Principal Engineer, Information & Data Privacy
Zuellig PharmaZuellig Pharma is a leading healthcare solutions company in Asia, and our purpose is to make healthcare more accessible to the communities we serve. We provide world-class distribution, digital, and commercial services to support the growing healthcare needs in this region.
The company was started a hundred years ago and has grown to become a multibillion-dollar business covering 17 markets with over 12,000 employees. Our people serve more than 200,000 medical facilities and work with over 450 clients, including the top 20 pharmaceutical companies in the world.
Purpose of the Role:
The Principal Engineer for Information & Data Privacy will lead the strategic design, implementation, and management of the enterprise-wide Information Security Management System (ISMS) based on the ISO 27001 framework. This role acts as the central subject matter expert, responsible for developing robust information security and data privacy policies, conducting comprehensive risk assessments, and ensuring compliance across all markets.
By driving security awareness, guiding audit activities, and providing expert consultation to all business units, this position is critical to safeguarding Zuellig Pharma's information assets and upholding our commitment to making healthcare accessible in a secure and trusted manner.
What You’ll Do:
- Leads the design, implementation, operation and maintenance of ISO 27001 Information Security Management System for ZP enterprise which includes the development of audit program related to ISMS for ZPAP ROHQ and cascaded to the Markets IT Heads/Managers in adapting the same.
- Develop and maintain information security policy, standards, and procedures align with ISO 27000 Framework and other industry best practices standards such as NIST and others.
- Perform and conducts risk assessment for ZPAP and provide guidance to ZP Market IT Heads/Managers or designated support ream in performing such risk assessment with data privacy and cybersecurity.
- Assist the ZP Market IT Heads/Manager in performing internal audit activities preparation in relation to ISO 27001 ISMS activities
- Act as an internal consulting resource on information security issues and data privacy protections for Zuellig Pharma enterprise.
- Conduct information security risk assessments that includes data privacy and cybersecurity controls.
- Identifies technology, process, or administrative controls to address an audit findings or non-conformities by applying the corrective and preventive controls
- Perform review of IT security compliance documentations (policies, standards, and procedures) for ZP in a periodic basis and cascading to ZP Market IT Heads/Managers for consumption and roll out.
- Review the compliance of ZP Markets, Business Units and Enabling Functions on data protection policies and controls.
- Conducts Privacy Impact Assessment in coordination to internal stakeholders and business units and ensure that consent forms are up-to-date and development of data privacy program for ZP enterprise
- Coordinate and be active in information security efforts within and across ZP business units, and cooperate with the IT, HR, legal, financial, and executive offices.
- Provide periodic reporting on information security issues to IT management and from time to time report to the Information Technology Steering Committee
- Formulate and maintain information security awareness and data privacy programs for the enterprise and cascade the same to Business Units for implementation and ensure to improve the mentioned security programs.
- Liaises with various Markets HR teams, Business Units, Markets IT Heads/Managers for the implementation of security awareness compliance and data privacy programs and monitoring the KPIs.
- Provide assistance to the concerned team regarding the Business Continuity and Disaster Recovery best practices with respect to the result of the risk assessment on ZP system.
- Perform IT Security and Data Privacy due diligence activities for vendors and technology solutions to ensure that meets the cybersecurity controls of Zuellig Pharma
- Assist the ZP Business Units, Markets, and Enabling Function team such as legal team in reviewing MSA, Scope of Work, and other related documentation associated to a contract.
- Leads the preparation for any IT audit activities (initiated by internal or external) within ZP enterprise and helping various ZP Markets IT Head/Manager and teams with the preparations as well
- Liaises with SAP GRC team of ZP for the access controls activities that needs collaboration with the cybersecurity team.
- Helps the ZP enterprise cybersecurity and infrastructure teams to ensure technology controls are aligned with the current policies, standards, and procedures through technical audits
- Perform the monitoring of KPI scores of ZP Market IT and report to ZPAP Management
- Responsible in updating the Cybersecurity Audit Committee slides and ensures that the report is accurate based on the information gathered from the Markets IT Support
- Assist the cybersecurity team in performing technical security audit activities for ZPAP and ZP Enterprise.
What will make you successful:
Must-Have:
- Bachelor's degree in MIS / Business / IT or a similar subject with strong exposure to information technology.
- Preferably, with IT Security Certifications such as ISO-LA, CISA, and the like, preferably.
- At least 5-8 years of professional experience in IT Security and Compliance
- At least 3 years of professional experience in Data Privacy and Compliance
- Experience in working in a multinational company
- Experience in conducting Risk Assessment
- Experience in performing IT Systems Audit, or ISO 27001 internal audit
- Experience in policy & standard development and implementation align with ISO 27001 (e.g., performing internal audits align with the framework)
- Experience in development a security and data privacy awareness education program for the organization
Advantage to Have:
- Strong knowledge on ISO 27001 ISMS and IT Security processes
- Advanced knowledge of Data Privacy Protection practices
- Advanced knowledge on NIST Cybersecurity publications
- Knowledgeable in GRC for SAP Systems
- Able to comprehend IT technology concepts and able to translate into a framework or process flow
- Good communications and technical writing skills to support the function in developing security policies, standards and procedures and cascading to internal stake holders
- Advanced know how in using the Microsoft Office Applications
- Familiarity with MS Conditional Access, Intune MDM, TPRM Tools
- Able to understand the logs and can conduct investigation and formulate a root cause analysis through a documentation
- Able to represent the audit results to management with an ease and avoiding technicalities for better appreciation of the ZP Management
- Ability to identify the work required and organize, facilitate and / or perform the work with only minimal guidance from senior management.
- Excellent analytical skills
- Able to work with very minimal supervision
What we offer:
- We are committed to fostering an inclusive environment where our employees can learn, grow, and achieve shared success.
- We champion diversity, equity, and inclusion, ensuring every individual feels valued, respected, and treated fairly.
- As a leading multi-market healthcare solutions provider, we empower our employees to gain comprehensive knowledge and expertise in the dynamic healthcare industry across the region.
- Enjoy the flexibility to effectively balance your work and personal life while taking charge of your career journey through our empowering growth opportunities.
- Our Total Rewards program is designed to support your overall well-being in every aspect.