Apply now »

Business Information Security Officer

Location: 

Pudong New District, SH, CN, 200120

Req ID:  86113
Facility:  Shanghai-484
Department:  Business Systems Security, AP
Division:  Innovation

Business Information Security Officer

Basic Function

The BISO will provide tactical direction to the regional and local sites. This role is a hands-on role that will ensure the subject matter expertise, and processes for the effective execution of global cybersecurity program, support the computing systems of site’s business and process control systems to coordinate changes and provide security and to ensure optimum integrity, confidentiality, reliability, and availability.  The role acts as the main local point of contact with the business and manufacturing in supporting the center led business systems security in the APAC region.  This role will be a security evangelist and drive company-wide focus to prevent, detect, and remediate cyber security threats.

Roles & Responsibilities

•    Oversee the operation of regional and local preventative systems and business / manufacturing computing systems (firewall, versions, patches, protection, certificate management, etc.)
•    Ensure that all regional sites’ networks and systems comply with corporate standards and communicate threats appropriately
•    Coordinate IT and manufacturing changes, etc. with site management
•    Participate in Level 2 and 3 monitoring, support, and SVA (site vulnerability assessments)
•    Assist in Operational Excellence assessment support and facilitate forensics investigations
•    Support project design and implementation
•    Ensure effective regional security awareness program implementation
•    Effectively facilitate center-led (located on-site or regional) support model to ensure the accountability of operational security (OT) for site’s manufacturing computing equipment
•    Assist in setting technical direction and strategy for ICS systems architecture and security 
•    Support the management, planning and execution of budget activities for OT related security systems
•    Improve overall cyber resilience to the next level of maturity and effectiveness
•    Regularly analyze LyondellBasell’s intrusion resistance and lead efforts to improve it through automation, integration, and aggregation.
•    Provide information protection expertise to IT operational teams to ensure OT systems are properly protected and monitored by design.
•    Evangelize security within LyondellBasell and drive changes needed to response to emerging threats
•    Profile new and emerging threats to the IT and OT landscape
•    Serve as a member to the incident response (IR) team, providing mentoring to other team members as needed, while performing Level 2 and 3 support.
•    Contribute ideas to the future state technology roadmap ensuring effective investments are made to enable scale, quality, and maintenance and overall cost effectiveness.
•    Understand security vulnerability management and the process
•    Be able to conduct vulnerability assessments for the IT and OT infrastructure
•    Be able to support the manufacturing sites’ OT Disaster Recovery (DR) planning activities and conduct period review and support as needed

Min. Qualifications

Education
•    Bachelor’s degree in an appropriate field, or equivalent professional experience
Work Experience 
•    Minimum of five (5) years of experience in information security, information technology (IT), or operational technology (OT) 
•    Experience developing and refining risk based, defense-in-depth security architectures based on established frameworks such as NIST or ISO
•    Exceptional communication and advocacy skills, both verbal and written, with the ability to express complex and technical issues in clear and concise language
•    Ability to collaborate and communicate effectively with both business-oriented and technology-oriented personnel
•    Working knowledge of plant ICS systems (i.e. Modbus, OPC communications, Aspentech, PAS, Honeywell, DeltaV etc.)
•    Working knowledge of one or more of these technologies: Microsoft Windows, Active Directory, Azure Cloud, MS Power BI, domain architecture & management, group policies, network topology and components, antivirus, SQL server, and database management

Preferred Qualifications

•    Practical knowledge of different message distribution techniques to ensure end user’s understand and apply the behavioral changes necessary to reduce the ‘human factors’ risk
•    Detailed understanding of manufacturing and business systems 
•    Ability to work with minimal supervision with demonstrated mentoring skills
•    Ability to travel as required, up to 20%
•    Experience with security incident and event analytics and monitoring technology including regular maintenance and tuning, correlation rules, filters, lists, views, and reports
•    CISSP, CCNA, CISA or other security recognition desirable
•    Intercultural competence

Languages: English

Competencies

Build Partnerships
Deliver Results
Drive Innovation
Grow Capabilities
Promote Inclusion
Motivational/Cultural Fit
Technical Skills

Apply now »