Apply Edge Start your job search

Director of Information Security

BizLink Group · Zhonghe District, New Taipei City, Taiwan

Apply & track with Apply Edge

Job SummaryAs the Director of Information Security at BizLink, you will own and lead the global Governance, Risk, and Compliance (GRC) function for information security and BizLink’s Information Security Management System (ISMS). In this role, you will serve as the critical bridge between our business units and technical execution teams. You will ensure that business objectives and external compliance requirements are met, establish overarching security policies, and guarantee that technical standards align with these policies. Additionally, you will oversee enterprise ICT resilience, cyber crisis management, and global security culture.Key ResponsibilitiesStrategic GRC Leadership: Establish and drive the global Information Security GRC strategy. Form the bridge between business stakeholders and technical teams to ensure security aligns with business goals.Policy & Governance: Maintain and continuously improve the overarching Information Security Policy framework. Ensure that technical standards proposed by IT/Security Engineering align with corporate policy.Risk Management: Oversee comprehensive risk assessment programs across the business. Identify, track, and ensure the mitigation of risks across both business and technical landscapes and report relevant risks to top management.ICT Resilience & Cyber Crisis Readiness: Oversee the strategic planning for ICT resilience and own the global cyber crisis management framework, ensuring organizational readiness for major cyber events.Internal Assurance: Ensure that technical standards are practically implemented into compliant procedures by the operational teams, maintaining oversight of global regulatory adherence.Third-Party Risk: Oversee vendor risk management and external security posture monitoring, utilizing platforms like SecurityScorecard.Security Culture: Design and direct the global security awareness and culture program to ensure security is embedded in the organization's DNA.Team Leadership: Lead and mentor a distributed team of regional Information Security Managers (e.g., APAC, EU/NA) and continuity experts.Qualifications & RequirementsExperience: 8+ years in Information Security, with a strong, dedicated focus on GRC, IT audit, or enterprise risk management. Proven leadership experience.Skills: Exceptional ability to act as a translator between highly technical teams and business/executive leadership. Deep expertise in policy creation, cyber crisis management, and regulatory frameworks (ISO 27001, SOC 2, etc.).Mindset: Strategic thinker with a focus on governance and risk, rather than hands-on technical implementation.Certifications: Active industry certifications such as CISSP, CISM, or CRISC are highly preferred.