- Location
- Shanghai, Shanghai, China
- Type
- Full-time
- Seniority
- Lead
- Experience
- 4+ years
- Closing date
- Today
- Source
- Workday
Description
At ABB, we help industries outrun - leaner and cleaner. Here, progress is an expectation - for you, your team, and the world. As a global market leader, we’ll give you what you need to make it happen. It won’t always be easy, growing takes grit. But at ABB, you’ll never run alone. Run what runs the world.
This role sits within ABB's Robotics business, a leading global robotics company. We're entering an exciting new chapter as we’ve announced the plan for SoftBank Group to acquire ABB Robotics. SoftBank is a globally recognized technology group and investor/operator focused on AI, robotics, and next-generation computing. By joining us now, you’ll be part of a pioneering team shaping the future of robotics—working alongside world-class experts in a fast-moving, innovation-driven environment.
This Position reports to:
IS Manager
Your Role:
The Regional Information Security Lead is the single accountable InfoSec representative in the region, responsible for executing the global security program locally, embedding security into regional IT and business operations, and acting as the first escalation point for security risks and incidents.
The role bridges central InfoSec strategy and regional execution, ensuring global standards are applied pragmatically while respecting local constraints.
Key responsibilities:
Regional Security Governance & Risk Ownership
- Act as the regional owner of information security execution
- Maintain regional risk register inputs, exceptions, and remediation plans
- Ensure alignment with global ISMS, policies, and standards, within the given scope
- Ensure regional compliance with security and compliance requirements defined by central InfoSec, within the given scope
- Ensure compliance with local security and compliance regulations
- Represent InfoSec in regional governance forums and project reviews
- Identify and escalate regional IT and security risks to central
Security Enablement & Technical Execution (Hands-on)
- Support and coordinate implementation of security controls across:
- Endpoints / Digital Workplace (with central Workplace & outsourcer)
- Local infrastructure and cloud workloads
- Network security controls (segmentation, NAC, firewall coordination)
- Application owned/managed by Robotics, within the region
- Provide regional L2/L3 security support for Incidents and compliance related issues
- Support rollout of central security platforms
Incident & Crisis Coordination (Regional)
- Act as the regional incident coordinator for security events
- Ensure local containment actions are executed quickly
- Ensure evidence collection in line with the global guidelines, where needed
- Coordinate regional stakeholders (IT, workplace, facilities, business)
- Interface with central SecOps / IR lead for investigation and response
- Drive post-incident remediation and lessons learned locally
Compliance, Audit & Supplier Security (Regional Liaison)
- Coordinate regional audit evidence collection, site assessments, and remediation actions
- Track remediation of audit findings and compliance gaps
- Support regional third-party / supplier / customer security assessments
- Ensure exceptions are time-bound and reviewed
- Assist on Cyber Security assessments for NIS 2 relevant legal entities within the region (and equivalent in non-EU countries)
Business & IT Security Partnering
- Act as the trusted security advisor to regional business and IT leads
- Support regional projects and changes with security input
- Promote secure working practices for employees and contractors
- Drive awareness of secure collaboration and data handling
Key Requirements:
- 4–7 years of experience in cybersecurity
- Knowledge of local regulations (e.g. China Cyber Security Law, NIS 2) for the region in scope is mandatory
- Knowledge of ISO 27001, NIST CSF, CIS Controls, MITRE ATT&CK, OWASP, TISAX, and SOX
- Familiarity with security technologies such as firewalls, WAF, SIEM, IAM, DLP, endpoint protection, and cloud security
- Relevant certifications: CISSP, CISM, cloud security, ITIL Foundation
We value people from different backgrounds. Could this be your story? Apply today or visit www.abb.com to read more about us and learn about the impact of our solutions across the globe.