Objectives:
1. Based on laws and regulations and best industry practices, help establish and improve RD's data security and data compliance management system. Promote and ensure its implementation incl. risk assessment, consultation, and mitigation
2. Support to prepare authority audit / reporting / filing / onsite inspections / etc. based on authority requests, and company needs. Lead to implement identified governance measures incl. data categorization and classification, RD round table, GenAI evaluation, etc.
3. Promote the publicity and training of data security management systems, strategy and goals, processes, requirements, etc., and enhance data security / data compliance awareness of RD China employees based on national and international laws, regulations, technical standards
4. Be responsible for data security risk management. Identify and evaluate data security risks in the development lifecycle and propose corresponding compliance improvement suggestions for the identified risks.
6. Carry out regular governance activities, incl. spot check of DPA / DPIA / Data clearing / etc.
Qualifications:
1. Bachelor degree or above, in electrical engineering, electronics engineering, automotive engineering, computer science, software engineering and other engineering majors
2. At least 3 years or above working experience in data security / data management / data compliance / privacy protection. Experience in mainstream OEMs and multinational companies preferred
3. Comprehensive and profound understanding of data security and data protection related regulations and standards (domestic and international), such as GDPR, Personal Information Protection Law, Data Protection Law, Several Provisions on Vehicle Data Security Management, GB/T-44464, personal information security norms, etc., DPIA (Data Protection Impact Assessments) and PbD (Privacy By Design) practical experience
4. Experience in setting up / operation / implementation of data security / data compliance management system. Familiar with the development process of information or data security related regulations and technical standards, and the corresponding assessment/ certification methods.
5. Familiar with commonly used data and privacy protection technologies, including data categorisation and classification, data desensitization, data encryption, etc., familiar with risk identification in different data processing scenarios, experience in designing data security technical solutions, and implementing data privacy protection solutions preferred
6. Certified with CISP-DSG preferred
7. Good English communication and writing skills. Strong motivation, execution in logical ways. Good project management, operation coordination, problem handling skills, good documentation and writing skills
