The Role
- Drive regulatory security compliance and certification
- Maintain and update the content in security compliance tool
- Maintain and improve security compliance knowledge base and process
- Support the security experts in the product and process teams in understanding and implementing the security requirements derived from the regional cybersecurity regulations
- Design and deliver knowledge transfer materials and sessions
- Deliver system security pre-assessment service
- Coordinate, support and oversight security compliance audits, certifications
- Optimize the end-to-end process and improve the efficiency
- The role works closely with local and global teams across all lines of business
- Support product teams on security compliance related topics to enable product landing & compliance
- Supports sales and customers on security certification related topics to enable business
- Manage partners and suppliers to ensure smooth collaboration on security and deliver the best result
Role Requirements
- 5+ years of working experience in product security related devops(e.g. security architecture, threat modeling, web application security, Docker/ Kubernetes security, network security, security configuration, security monitoring, incidents investigation etc.), Internal control and security compliance, cloud security (e.g. virtualization, VPCs) , or related field
- Experience or knowledge on Hyper-scaler native security and network services (AWS, Azure, Ali Cloud) is highly preferred
- Proven experience in driving and coordinating between multi-culture, cross-function and diverse environment
- Conflict resolution and negotiation skills, solution orientation and to learn and adapt quickly, thinking out of the box mindset
- Experience with information security best practices andsecurity frameworks / requirements e.g. NIST, OWASP, CIS, ISO27001, CC etc.
- Bachelor's degree in Information Security, Computer Science, or related field required
- Familiar with China Cybersecurity Law, Cryptography Law, CCPS and National Security Standards is a plus
- CISSP, or CCSP, or CISM, CISA certificate preferred
- Good communication (auditor facing) skill and fluent in English
- Good project management skill
Job Segment:Compliance, Cloud, ERP, Information Security, Computer Science, Legal, Technology