
Principal Security Architect – Lilly China
Eli Lilly and Company27 days ago
Shanghai, ChinaStaff+
Responsibilities
- Act as the senior technical reviewer and decision-maker for security architecture across Lilly China.
- Conduct security consulting engagements focused on threat modeling, risk assessment, and security improvements.
- Develop technical specifications, design patterns, standards-as-code, and security guidance for cloud and secure application development.
- Perform threat analysis and modeling throughout the secure development and operations lifecycle.
- Apply security, threat-modeling, and architecture frameworks to document technical references, guidelines, and standards.
- Ensure technology designs meet China regulatory obligations and Lilly global and industry standards.
- Partner with Information Security leadership and business and engineering teams in China and globally.
- Prioritize security mitigations related to technology upgrades, enhancements, and process improvements.
- Provide technical leadership and mentorship to regional security engineers and oversee their threat-modeling projects.
Requirements
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or a related field, or a high school diploma/equivalent with 4+ years of related experience.
- 8+ years of demonstrated experience in cloud architecture and security, including hands-on Alibaba Cloud and AWS experience.
- Strong understanding of secure application development, the secure software development lifecycle, and threat-mitigation techniques.
- Working knowledge of China’s data and cybersecurity regulatory environment, including PIPL, the Cybersecurity Law, the Data Security Law, and MLPS/data-localization requirements.
- Experience integrating regulatory and industry standards such as ISO/IEC, GDPR, and GxP/FDA into cybersecurity designs.
- Broad technology knowledge with deep expertise in cloud and application security.
- Experience developing architecture references, security guidelines, and standards and applying security controls and frameworks.
- Strong experience in threat analysis and modeling, cybersecurity engineering and operations, incident response, and GRC functions.
- Proven ability to define and influence security strategy and vision while guiding tactical initiatives.
- Excellent critical-thinking, analytical-reasoning, communication, presentation, and cross-cultural collaboration skills.
- Demonstrated mentorship of junior staff and the technical credibility to hold partners accountable.
- Mandarin proficiency is strongly preferred.
- Must be based in China and able to partner across Lilly China and global teams.