3 дня назад
Senior Security Engineer (Privacy & Data Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Privacy & Data Security) (AI cloud): Building technical privacy and data security controls for a global GPU cloud with an accent on encryption, key management, data discovery, and GDPR compliance. Focus on implementing DSAR capabilities, designing cross-border safeguards for SG↔EU transfers, and producing evidence mapped to SOC 2, ISO 27001, and ISO 27701.
Location: Penang, Malaysia or Singapore
Company
develops Bitcoin mining infrastructure, ASIC chips, mining rigs, datacenters, and AI cloud capabilities.
What you will do
- Design and implement encryption at rest and in transit, KMS/HSM capabilities, BYOK/HYOK, and key lifecycle management for a multi-tenant cloud platform.
- Establish PII discovery, data classification, and data-flow mapping across compute, storage, and logs.
- Implement DLP, pseudonymization, tokenization, least-privilege access controls, and data residency architecture including an EU region.
- Build technical capabilities for locating, exporting, and deleting personal data across logs and backups, while managing retention conflicts.
- Translate GDPR requirements into runnable technical controls, privacy-by-design measures, TOMs, SCC Annex II documentation, and auditable evidence.
- Support customer security and privacy due diligence and collaborate with Legal, the DPO, Group Risk & Compliance, infrastructure security, engineers, auditors, and customers.
Requirements
- 5–8 years of hands-on security or data security engineering experience, including encryption, KMS/HSM, and cloud security.
- Experience with privacy engineering, data-flow mapping, DSAR implementation, data minimization, de-identification, and privacy by design.
- Ability to map GDPR requirements to technical controls, TOMs, SCC Annex II, and DPA security annexes.
- Understanding of Kubernetes multi-tenant isolation, cloud platform data flows, GPU cloud or AIDC architectures, and cross-border data transfers.
- Experience implementing or supporting SOC 2, ISO 27001, or ISO 27701, plus automated compliance evidence collection or policy as code.
- Mandarin is required for day-to-day Security Team collaboration; English is required for technical documentation, DPA annexes, and customer due diligence.
Nice to have
- CIPT, CIPP/E, ISO 27701 LI/LA, CIPM, or CDPSE certification.
- End-to-end GDPR, DPA, or equivalent privacy compliance implementation experience.
Culture & Benefits
- Inclusive environment that values authenticity and diverse perspectives.
- Startup spirit within a fast-growing technology company.
- Autonomy, personal accountability, and opportunities to contribute to new systems and projects.
- Training, mentoring, welfare benefits, and development opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →