[工作內容 ]
Company Works 公司相關
-Corporate Infrastructure
1.) Information system 資訊系統
2.) Network architecture 網路架構
3.) Security System 安全系統
4.) Cloud solution and service maintain 雲端解決方案及服務維護
Department Works 部門相關
1.) Project Service 專案服務
2.) Solution Service 解決方案服務
3.) Maintain system 系統維護
4.) Technical Support 技術支援
Employee Works Detail 員工相關
-System & Server 系統與伺服器
1.) AD
2.) DNS
3.) Microsoft 365
4.) Hyper-V virtual technology
5.) Web
6.) SQL
7.) Backup solution
8.) AntiVirus Security
9.) ERP
10.) Azure/AWS
*須配合輪值on call, 津貼另計.
工作內容
1. 使用者需求處理與障礙排除
2. 資訊系統軟、硬體維護
3. 網路、通訊相關軟、硬體維護
4. 資訊軟硬體專案規劃與執行
5. 行政事務處理與主管交辦執行
# Microsoft Active Directory & Google Workspace 管理維護
# IT Daily check
# IT Support
# Backup Restore DRP
# 資通安全演練
About the role:
As a Senior GRC Officer, you will play a critical role in strengthening the organization’s cybersecurity governance and supporting the broader Governance, Risk & Compliance (GRC) program. Partnering with IT, HR, and business teams, you will drive initiatives that enhance security awareness and reinforce compliance across the group. You will collaborate with internal stakeholders and translate complex security concepts into clear, actionable guidance aligned with leading frameworks, including:
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF) & SP 800 series
- PCI-DSS
(身為資訊安全風險資深管理師,您將在強化本組織的資安治理及推動更廣泛的治理、風險與合規(GRC)計劃中發揮關鍵作用。您將與 IT、HR 及業務團隊合作,推動提升資安意識及強化集團合規的各項行動。同時,您將與內部利害關係人合作,將複雜的資安概念轉化為清晰且可執行的指引,並確保與主要框架保持一致,包括:ISO/IEC 27001, NIST 網路安全框架(CSF)與 SP 800 系列及PCI-DSS))
What this job involves:
[Assess & Benchmark]:
1. Perform cyber-risk and control-maturity assessments using frameworks such as NIST CSF, ISO 27001, Essential Eight, and proprietary models.
(依據 NIST CSF、ISO 27001、Essential Eight 及內部專有模型,執行資安風險與控制成熟度評估)
2. Translate technical findings into executive-level insights and actionable roadmaps.
(將技術發現轉化為高階管理層能理解的見解與可行的行動計劃)
[Programme Design & Delivery]:
1. Design and implement cyber-risk programs, including risk registers, treatment plans, and dashboards.
(設計並導入資安風險計劃,包括風險登錄表、處理計劃與儀表板)
2. Develop policies, standards, and procedures that ensure compliance and are practical for engineers to adopt.
(制定符合合規要求且工程團隊能實際落實的政策、標準與程序)
[Governance & Compliance]:
1. Own the GRC framework and policy suite; embed the “three lines of defence” model.
(主導 GRC 框架與政策體系;落實「三道防線」模型)
2. Guide stakeholders through audits and regulatory reviews (e.g., APRA CPS 234, SOC 2).
(引導利害關係人通過稽核與法規審查(如 APRA CPS 234、SOC 2))
3. Monitor regulatory changes and advise the business on impacts within 30 days.
(監控法規變化,並於 30 日內向業務部門提供影響評估與建議)
[Strategic Advisory]:
1. Develop rolling multi-year cybersecurity and risk strategies aligned with corporate OKRs.
(制定與公司 OKRs 相符的多年度資安與風險策略)
2. Present risk posture, KPI/KRI trends, and investment options to boards and regulators.
(向董事會及監管機構呈報風險現況、KPI/KRI 趨勢及投資選項)
[Leadership & Coaching]:
1. Mentor junior GRC analysts and upskill cross-functional teams on secure-by-design and offensive-security practices.
(指導初階 GRC 分析師,並提升跨部門團隊在安全設計及攻擊性安全實務上的能力)
2. Foster a culture of continuous improvement and measurable risk reduction.
(培養持續改進與可衡量風險降低的文化)