Cyber Security Manager (China & Asia Region) & Data Protection Officer (China)
- Full-time
- Contract Type: Permanent
Company Description
The present and future of Audemars Piguet are built on the invaluable contributions of all our talents. Inspired by the wealth of our past, we are excited about the endless possibilities that our future holds. Together, we are resolutely forward-thinking and strive for excellence in all areas of our business.
If this journey inspires you, come chart your own path within our family and let’s continue creating the extraordinary. Together, let's write the next chapter of your career!
Job Description
Reporting Line
- Hierarchical reporting: Country General Manager
- Functional / dotted line: Group CISO & Group Data Protection Officer (GDPO)
Role Purpose
This role combines local cyber security leadership and formal Data Protection Officer (DPO) responsibilities under Chinese data protection laws.
The role holder is the single accountable individual in China for:
- Information Security governance and operations (local CISO role), and
- Personal Information Protection compliance under the Personal Information Protection Law (PIPL), Data Security Law (DSL) and Cybersecurity Law (CSL).
The position acts as the officially designated and, where applicable, registered China DPO with the Cyberspace Administration of China (CAC) and ensures alignment with Group policies and standards across the Asia region.
Key Responsibilities
- Cyber Security & Information Security (Local CISO)
- Coordinate, deploy and enforce Group cyber security policies, standards and controls in China and, where relevant, across the Asia region.
- Ensure continuous alignment with PRC cybersecurity laws, regulatory requirements and Group security frameworks.
- Identify gaps or control deficiencies, define remediation plans and monitor their execution.
- Conduct local cyber risk assessments covering IT systems, OT environments and third parties.
- Support and coordinate the response to local cybersecurity incidents with the global SOC; participate in crisis management committees for major global or local incidents.
- Act as the primary local point of contact for internal and external cybersecurity audits and ensure effective follow-up of audit recommendations.
- Define, implement and maintain local cyber security governance, roles and escalation mechanisms.
- Provide guidance and support to local business and service units on cybersecurity matters.
- Deliver cybersecurity awareness and training programs adapted to the China threat landscape.
- Maintain regular interactions with local cyber security, IT and supervisory authorities.
- Maintain and continuously improve cyber defense capabilities through operational monitoring, incident management and lessons learned.
- Data Protection Officer (China – PIPL)
1. Governance & Compliance
- Ensure compliance with PIPL, DSL, CSL and their implementing regulations.
- Define and maintain the local Personal Information Protection governance framework.
- Advise management on data protection risks, including large-scale processing and sensitive personal information.
- Ensure privacy by design and by default across local projects, systems and business processes.
2. DPO Registration & Regulatory Interface
- Act as the registered China DPO with the CAC online portal, where statutory thresholds are met.
- Ensure the accuracy and timely update of DPO filing and regulatory information.
- Serve as the formal contact point with the CAC and other local data protection authorities.
- Coordinate and respond to regulatory inquiries, inspections and mandated audits.
3. Data Protection Risk Management & Audits
- Oversee and conduct Personal Information Protection Compliance Audits (regular and regulator-mandated).
- Coordinate internal and external audit activities in line with CAC Audit Measures.
- Track remediation plans and ensure timely closure of findings.
4. Data Subject Rights & Incident Handling
- Oversee the handling of data subject rights requests under PIPL.
- Participate in personal data breach assessment, notification and remediation.
- Coordinate personal data breach responses with Cyber Security, Legal, HR and HQ teams.
- Cross-Functional & Group Coordination
- Act as the single local authority bridging Cyber Security, Privacy, IT and Business functions.
- Coordinate with Group CISO and Group DPO to ensure consistency, escalation and alignment.
- Support local and regional business transformation initiatives while ensuring regulatory compliance.
- Contribute to Group-level cyber security and privacy programs from a China/Asia perspective.
Qualifications
- Education: Bachelor’s degree in Information Technology, Cyber Security, Law, Privacy or a related field. Advanced degree is a strong plus.
- Experience
- Minimum 7–10 years of experience in cyber security, information security, risk or compliance roles.
- Proven experience in data protection and privacy compliance in China.
- Hands-on exposure to regulatory interactions, inspections and audits with Chinese authorities.
- Experience operating in a regional or multinational environment is an advantage.
- Regulatory & Technical Expertise: Strong working knowledge of:
- Personal Information Protection Law (PIPL)
- Data Security Law (DSL)
- Cybersecurity Law (CSL)
- CAC compliance audit and DPO registration requirements
Strong technical understanding of cybersecurity controls, incident management and risk assessment.
- Skills & Attributes
- Excellent communication and stakeholder management skills.
- Ability to operate independently while working effectively in a matrixed, global organization.
- Strong analytical and problem‑solving capabilities.
- Proven leadership in driving security and compliance initiatives.
- High level of integrity, authority and independence to challenge business decisions where required.
- Strong cultural awareness and ability to operate effectively in a Chinese and international context.
- Ability to adapt to a dynamic and fast‑paced regulatory and business environment.
- Language & Location Requirements
- Chinese (Mandarin): fluent – written and spoken (mandatory).
- English: fluent (mandatory).
- Role must be physically based in Mainland China.
- Certifications (Highly Desirable)
- CISSP, CISM, ISO 27001 Lead Implementer / Lead Auditor.
- Privacy certifications (CIPP/E, CIPP/A or equivalent).
Additional Information
Audemars Piguet offers a competitive and comprehensive compensation and benefits package.
Audemars Piguet is an equal opportunity and affirmative action employer. Audemars Piguet hires without regard to age, sex, sexual orientation, gender identity, genetic characteristics, race, color, creed, religion, ethnicity, national origin, alienage, citizenship, disability, marital status, military status, pregnancy, or any other legally-recognized protected basis prohibited by applicable law.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply