Drive regulatory security compliance and certification
Maintain and update the content in security compliance tool
Maintain and improve security compliance knowledge base and process
Support the security experts in the product and process teams in understanding and implementing the security requirements derived from the regional cybersecurity regulations
Design and deliver knowledge transfer materials and sessions
Deliver system security pre-assessment service
Coordinate, support and oversight security compliance audits, certifications
Optimize the end-to-end process and improve the efficiency
The role works closely with local and global teams across all lines of business
Support product teams on security compliance related topics to enable product landing & compliance
Supports sales and customers on security certification related topics to enable business
Manage partners and suppliers to ensure smooth collaboration on security and deliver the best result
Role Requirements
5+ years of working experience in product security related devops(e.g. security architecture, threat modeling, web application security, Docker/ Kubernetes security, network security, security configuration, security monitoring, incidents investigation etc.), Internal control and security compliance, cloud security (e.g. virtualization, VPCs) , or related field
Experience or knowledge on Hyper-scaler native security and network services (AWS, Azure, Ali Cloud) is highly preferred
Proven experience in driving and coordinating between multi-culture, cross-function and diverse environment
Conflict resolution and negotiation skills, solution orientation and to learn and adapt quickly, thinking out of the box mindset
Experience with information security best practices andsecurity frameworks / requirements e.g. NIST, OWASP, CIS, ISO27001, CC etc.
Bachelor's degree in Information Security, Computer Science, or related field required
Familiar with China Cybersecurity Law, Cryptography Law, CCPS and National Security Standards is a plus
CISSP, or CCSP, or CISM, CISA certificate preferred
Good communication (auditor facing) skill and fluent in English
Good project management skill
Job Segment:Compliance, Cloud, ERP, Information Security, Computer Science, Legal, Technology