Zuellig Pharma is a leading healthcare solutions company in Asia, and our purpose is to make healthcare more accessible to the communities we serve. We provide world-class distribution, digital, and commercial services to support the growing healthcare needs in this region.
The company was started a hundred years ago and has grown to become a multibillion-dollar business covering 17 markets with over 12,000 employees. Our people serve more than 200,000 medical facilities and work with over 450 clients, including the top 20 pharmaceutical companies in the world.
Purpose Of The Role
The Principal Engineer for Information & Data Privacy will lead the strategic design, implementation, and management of the enterprise-wide Information Security Management System (ISMS) based on the ISO 27001 framework. This role acts as the central subject matter expert, responsible for developing robust information security and data privacy policies, conducting comprehensive risk assessments, and ensuring compliance across all markets.
By driving security awareness, guiding audit activities, and providing expert consultation to all business units, this position is critical to safeguarding Zuellig Pharma's information assets and upholding our commitment to making healthcare accessible in a secure and trusted manner.
What You’ll Do
Leads the design, implementation, operation and maintenance of ISO 27001 Information Security Management System for ZP enterprise which includes the development of audit program related to ISMS for ZPAP ROHQ and cascaded to the Markets IT Heads/Managers in adapting the same.
Develop and maintain information security policy, standards, and procedures align with ISO 27000 Framework and other industry best practices standards such as NIST and others.
Perform and conducts risk assessment for ZPAP and provide guidance to ZP Market IT Heads/Managers or designated support ream in performing such risk assessment with data privacy and cybersecurity.
Assist the ZP Market IT Heads/Manager in performing internal audit activities preparation in relation to ISO 27001 ISMS activities
Act as an internal consulting resource on information security issues and data privacy protections for Zuellig Pharma enterprise.
Conduct information security risk assessments that includes data privacy and cybersecurity controls.
Identifies technology, process, or administrative controls to address an audit findings or non-conformities by applying the corrective and preventive controls
Perform review of IT security compliance documentations (policies, standards, and procedures) for ZP in a periodic basis and cascading to ZP Market IT Heads/Managers for consumption and roll out.
Review the compliance of ZP Markets, Business Units and Enabling Functions on data protection policies and controls.
Conducts Privacy Impact Assessment in coordination to internal stakeholders and business units and ensure that consent forms are up-to-date and development of data privacy program for ZP enterprise
Coordinate and be active in information security efforts within and across ZP business units, and cooperate with the IT, HR, legal, financial, and executive offices.
Provide periodic reporting on information security issues to IT management and from time to time report to the Information Technology Steering Committee
Formulate and maintain information security awareness and data privacy programs for the enterprise and cascade the same to Business Units for implementation and ensure to improve the mentioned security programs.
Liaises with various Markets HR teams, Business Units, Markets IT Heads/Managers for the implementation of security awareness compliance and data privacy programs and monitoring the KPIs.
Provide assistance to the concerned team regarding the Business Continuity and Disaster Recovery best practices with respect to the result of the risk assessment on ZP system.
Perform IT Security and Data Privacy due diligence activities for vendors and technology solutions to ensure that meets the cybersecurity controls of Zuellig Pharma
Assist the ZP Business Units, Markets, and Enabling Function team such as legal team in reviewing MSA, Scope of Work, and other related documentation associated to a contract.
Leads the preparation for any IT audit activities (initiated by internal or external) within ZP enterprise and helping various ZP Markets IT Head/Manager and teams with the preparations as well
Liaises with SAP GRC team of ZP for the access controls activities that needs collaboration with the cybersecurity team.
Helps the ZP enterprise cybersecurity and infrastructure teams to ensure technology controls are aligned with the current policies, standards, and procedures through technical audits
Perform the monitoring of KPI scores of ZP Market IT and report to ZPAP Management
Responsible in updating the Cybersecurity Audit Committee slides and ensures that the report is accurate based on the information gathered from the Markets IT Support
Assist the cybersecurity team in performing technical security audit activities for ZPAP and ZP Enterprise.
Must-Have
What will make you successful:
Bachelor's degree in MIS / Business / IT or a similar subject with strong exposure to information technology.
Preferably, with IT Security Certifications such as ISO-LA, CISA, and the like, preferably.
At least 5-8 years of professional experience in IT Security and Compliance
At least 3 years of professional experience in Data Privacy and Compliance
Experience in working in a multinational company
Experience in conducting Risk Assessment
Experience in performing IT Systems Audit, or ISO 27001 internal audit
Experience in policy & standard development and implementation align with ISO 27001 (e.g., performing internal audits align with the framework)
Experience in development a security and data privacy awareness education program for the organization
Advantage To Have
Strong knowledge on ISO 27001 ISMS and IT Security processes
Advanced knowledge of Data Privacy Protection practices
Advanced knowledge on NIST Cybersecurity publications
Knowledgeable in GRC for SAP Systems
Able to comprehend IT technology concepts and able to translate into a framework or process flow
Good communications and technical writing skills to support the function in developing security policies, standards and procedures and cascading to internal stake holders
Advanced know how in using the Microsoft Office Applications
Familiarity with MS Conditional Access, Intune MDM, TPRM Tools
Able to understand the logs and can conduct investigation and formulate a root cause analysis through a documentation
Able to represent the audit results to management with an ease and avoiding technicalities for better appreciation of the ZP Management
Ability to identify the work required and organize, facilitate and / or perform the work with only minimal guidance from senior management.
Excellent analytical skills
Able to work with very minimal supervision
What We Offer
We are committed to fostering an inclusive environment where our employees can learn, grow, and achieve shared success.
We champion diversity, equity, and inclusion, ensuring every individual feels valued, respected, and treated fairly.
As a leading multi-market healthcare solutions provider, we empower our employees to gain comprehensive knowledge and expertise in the dynamic healthcare industry across the region.
Enjoy the flexibility to effectively balance your work and personal life while taking charge of your career journey through our empowering growth opportunities.
Our Total Rewards program is designed to support your overall well-being in every aspect.
Pharmaceutical Manufacturing Medical Equipment Manufacturing And Transportation Logistics Supply Chain And Storage
What We Offer
About the Company
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Your application for Principal Engineer Information And Data Privacy
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!