security incident management processes.

• Organize incident response and disaster recovery exercises for cyberattacks, data breaches, and industrial control system (ICS) security incidents.

3. 安全运营与应急管理

• 建立安全运营体系和安全监测能力

• 推动SOC建设及安全事件管理机制完善

• 组织网络攻击、数据泄露及工控系统安全事件应急响应和灾难恢复演练

4. Digital Transformation & Emerging Technology Security

• Provide security governance and advisory support for emerging technologies, including Industrial AI, Digital Twins, Industrial Internet, and cloud platforms.

• Embed security requirements throughout the entire lifecycle of digital transformation projects.

• Lead to drive the serial IT/OT security fostering projects from technical solution to implementation, to secure IT/OT system in a dynamic environment

4. 数智化与新技术安全保障

• 为工业AI、数字孪生、工业互联网、云平台等新技术应用提供安全治理支持。

• 将安全要求融入数字化项目全生命周期管理

• 推动IT/OT网络安全能力建设与持续优化

5. Information Security Culture & Capability Development

• Establish and promote an enterprise-wide information security culture program.

• Develop and implement information security awareness initiatives and professional capability enhancement programs.

• Provide security training, technical guidance, and capability-building support for IT, OT, and business teams.

5.培育信息安全文化与组织能力

• 建设覆盖全员的信息安全文化体系

• 建立信息安全意识培训、专业能力提升

• 为IT、OT及业务团队提供专业培训和技术赋能

任职要求

1.Educational background:

• Bachelor's degree or above in Computer Science, Information Security, Network Engineering, Software Engineering, Automation, or a related field.

• A master’s degree or higher is preferred.

2. Professional Background:

• Minimum 15 years of professional experience in Information Security, Cybersecurity, OT Security, IT Infrastructure Security, or related disciplines.

• Minimum 10 years of Information Security management experience

• Experience in both IT and OT environments is required.

• Proven experience in managing cybersecurity risk assessments, compliance programs, audits, and major security incident response activities.

• Experience in petrochemical, oil & gas, energy, manufacturing, or other critical infrastructure industries is highly preferred

3. Professional Certifications and Language Proficiency:

• CISSP / CISM/ GICSP is preferred

• Fluent in spoken and written English and Mandarin.

4. PC skills:

• Proficient in PC skills: Word/Excel/PowerPoint.

1.教育背景

• 本科及以上学历,计算机、信息安全、网络工程、软件工程、自动化等相关专业

• 硕士及以上学历优先

2.工作经验

• 15年以上信息安全相关经验。

• 10年以上信息安全管理经验。

• 具备IT与OT双领域安全管理经验。

• 具备大型企业安全治理、风险管理、合规审计及安全事件处置经验。

• 石油化工、能源、制造业等行业经验优先

3.资格认证及语言

• 持有CISSP、CISM、GICSP等认证优先

• 具备良好的中英文书面及口头沟通能力

• 具备流利的中英文书面和口头沟通能力

4.计算机技能

• 熟练使用Microsoft Office办公软件,包括Word、Excel、PowerPoint等

前往官方投递

提示:投递请认准招聘单位官方招聘官网,谨防中介收费。