Information Security

2020.01.01 Taiwan

[Job Description]

LINE is committed to user privacy and compliance with data protection regulations. Our information security team is involved from the early service planning stages, and oversees how user data is to be processed throughout the service provision to ensure that our data management practice complies with security regulations and the company’s data policy. In addition, this team is in charge of preparing and enforcing internal security policy, operating information security management systems, and conducting security awareness training to maintain the appropriate level of data governance throughout the company. 

Knowledge of information security management and personal data protection is mandatory for this position. Furthermore, to be capable of conducting privacy impact assessment and providing effective advice on the service specification, you need to have basic IT understanding. 

This position will cooperate with legal, planning, government relationship, and engineering departments. You will learn how to provide a reliable service by designing user-facing UX flows and applying security technologies. 

Privacy assessment 
1. Perform privacy assessment to ensure that LINE services and campaigns are in compliance with the personal data protection regulations as well as internal policy. 
2. Engage in service design review and provide privacy-friendly suggestions to protect LINE users’ personal data. 
3. Co-work with global teams to deal with privacy and data protection issues. 

Security policy enforcement 
1.Perform internal and external security audit. 
2.Assess the security risks within the office, develop local guidelines, and help employees to comply with company’s information security policy. 
3.Provide security training to employees. 


Required Skills and Qualifications 
1. Must be familiar with Information Security Management Systems (ISMS) and its practices.
2. Must be familiar with Taiwan Personal Data Protection Act
3. Must be familiar with personal information management system, such PIMS or TPIPAS
4. Should be familiar with corporate security management systems, such as endpoint security, anti-virus, DLP, internal network security, and physical security management.
5. Team orientation who can communicate with teams from different countries/departments
6. Fluent English

Preferred Skills and Qualifications 
1. Information security certificates, such as ISO 27001 LA, BS10012, CISSP, CISA or TPIPAS
2. Experience in building the ISMS and PIMS for enterprises 
3. Basic understanding of Internet, instant messengers, web/mobile services and encryption technology
4. Working experience in firewall, DLP, and anti-virus systems
5. Incident response ability 
6. Japanese or Korean language skill would be a plus