岗位描述
Job Description:
配合全球风险监控团队,建立并维护高效的供应商风险沟通与协作机制,对在库供应商进行持续性风险审查,确保合同合规性及信息安全标准的落实,并通过清单化管理推动风险闭环处置。
Collaborate with the global risk monitoring team to establish and maintain efficient communication and collaboration mechanisms for supplier risk oversight. Conduct ongoing risk reviews of active suppliers, ensure contractual compliance and information security standard adherence, and drive closed-loop risk resolution through structured list management.
Key Responsibilities:
1. 沟通机制建立与标准对齐 / Communication Mechanism Setup & Standard Alignment
a) 与全球监控团队建立定期沟通机制(如周会/月报/联合评审),确保信息同步与协作顺畅 / Establish regular communication mechanisms with the global monitoring team (e.g., weekly meetings/monthly reports/joint reviews) to ensure information synchronization and smooth collaboration
b) 对齐全球供应商风险管理的统一标准、评估框架及分级策略,确保本地执行与集团方针一致 / Align with global unified standards, assessment frameworks, and tiering strategies for supplier risk management, ensuring local execution is consistent with corporate guidelines
2. 在库供应商定期及事件驱动审查 / Regular & Event-Driven Review of Active Suppliers
a) 按既定周期(如季度/半年度)对在库供应商进行系统性风险再评估 / Conduct systematic risk reassessments of active suppliers at defined intervals (e.g., quarterly/semi-annually)
b) 当供应商发生重大变更(如股权变动、数据泄露、安全事件、监管处罚等)时,立即启动专项审查 / Initiate ad-hoc reviews immediately upon major supplier changes (e.g., equity changes, data breaches, security incidents, regulatory penalties, etc.)
3. 合同状态核实与到期预警机制建立 / Contract Status Verification & Expiry Alert Mechanism
a) 核实在库供应商合同的当前状态(有效期、续约条款、终止条件等),确保合同信息准确无误 / Verify the current status of active supplier contracts (validity period, renewal terms, termination clauses, etc.) to ensure accuracy of contract information
b) 建立合同到期预警机制,提前通知相关业务及采购团队,避免合同失效或服务中断风险 / Establish a contract expiry alert mechanism to proactively notify relevant business and procurement teams, preventing contract lapse or service disruption risks
4. 第三方信息安全证书及安全报告审核 / Third-Party Information Security Certificates & Reports Review
a) 审核供应商提供的信息安全证书(如ISO 27001、SOC 2、等保等)的真实性、有效性与覆盖范围 / Review the authenticity, validity, and scope of information security certificates provided by suppliers (e.g., ISO 27001, SOC 2, MLPS, etc.)
b) 审阅供应商定期提交的安全评估报告、渗透测试结果及漏洞修复承诺,判断其安全态势是否达标 / Evaluate periodic security assessment reports, penetration test results, and vulnerability remediation commitments to determine whether the supplier’s security posture meets requirements
5. 供应商风险清单维护与未解决风险追踪 / Supplier Risk Register Maintenance & Open Risk Tracking
a) 维护并实时更新供应商风险清单(风险登记册),记录风险等级、影响范围、责任方及处置状态 / Maintain and continuously update the supplier risk register, documenting risk levels, impact scope, responsible parties, and disposition status
b) 对未解决风险设定明确整改时限,定期追踪整改进展,直至风险关闭或接受,并向上级汇报风险趋势 / Set clear remediation deadlines for unresolved risks, regularly track progress until risk closure or acceptance, and report risk trends to management
Skills and Attributes for Success
1. 本科及以上学历,供应链管理、信息安全、风险管理或相关专业优先 / Bachelor’s degree or above in Supply Chain Management, Information Security, Risk Management, or related fields preferred
2. 2年以上供应商管理、风险管理或信息安全管理相关经验 / 2+ years of experience in supplier management, risk management, or information security management
3. 熟悉ISO 27001、NIST、SOC 2等信息安全框架及评估标准 / Familiar with information security frameworks and assessment standards such as ISO 27001, NIST, and SOC 2
4. 具备良好的数据分析能力及合同审阅基础能力 / Proficient in data analysis and possess foundational contract review capabilities
5. 英语可作为工作语言(书面及会议沟通) / Fluent in English as a working language (both written and meeting communication)
6. 细致严谨,具备跨团队沟通与协调能力 / Detail-oriented, rigorous, with strong cross-team communication and coordination skills