Skip to content
← Back to job listings

(Senior) Analyst, GTS GRC, APAC

beigene · 大连市, 辽宁, 中国

Imported listingfull-time6 days ago

About The Role

General Description: BeOne is seeking an experienced GTS GRC Program (Senior) Analyst to join our growing information security function, who has GRC responsibilities from a technology and security perspective across the organization. Working closely with the APAC GTS GRC Senior Manager, this position will be responsible for conducting and enhancing the GRC effort to raise the overall security and compliance posture for BeiGene. This position will also be directly responsible for implementing, maintaining and improving policies, procedures and internal controls to assure compliance with applicable regulatory and legal requirements as well as best practices. The GRC (senior) analyst will conduct risk analysis for internal and external third-party risk assessments based on controls and implementing industry best practice processes utilized across the organization. The role will work across multiple frameworks and regulatory standards including, but not limited to SOX, GxP, ISO, NIST CSF, CSL/DSL/PIPL, etc. This position will liaise with business groups including but not limited to Finance, Legal, Compliance, Quality and other stakeholders to implement new solutions and processes as well as document and remediate outstanding issues. This role will also have responsibility for the implementation of a GRC system that will be used to further the automation of the program. Essential Functions of the job : Responsible for supporting and conducting IT audit and compliance activities, including IT General Controls (ITGC), application controls, IT SOX compliance, control testing, remediation management, and internal/external audit engagements. Responsible for conducting and supporting Third-Party Risk Assessments (TPRA), including security, privacy, compliance, technology, and operational risk due diligence activities throughout the third-party lifecycle. Responsible for conducting IT, cybersecurity, and third-party risk assessments; maintaining the enterprise risk register; identifying control gaps; evaluating business impact; and tracking risk remediation activities across systems, processes, technologies, and service providers. Responsible for implementing, monitoring, and enhancing controls within the GRC program, tracking remediation efforts and reporting control deficiencies across IT and cybersecurity domains. Provide management-level reporting, risk dashboards, and updates on control maturity and program effectiveness. Assess, report on, and continuously improve the organization's compliance posture against internal policies, standards, and regulatory requirements, including but not limited to NIST CSF, ISO 27001, GDPR, SOX, GxP, CSL, MLPS 2.0, and other applicable frameworks. Maintain, improve, and enforce BeiGene information security policies, standards, procedures, and security exception management processes. Effectively engage with IT, business stakeholders, Legal, Compliance, Quality, vendors, and other functions to understand current and emerging risks, evaluate environmental changes, and develop practical mitigation and remediation plans. Support the implementation and continuous improvement of GRC platforms and processes to enhance governance, risk visibility, compliance monitoring, and program automation. Assist and support the Senior Manager of GRC by providing detailed business and technical coordination across strategic initiatives, risk programs, compliance activities, and key cybersecurity projects. Qualifications: 3+ years of experience in IT Governance, Risk, and Compliance (GRC), IT Audit, IT Risk Management, Information Security Compliance, or related fields. Experience supporting and managing SOX compliance activities, including IT General Controls (ITGC), application controls, control testing, remediation tracking, and internal/external audit support. Experience conducting and supporting Third-Party Risk Assessments (TPRA), including security, privacy, compliance, technology, and operational risk reviews throughout the third-party lifecycle. Experience conducting IT and cybersecurity risk assessments, maintaining risk registers, tracking remediation activities, and supporting enterprise risk management programs. Experience implementing and operating GRC platforms and related governance, risk, and compliance processes. Experience developing, maintaining, and improving information security policies, standards, procedures, and supporting documentation. Strong knowledge of information security, risk management, and compliance frameworks, including but not limited to NIST CSF, ISO 27001, SOX, GxP, GDPR, CSL, and MLPS 2.0. Working knowledge of key information security domains, including cloud security, identity and access management, encryption, network security, vulnerability management, disaster recovery, security operations, and