岗位描述
职位描述
- Support global GRC initiatives and provide operational support to the Head of IT GRC across Trip.Biz.
- Coordinate ISO 27001, SOC 2, PCI DSS or similar certification and audit activities, including evidence collection and remediation tracking.
- Support client security assessments, RFP questionnaires, and due-diligence reviews across global markets.
- Maintain risk registers, track remediation actions, and support periodic risk assessments across systems and projects.
- Coordinate internal and external audits and support regulatory or contractual compliance documentation.
- Work with product, R&D, legal, and security teams to validate controls and ensure compliance alignment.
- Support third-party and partner security reviews where required.
- Prepare reports and materials for management and stakeholders on compliance and risk posture.
- Support global initiatives and cross-regional coordination, including travel where required.
任职资格
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field.
- 3+ years of experience in IT governance, risk and compliance, information security, or technology risk roles.
- Experience supporting audits, certifications, or client security assessments.
- Familiarity with frameworks such as ISO 27001, SOC 2, PCI DSS, or similar.
- Experience working in multinational or global environments with cross-functional teams.
- Experience in technology, internet, SaaS, or platform-based organisations is advantageous.
- Exposure to the travel or online travel industry would be beneficial but not required.
- Strong bilingual proficiency in English and Chinese (written and spoken).
- Ability to travel internationally as business needs arise.