【主要工作內容】
1.資訊安全相關專案執行
2.維運及管理個人資料防護系統
3.維運及管理帳號權限管理系統
4.維運及管理資料庫稽核系統
5.執行弱點掃描作業
6.資訊安全事件分析與後續追蹤
7.定期辦理資訊安全事件演練,如分散式阻斷服務攻防演練、模擬駭客攻擊演練、防範個資洩漏演練。
8.辦理資訊安全通報作業
【Job description】
1.Executing information security projects
2.Maintaining and managing personal data protection system, DLP
3.Maintaining and managing user access permissions
4.Maintaining and managing database audit system
5.Performing the vulnerability scan
6.Information security incident analysis and follow-up
7.Regularly conducting the information security incident drill such as decentralized denial of service, DDOS, attack and defense
drill, simulated hacker attack drills and drills on preventing personal information leakage
8.Handling information security notification
1. 執行第三方資訊安全相關管理系統的驗證稽核服務。
(如:資訊安全管理系統、個資管理系統、營運持續管理系統、Cyber Security相關...)。
2.新國際資安標準的研讀及推動。
3 .擔任相關管理系統課程的教育訓練講師,如:公開班或包班講師。
Key responsibilities and accountabilities
· Ensure that value is added to customers and their business/organization through the assessment of their systems and processes against BSI requirements
· Prepare assessment reports and deliver findings to clients to ensure client understanding of the assessment decision and clear direction to particular items of corrective action where appropriate.
· Recommend the issue, re-issue or withdrawal of certificates, and report recommendations in accordance with BSI policy, procedures and prescribed time frame.
· Continually enhance & uphold the reputation and perception of BSI through excellent planning, delivery, report writing and day-to-day interactions with customers and other key stakeholders
· Demonstrate commercial acumen and real added value when feeding back to clients
· Continually demonstrate a professional and engaging approach w
核心工作內容如下
1. 資安法規遵循與合規性確認:
A. 解讀金融業相關的資安法規、標準(如金管會要求、國際標準如 ISO 27001、NIST CSF、GDPR等)。
B. 協助客戶進行差異分析(Gap Analysis),找出現有資安措施與法規要求的差距。
C. 提供改善建議與規劃,確保客戶符合法令規範。
2. 資訊安全管理制度(ISMS)建立與優化:
A. 協助規劃、建立或維護資訊安全管理制度、個人資料保護(個資法)制度、營運持續管理(BCM/BCP)等。
B. 負責資安文件(如政策、程序書)的撰寫與審查。
3. 風險評估與管理:
A. 執行資安風險評估、弱點分析、滲透測試(Penetration Testing)或協助管理相關測試。
B. 識別、分析和評估金融機構面臨的潛在資安威脅與弱點。
C. 制定和實施風險處理策略,以有效保護資訊資產。
4. 稽核與審查:
A. 執行內部稽核、遵循性稽核或查核,確保資安管理制度有效運行。
B. 協助客戶準備第三方審核或認證(如 ISO 27001 認證)。
5. 教育訓練與溝通:
A. 規劃和執行資安與個資保護的教育訓練和意識宣導。
B. 撰寫專業報告與簡報,向客戶高階主管或相關團隊清晰溝通複雜的資安議題、風險與解決方案。
The Cyebr Security Expert will be responsible for the day-to-day operation of our Taiwan laboratory and provide technical support to regional cyber labs. Working in partnership with SGS clients in Taiwan and Asia-Pacific, you will provide a best-in-class commercial cybersecurity testing, inspection and certification service and solution offering that focuses on device, infrastructure and cloud security.
【Key Responsibilities】
• Cybersecurity Assessment – Conduct assessments, gap analysis, and testing for Industrial Control Systems (ICS/OT) based on the IEC 62443 series standards.
• Compliance Assessment – Support clients in establishing OT cybersecurity management systems, perform assessments, and verify compliance with international standards and local regulations.
• Compliance Solutions – Provide recommendations to strengthen ICS/OT environments, covering areas such as vulnerability remediation, risk management, product security, and supply chain security.
• Project Management & Client Engagement – Independently or collaboratively manage projects, including planning, executing assessment, drafting reports, and delivering professional advice to clients.
• Training & Knowledge Sharing – Conduct cybersecurity training sessions, workshops, and internal knowledge-sharing to enhance both client and team capabilities.
【What We Offer】
• Opportunity to work in a global organization with cross-border cybersecurity projects and experts.
• Exposure to real-world cybersecurity use cases across industries.
• Career development and growth.