security architecture. Experience working in a global and matrixed enterprise environment. Strong communication, stakeholder management, analytical, and documentation skills. Fluent in both written and spoken English. Preferred: Strong accountability, ownership, and self-motivation, with the ability to independently drive initiatives and deliver results. Strong communication, stakeholder management, analytical, and documentation skills. Experience with SOX compliance, SAP IT controls or other ERP control environments. Experience supporting regulatory and compliance initiatives involving CSL, DSL, PIPL, or other APAC cybersecurity and data protection regulations. Experience leveraging automation, data-driven approaches, or AI-enabled capabilities to improve cybersecurity and GRC processes. Experience working in a global and matrixed enterprise environment. Security certifications preferred: CISA, CISM, CISSP, CRISC. Competencies: Ethics - Treats people with respect; Inspires the trust of others; Works with integrity and ethically; Upholds organizational values. Planning/Organizing - Prioritizes and plans work activities; Uses time efficiently. Completes administrative tasks correctly and on time. Follows instructions and responds to management direction. Communication - Listens and gets clarification; Responds well to questions; Speaks clearly and persuasively in positive or negative situations. Writes clearly and informatively. Able to read and interpret written information. Teamwork - Balances team and individual responsibilities; Gives and welcomes feedback; Contributes to building a positive team spirit; Puts success of team above own interests; Supports everyone's efforts to succeed. Contributes to building a positive team spirit; Shares expertise with others. Adaptability – Able to adapt to changes in the work environment. Manages competing demands. Changes approach or method to best fit the situation. Able to deal with frequent change, delays, or unexpected events. Technical Skills - Assesses own strengths and development areas; Pursues training and opportunities for growth; Strives to continuously build knowledge and skills; Shares expertise with others. Dependability - Follows instructions, responds to management direction; Takes responsibility for own actions; Keeps commitments; Commits to long hours of work when necessary to reach goals; Completes tasks on time or notifies appropriate person with an alternate plan. Quality - Demonstrates accuracy and thoroughness; Looks for ways to improve and promote quality; Applies feedback to improve performance; Monitors own work to ensure quality. Analytical - Synthesizes complex or diverse information; Collects and researches data; Uses intuition and experience to complement data. Problem Solving - Identifies and resolves problems in a timely manner; Gathers and analyzes information skillfully. Project Management - Communicates changes and progress; Completes projects on time and budget. 百济神州全球胜任力 当我们通过以下十二项全球胜任力,展现出 "患者为先"、"无界协作"、"锐意创新 "和 "追求卓越 "的价值观时,我们就能帮助全世界更多患者获得更多负担得起的药品。 ●团队协作 ●提供并征求坦诚及可行的反馈 ●自我认知 ●兼容并蓄 ●积极主动 ●开拓精神 ●持续学习 ●拥抱变化 ●结果导向 ●分析性思维/数据分析 ●卓越财务 ●清晰沟通 BeOne Global Competencies When we exhibit our values of Patients First, Collaborative Spirit, Bold Ingenuity and Driving Excellence, through our twelve global competencies below, we help get more affordable medicines to more patients around the world. ●Fosters Teamwork ●Provides and Solicits Honest and Actionable Feedback ●Self-Awareness ●Acts Inclusively ●Demonstrates Initiative ●Entrepreneurial Mindset ●Continuous Learning ●Embraces Change ●Results-Oriented ●Analytical Thinking/Data Analysis ●Financial Excellence ●Communicates with Clarity 求职者隐私申明: 百济神州致力于尊重和保护您的个人信息权利,并承诺依据合法、正当、必要和诚信的原则处理您的个人信息(包括个人敏感信息 )。 由于百济神州在全球范围内开展业务,我们可能需要基于人力资源管理等合理业务目的而将您的个人信息发送和/或存储在位于您所在国家以外其他国家(例如:美国)的服务器和数据库中,详情参见百济神州《求职者隐私政策》(百济神州官网 - 隐私政策 - 求职者隐私政策)。 如您主动向我们提供您的简历信息或其他个人信息,则视为您已经充分理解并确认接受百济神州《求职者隐私政策》内容。如您对此有任何疑问的,请勿提交简历信息或其他个人信息。 BeOne is committed to respect and protect your personal information rights, and will process your personal information, including your sensitive personal information, based on the principles of legality, legitimacy, necessity, and integrity. Due to the reasonable business need for human resource management as a result of BeOne’s global operation, your personal information may be transferred and/ or stored in a server/database located in a third country (e.g., the United States) other than your own country. For further details, please refer to BeOne Job Applicant Privacy Policy (BeOne official website - Privacy Policy - Job Applicant Privacy Policy). If you voluntarily provide your resume or other personal information to us, it is deemed as you have thoroughly acknowledged and accepted BeOne Job Applicant Privacy Policy. If you have any concern, please DO NOT submit your resume or any other personal information.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing