asus
Security Compliance Engineer
Boston, Massachusetts · Posted yesterday
Opens app.jobvite.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Not specified
- Source
- Jobvite (employer's hiring system)
Skills mentioned
Supply Chain, CI/CD, DevOps, ISO 27001, Threat Modeling
About the role
Job Description Overview:
The ASUS Robotics & AI Center is seeking a Security Compliance Engineer to establish and maintain the security compliance program for our autonomous systems and the platform that supports them. This role brings the security work of our engineering teams in Boston and Taipei together into a coherent, documented, and auditable whole, from system security planning through certification readiness and ongoing assurance.
We are looking for a disciplined professional with a background in information security, risk management, and information assurance who can translate frameworks and regulatory requirements into practical controls and processes. The ideal candidate is organized, self-directed, and comfortable working closely with engineers, product leads, and external assessors.
Essential Duties and Responsibilities:
- Develop and maintain the system security plan and related security compliance documentation for ARAIC products, infrastructure, and development processes, and keep them current as the systems evolve.
- Map security controls to applicable frameworks and standards and identify gaps between documented controls and the implemented system.
- Coordinate security efforts across engineering teams so that hardware, embedded, cloud, and application work fits within a single coherent security architecture.
- Coordinate threat modeling, risk assessments, and control prioritization with engineering teams.
- Own certification and audit readiness, including assessment packages, readiness declarations, evidence collection, and responses to assessor requests.
- Build and maintain processes for producing standard operating procedures for information assurance and compliance activities.
- Establish processes that keep security documentation aligned with the implemented system, including configuration and change management practices.
- Partner with DevOps and engineering teams to build compliance controls, validation, and evidence generation into development and operational workflows, including secure software supply chain practices.
- Provide security awareness guidance and training to engineering and business teams.
Knowledge and Skills:
- Working knowledge of security and compliance frameworks such as the NIST Risk Management Framework, NIST SP 800-53 or SP 800-171, CMMC, or ISO 27001.
- Experience with risk assessment methods and the development of security controls, policies, and procedures.
- Experience managing secure communications, cryptographic material, or controlled information in a regulated environment.
- Strong documentation and written communication skills, including the ability to produce audit-ready material and to explain security requirements to engineers and non-technical stakeholders.
- Demonstrated organizational skill and follow-through in coordinating work across multiple teams and disciplines.
- Familiarity with secure system design concepts such as hardware roots of trust, secure boot, certificate management, and configuration management is a plus.
- Experience with requirements management or compliance tracking tools is a plus.
- Familiarity with DevSecOps practices and CI/CD pipelines is a plus.
- Relevant certifications such as CISSP, CISA, CISM, CRISC, or CompTIA Security+ are a plus.
- Flexibility to attend virtual meetings with the Taiwan-based team at least three nights per week, and to travel to Taipei once per quarter for stays of approximately two to three weeks.
- Ability to work confidently in a rapidly changing, fast-paced and results-oriented corporate environment where a high degree of flexibility is required
- Excellent written and verbal communication skills in English
Required Qualifications:
Years of Education
- Bachelor’s degree or higher in cyber operations, information security, computer science. Or related field
Work Experience
- 5+ years of experience in information security, information assurance, security compliance, or risk management, including responsibility for secure systems in an operational setting.
Working Conditions:
- Typically work in an office environment. Currently 3 days in office/2 days work from home
- Requires sitting, operating a computer keyboard, telephone and other office equipment for extended periods of time
- Travel requirements: 5% Domestic travel, 5% International travel
About the ASUS Robotics & AI Center
The ASUS Robotics and AI Center is a world-class research and development laboratory that was established with the mission of developing ambitious technologies that will define the future. Our multidisciplinary team of the brightest engineers and scientists is dedicated to creating software-focused solutions that will solve some of the most enduring challenges in the fields of robotics and artificial intelligence.
More About ASUS
ASUS is a global technology leader that provides the world’s most innovative and intuitive devices, components, and solutions to deliver incredible experiences that enhance the lives of people everywhere. With its team of 5,000 in-house R&D experts, the company is world-renowned for continuously reimagining today’s technologies. Consistently ranked as one of Fortune’s World’s Most Admired Companies, ASUS is also committed to sustaining an incredible future. The goal is to create a net-zero enterprise that helps drive the shift towards a circular economy, with a responsible supply chain creating shared value for every one of us.
$100,000 - $150,000 annually is the estimated pay range for this role working in the Boston, MA office. The final amount will be determined based on qualifications & experience of the candidate relative to the role. Our comprehensive employee benefits include bonuses, medical, dental, vision, life insurance, AD&D insurance, Paid Time Off, EAP, & 401(k).
ASUS is an equal employment opportunity employer. The Company makes employment decisions without regard to race, color, religion, sex, gender, pregnancy/ breastfeeding, medical conditions related to pregnancy or childbirth, sexual orientation, age, national origin or ancestry, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, as well as any other characteristic protected by law, regulation or local ordinance, and strives to comply with all applicable laws on the subject. These employment decisions extend to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment, pay and other forms of compensation, training and other terms and conditions of employment.
Job ID jv-asus-oi8wafwg · Original posting ↗