新北市中和區6年以上大學
Product Compliance, Security & Cybersecurity
We are seeking an experienced Security Lead with a strong background in product compliance, security, and cybersecurity to support and enhance our organization’s compliance and security initiatives. This role will focus on implementing global compliance programs (e.g., PII, GDPR, SOC 2, CSA Star Level 1), strengthening cybersecurity practices, and ensuring secure product development. The ideal candidate will possess technical expertise, project management skills, and a solid understanding of global and US-specific compliance frameworks.
*Key Responsibilities:
◎Team and Project Support
-Assist in managing a high-performing team focused on compliance, product security, and cybersecurity initiatives.
-Collaborate with team leads to ensure timely delivery of compliance and security projects.
◎Compliance Management
-Support product compliance efforts, adhering to global standards like GDPR, NIST CSF, SOC 2, CSA Star Level 1, and US-specific PII regulations (e.g., FTC COPPA).
-Assist in maintaining compliance with data privacy and protection frameworks, including those related to Personally Identifiable Information (PII).
-Help prepare documentation and processes for regulatory audits and certifications.
◎Cybersecurity Implementation
-Contribute to cybersecurity initiatives, including Security Severity Modeling, Incident Response (IR) policies, and risk management.
-Assist in executing critical programs, such as Zero Touch Production, DRATA implementation, and AWS permission reviews.
-Collaborate with teams to identify and mitigate risks across the product lifecycle.
◎Operational and Tool Management
-Support the adoption and integration of tools like JIRA, Confluence, and Drata to streamline compliance and security processes.
-Track and report operational metrics to align with compliance and security goals.
◎Stakeholder Engagement
-Act as a liaison between compliance, product, and legal teams to support the alignment of business objectives with security initiatives.
-Provide updates on project progress, risks, and key initiatives to senior leadership.
◎Education & Experience:
-Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
-6+ years of experience in software engineering, security, or compliance roles, with at least 3+ year in a leadership a team of at least 5+ members with strong people and project management skills
◎Technical Skills:
-Experience in product compliance and global regulatory standards (PII, GDPR, SOC 2, CSA Star Level 1, and US-specific frameworks like FTC COPPA).
-Knowledge of secure software development lifecycles (SDLC), DevSecOps, and cloud security (AWS, Azure, or GCP).
-Familiarity with cybersecurity tools, such as SAST/DAST, SIEM, and WAF.
◎Leadership & Soft Skills:
-Proven ability to manage and inspire cross-functional teams to meet strategic goals.
-Strong decision-making skills, with the ability to balance technical, compliance, and business priorities effectively.
-Experience in conflict resolution, fostering team cohesion, and driving alignment across departments.
-Ability to delegate tasks effectively while maintaining accountability for overall project outcomes.
-Skilled in setting clear objectives and measurable key results (OKRs) to guide team efforts and assess success.
-Excellent interpersonal and communication skills, with a focus on building relationships and influencing stakeholders at all levels.
◎Preferred Qualifications:
-Security certifications (CISSP, CISM, CEH) are a plus.
-Experience in compliance-heavy industries such as fintech, healthcare, or education.
-Familiarity with container security, Kubernetes, and CI/CD pipelines.
-Understanding of global compliance frameworks and their practical implementation.