주요업무
Own and improve product security across the lifecycle (design, implementation, testing, and deployment including security standards, directions).
Design security architecture to address increasing security threats and global regulations and compliance requirements.
Assess and advise on network architecture risks, encryption choices, and secure protocol selection in collaboration with development teams.
Perform and support security risk assessments, threat modelling, and security reviews for products.
Support vulnerability management: identify, analyze, and track remediation of vulnerabilities, follow up on verification and closure.
Understand security requirements from external partners and customers, translate them into concrete actions, and help prioritize them based on risk and business impact.
Lead and coordinate Cyber Resilience Act (CRA) readiness and compliance activities for relevant products and services.
Contribute to and improve information security policies, standards, and guidelines collaborating with Business Area's stakeholders to drive information security adaptation.
Lead type approval activities for relevant products.
제품 전 생애주기(설계, 개발, 테스트, 배포) 전반의 보안 주도 및 개선, 보안 표준·전략 수립
증가하는 보안 위협 및 글로벌 규제/컴플라이언스 요구사항 대응을 위한 보안 아키텍처 설계
개발팀 협업 기반 네트워크 아키텍처 리스크 평가, 암호화 방식 및 보안 프로토콜 선정·자문
제품 보안 리스크 평가, 위협 모델링(Threat Modeling), 보안 검토 수행
취약점 식별·분석, 대응 추적, 검증 및 조치 완료까지의 취약점 관리 프로세스 운영
외부 파트너 및 고객 보안 요구사항 분석, 실행 과제 도출 및 위험도·비즈니스 영향도 기반 우선순위 설정
Cyber Resilience Act(CRA) 대응 및 컴플라이언스 활동 주도, 제품 및 서비스 규제 준수 확보
사업부 및 이해관계자 협업 기반 정보보안 정책·표준·가이드라인 수립 및 개선, 보안 체계 내재화 지원
관련 제품 형식 승인(Type Approval) 활동 리딩 및 조율