Senior Security Emergency Response Expert (m/f/d)
München, Germany
Huawei Research Center Germany & Austria
Huawei is a leading global provider of information and communications technology (ICT) infrastructure and smart devices.Huawei's Munich Research Center is responsible for advanced technology research, architectural development, design and strategic engineering of our products.
Huawei Vulnerability Management Center (PSIRT) was founded and accepted as a member of the Forum of Incident Response and Security Teams (FIRST) in 2010. It has established a vulnerability response process in compliance with ISO/IEC 29147 and ISO/IEC 30111. PSIRT is a dedicated team that receives, investigates, and discloses security vulnerabilities in Huawei products and solutions and is an important vulnerability disclosure window.
PSIRT is responsible for vulnerability management during the Group's deep dive into digital transformation and new business. It builds an end-to-end (E2E) vulnerability governance and capability system and an open vulnerability management ecosystem, implements vulnerability management requirements under the company's diverse business structure to meet stringent external requirements, and ensures that product security capabilities can be translated into competitiveness.
Join us as a
Senior Security Emergency Response Expert (m/f/d)
Your mission
- Be responsible for business planning and architecture design of Huawei security incident response capabilities to support the European market, including gaining deep insights into industry trends, applying advanced management concepts to business practices, establishing a collaborative security emergency response mechanism across different domains, ensuring an up-to-date emergency response architecture, and developing and implementing cyber security emergency plans under the business architecture.
- Support the development of the company's vulnerability management and incident response ecosystem with the academia and industry: identification of ecosystem partners, and establishment, on a case-by-case basis, of collaboration mechanisms and emergency response mechanisms.
- Support the business design of the company's vulnerability management & threat management information system, plan and deploy key threat management technologies; gain deep insights into related technical fields and research trends, and manage and improve Huawei's threat information management capabilities.
- Gather insights and support the development and maintenance of internal processes, to continuously align with industry standards and regulatory requirements in the emergency response field, and ensure compliance with European regulations.
Your areas of expertise
- Master's or PhD degree in cyber security, information security, computer application, or other related majors is preferred. Applicants must have outstanding technical contributions or professional achievements and be familiar with the software SDL process
- At least 5 years of experience in vulnerability management, security incident response, or related fields
- Hold key positions or play key roles in vulnerability-related industry/standards organizations, for example, security/standards organizations, such as OASIS's CSAF workgroup, ISO/IEC SC 27, FIRST, TF-CSIRT/Trusted Introducer, OpenWall, and European incident response communities with country-level constituency (example: InterCERT in France); key SIGs, such as CVSS SIG, PSIRT SIG, and EPSS SIG; key open source communities, such as Linux, Apache, K8S, and Docker; industry alliances and communities, such as OWASP and CSA; and GMSA/TCG/Wi-Fi/Bluetooth CVD teams.
- Hold deep knowledge of incident response practice and local incident response and threat information sharing communities in Europe, ideally through experience gained in a private or national CERT, CSIRT, SOC, or the PSIRT of a prominent manufacturer (proficiency in the native language of a European country is a plus)
- A track record of contributions to the emergency response community, such as guidelines, trainings, publications, presentations at conferences, or the making available of tooling is a plus,
- Fluency in written and spoken Business English
By applying to this position, you agree with our Recruitment Privacy Statement. You can read in full our privacy policy here.
Your rewards of working here
- Our culture is characterized by innovative power and team spirit as well as the intensive exchange of knowledge and experience within our global network.
- We offer healthy meals ranging from traditional Chinese to western delicacies in our famous company canteen.
- To keep your development ongoing, you will find a broad range of training opportunities. Many online and face-to-face training programs incl. language courses in German and Mandarin.
- Our diverse and welcoming environment is shaped by different backgrounds and around 40 individual nationalities.
- Self-responsible work in a competent, motivated and constantly growing team.
Please send your application and CV (incl. cover letter and reference letters) in English.
Huawei is a leading global information and communications technology (ICT) solutions provider. Driven by a commitment to operations, ongoing innovation, and open collaboration, we have established a competitive ICT portfolio of end-to-end solutions in Telecom and enterprise networks, Devices and Cloud technology and services. Our ICT solutions, products and services are used in more than 170 countries and regions, serving over one-third of the world's population. With 197,000 employees, Huawei is committed to develop the future information society and build a Better Connected World.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CERT Cloud Compliance CSIRT CVSS Docker Governance Incident response Kubernetes Linux Open Source OWASP PhD Privacy Product security PSIRT SOC Vulnerabilities Vulnerability management
Perks/benefits: Career development Conferences
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.