岗位
详情
Position Details
专业要求
计算机科学,信息安全,法律
职位介绍
- 发布日期:2026-09-10
- 职位条件:1. Bachelor's degree or above in Computer Science, Information Security, Law, or a related field; 5+ years of experience in data security / cybersecurity; experience across both in-house and consulting/vendor environments is preferred.
2. Solid knowledge of the European data compliance regulatory landscape, with hands-on experience in GDPR, NIS2, cross-border data transfer, DPIA/PIA, and data classification & grading.
3. Familiar with the ISO/IEC 27001 and ISO/IEC 27701 management system frameworks; hands-on experience in external audit preparation or audit response.
4. Solid data security technical background (access control, encryption, data masking, monitoring & auditing, etc.) with the ability to drive technical controls into the European region.
5. Strong cross-functional and cross-cultural communication and coordination skills; able to independently engage with regulators, external law firms, and audit bodies.
6. English as a working language; German language skills are a plus. Able to be based in Europe on a long-term basis or to take short-term overseas assignments.
Nice to Have
1. CISSP, CIPP/E, CISM, ISO/IEC 27001 Lead Auditor, or equivalent certifications.
2. Background in automotive, manufacturing, or the energy industry; familiar with UN R155 / CSMS or other automotive cybersecurity regulations; experience in EV charging or energy storage.
3. Prior engagement with regulators such as Germany's BSI, the Netherlands' NCSC, or European DPAs. - 职位描述:1. Data Security Governance in Europe – Manage the full lifecycle of data security and privacy compliance across the European region; lead the rollout of the Group's data security strategy, data classification & grading, and access control policies; help build and operate the European data security governance framework and operating mechanisms.
2. European Regulatory Compliance – Track regulatory developments in EU data security and cybersecurity, including GDPR, NIS2 (with Germany's NIS2UmsuCG and the Netherlands' Cbw), the EU AI Act, the Cyber Resilience Act (CRA), and the Data Act. Lead the implementation of compliance requirements such as DPIA and cross-border data transfer assessments. Build and operate dual incident notification mechanisms covering both the GDPR 72-hour and NIS2 24/72-hour timelines.
3. External Audit & Regulatory Engagement – Lead external audit preparation for European security systems (e.g., ISO/IEC 27001, ISO/IEC 27701); maintain audit evidence chains, SOPs, and drill records. Act as the security-side point of contact for Data Protection Authorities (DPAs) and other regulators, responding to inquiries, inspections, and security incident notifications.
4. HQ–Region Collaboration & New Business Security Review – As the European data security interface, collaborate with HQ Security Operations, Data Compliance, and Legal teams to support security review and risk closure for new business rollouts in Europe, such as energy storage & charging stations and smart charging.
若用人单位提供虚假招聘信息,以担保或其他任何名义收取财物,扣押或以保管为名索要证件,都属于违法行为,应当提高警惕。
收录时间:
截止时间:
审核人员: