ABB logo

Information Security and GRC Leader

ABB

On-site
Shanghai, China
Full-time
Mid Level
Senior
4+ yrs
Salary not listedPosted 43m ago

Real job — pulled straight from ABB’s careers page · Verified September 9, 2026 · No reposts.

Job description

ABB is hiring a Information Security and GRC Leader — a full-time, based in Shanghai, China role. Apply directly on ABB's careers page below.

Regional InfoSec and GRC Leader

Location: Shanghai, Shanghai, China

Category: Information Systems

Employment Type: Full Time

At ABB, we help industries outrun - leaner and cleaner. Here, progress is an expectation - for you, your team, and the world. As a global market leader, we’ll give you what you need to make it happen. It won’t always be easy, growing takes grit. But at ABB, you’ll never run alone. Run what runs the world.

This role sits within ABB's Robotics business, a leading global robotics company. We're entering an exciting new chapter as we’ve announced the plan for SoftBank Group to acquire ABB Robotics. SoftBank is a globally recognized technology group and investor/operator focused on AI, robotics, and next-generation computing. By joining us now, you’ll be part of a pioneering team shaping the future of robotics—working alongside world-class experts in a fast-moving, innovation-driven environment.

This Position reports to:

IS Manager


 

Your Role:

The Regional Information Security Lead is the single accountable InfoSec representative in the region, responsible for executing the global security program locally, embedding security into regional IT and business operations, and acting as the first escalation point for security risks and incidents.

The role bridges central InfoSec strategy and regional execution, ensuring global standards are applied pragmatically while respecting local constraints.

Key responsibilities:

Regional Security Governance & Risk Ownership

  • Act as the regional owner of information security execution
  • Maintain regional risk register inputs, exceptions, and remediation plans
  • Ensure alignment with global ISMS, policies, and standards, within the given scope
  • Ensure regional compliance with security and compliance requirements defined by central InfoSec, within the given scope
  • Ensure compliance with local security and compliance regulations
  • Represent InfoSec in regional governance forums and project reviews
  • Identify and escalate regional IT and security risks to central

Security Enablement & Technical Execution (Hands-on)

  • Support and coordinate implementation of security controls across:
    • Endpoints / Digital Workplace (with central Workplace & outsourcer)
    • Local infrastructure and cloud workloads
    • Network security controls (segmentation, NAC, firewall coordination)
    • Application owned/managed by Robotics, within the region
  • Provide regional L2/L3 security support for Incidents and compliance related issues
  • Support rollout of central security platforms

Incident & Crisis Coordination (Regional)

  • Act as the regional incident coordinator for security events
  • Ensure local containment actions are executed quickly
  • Ensure evidence collection in line with the global guidelines, where needed
  • Coordinate regional stakeholders (IT, workplace, facilities, business)
  • Interface with central SecOps / IR lead for investigation and response
  • Drive post-incident remediation and lessons learned locally

Compliance, Audit & Supplier Security (Regional Liaison)

  • Coordinate regional audit evidence collection, site assessments, and remediation actions
  • Track remediation of audit findings and compliance gaps
  • Support regional third-party / supplier / customer security assessments
  • Ensure exceptions are time-bound and reviewed
  • Assist on Cyber Security assessments for NIS 2 relevant legal entities within the region (and equivalent in non-EU countries)

Business & IT Security Partnering

  • Act as the trusted security advisor to regional business and IT leads
  • Support regional projects and changes with security input
  • Promote secure working practices for employees and contractors
  • Drive awareness of secure collaboration and data handling

Key Requirements:

  • 4–7 years of experience in cybersecurity
  • Knowledge of local regulations (e.g. China Cyber Security Law, NIS 2) for the region in scope is mandatory
  • Knowledge of ISO 27001, NIST CSF, CIS Controls, MITRE ATT&CK, OWASP, TISAX, and SOX
  • Familiarity with security technologies such as firewalls, WAF, SIEM, IAM, DLP, endpoint protection, and cloud security
  • Relevant certifications: CISSP, CISM, cloud security, ITIL Foundation

We value people from different backgrounds. Could this be your story? Apply today or visit www.abb.com to read more about us and learn about the impact of our solutions across the globe.

Get Information Security and GRC Leader jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Nir-Yu logo

Information Security Engineer

Remote · Argentina +18
✓ From careers page· 17m ago
OCBC Bank logo

Red Team Analyst

Singapore
✓ From careers page· 29m ago
ABB logo

ABB

New

Global Project Manager, Process Automation

Remote · Spain-eligible
✓ From careers page· 44m ago
ABB logo

ABB

New

Project Engineer, Process Power Manager

Bangalore, Karnātaka
✓ From careers page· 48m ago

Frequently asked questions

What skills are required for Information Security and GRC Leader at ABB?

The required skills for Information Security and GRC Leader at ABB include: Cybersecurity, ISO 27001, SIEM, IAM, CISSP, CISM.

What is the seniority level for Information Security and GRC Leader at ABB?

Information Security and GRC Leader at ABB is a Mid Level / Senior level position.

How do I apply for Information Security and GRC Leader at ABB?

You can view the full description and apply for Information Security and GRC Leader at ABB on EchoJobs: https://echojobs.io/job/abb-regional-infosec-and-grc-leader-e99fu.