IT GRC Specialist
岗位信息
| 招聘单位 | 携程集团 |
|---|---|
| 部门/事业群 | Corporate Travel |
| 工作地点 | 上海 |
| 官方更新时间 | 2026-07-10 |
任职要求
职位描述
<p>- Support global GRC initiatives and provide operational support to the Head of IT GRC across Trip.Biz.</p><p>- Coordinate ISO 27001, SOC 2, PCI DSS or similar certification and audit activities, including evidence collection and remediation tracking.</p><p>- Support client security assessments, RFP questionnaires, and due-diligence reviews across global markets.</p><p>- Maintain risk registers, track remediation actions, and support periodic risk assessments across systems and projects.</p><p>- Coordinate internal and external audits and support regulatory or contractual compliance documentation.</p><p>- Work with product, R&D, legal, and security teams to validate controls and ensure compliance alignment.</p><p>- Support third-party and partner security reviews where required.</p><p>- Prepare reports and materials for management and stakeholders on compliance and risk posture.</p><p>- Support global initiatives and cross-regional coordination, including travel where required.</p><p></p>
任职资格
<p>- Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field.</p><p>- 3+ years of experience in IT governance, risk and compliance, information security, or technology risk roles.</p><p>- Experience supporting audits, certifications, or client security assessments.</p><p>- Familiarity with frameworks such as ISO 27001, SOC 2, PCI DSS, or similar.</p><p>- Experience working in multinational or global environments with cross-functional teams.</p><p>- Experience in technology, internet, SaaS, or platform-based organisations is advantageous.</p><p>- Exposure to the travel or online travel industry would be beneficial but not required.</p><p>- Strong bilingual proficiency in English and Chinese (written and spoken).</p><p>- Ability to travel internationally as business needs arise.</p><p></p>
提示:投递请认准招聘单位官方招聘官网,谨防中介收费。