亚马逊Supply Chain Information Security Assessor, Supply Chain Intellectual Property Security
任职要求
基本任职资格 - Bachelor's degree in Cybersecurity, Information Security, or a related field - Fluency in both Mandarin (Chinese) and English (written and verbal). - 3+ years of experience in cybersecurity assessments, document control, or supplier security evaluations. - Understanding of data transmission security and document lifecycle management, including controlled distribution and certified destruction. - Familiarity with security frameworks (ISO 27001, ISO 9001 document control clauses, or similar). - Ability to influence outcomes across organizations without direct authority; strong interpersonal and stakeholder management skills. - Excellent analytical, documentation, and reporting skills. - Willingness to travel up to 75% across APAC region 优先任职资格 - Experience in manufacturing, electronics, or hardware production environments. - Understanding of physical security principles (access control, CCTV, secure storage). - Certifica…
工作职责
SOP & Document Lifecycle Assessment • Map end-to-end document workflows at CM facilities: receipt, storage in Document Control Centers (DCC), distribution to the factory floor, and destruction. • Assess transmission methods and storage controls for data-in-transit and data-at-rest risks. • Verify destruction processes (physical and digital) meet corporate standards with auditable logs. Downstream Information Flow & Contractual Navigation • Map how Amazon IP flows from CMs to sub-suppliers (component makers, PCB houses, tooling vendors), documenting content type, delivery method, and retention at each node. • Identify where Amazon's security requirements terminate in the contractual chain and flag gaps where sensitive content reaches suppliers with no direct obligation to Amazon. • Coordinate with Legal, Operations, and supply chain stakeholders to recommend remediation paths. Logical Asset Governance • Track and inventory logical assets (software licenses, firmware, digital keys, credentials) provided to suppliers; verify return, revocation, or secure destruction when no longer needed. Influence, Reporting & Continuous Improvement • Drive security outcomes across CM organizations and sub-supplier tiers through trust-based relationships, without direct reporting authority. • Document findings, develop risk ratings, and track remediation closure through follow-up assessments. • Contribute to standardized assessment frameworks and automation tools for document lifecycle security.
1. 全链路台账建立与监督:梳理供应链部门核心数据相关业务流程及配套IT系统,明确业务工作流、核心系统架构、关键数据流路径及重点关联人员,建立全链路台账,持续监督各类系统运行安全与数据安全状态;2. 风险识别与流程优化:深度了解供应链业务管理流程,识别信息安全风险点、数据泄露隐患及用户使用痛点,制定针对性管控方案与流程优化建议,跟踪落地并闭环管理;3. 标准落地与合规管控:跟踪ISO 27001等信息安全标准的落地执行,确保部门信息安全合规性,协助制定供应链部门人员信息安全行为基线及违规预警规则并推动执行;4. 精细化授权与应急响应:针对供应链部门特殊业务场景设计精细化授权访问规则并推动执行,参与信息安全事件监测与应急响应,组织部门内部信息安全意识培训及合规宣导;5. 策略编制与风险评估:编制及维护与供应链业务相关的信息安全策略、流程及实操工作指引,建立并动态维护安全风险台账,定期开展风险评估与复盘。
1-Solution Design: Develop tailored supply chain and logistics solutions for regional markets, aligning logistics capabilities with front-end business logic and commercial needs. 2-Partner Management: Build and optimize the partner ecosystem—from onboarding to performance tiering—using data-driven tools to enhance service quality and customer experience. 3-Planning & Fulfillment: Orchestrate supply chain and logistics planning to ensure seamless fulfillment and high customer satisfaction. 4-Operations & Strategy: Manage warehouse operations, merchant projects, and process optimization; lead logistics network design and infrastructure planning. Special Note: This position is part of the company’s Southeast Asia Talent Development Initiative. We are looking for candidates who are willing to complete an internship in China and prepared for long-term roles in Thailand, Philippines, Indonesia, Malaysia, or Vietnam upon successful conversion to full-time employment. Candidates with a strong passion for the Southeast Asian region and proficiency in Malay, Indonesian, Thai, Filipino, or Vietnamese are especially encouraged to apply.
• Conduct on-site physical and cybersecurity assessments of suppliers and contract manufacturers across APAC. • Evaluate supplier environments against company and industry security standards (e.g., ISO 27001, NIST 800-171, TAPA, and internal security frameworks). • Assess security domains including but not limited to: o Network segmentation and access control o Data encryption and protection mechanisms o Endpoint and server security o Secure software provisioning and storage o Incident response and monitoring practices o CCTV Coverage and Monitoring o Physical and environmental security controls • Document findings, develop risk ratings, and provide actionable remediation guidance to suppliers. • Partner with internal security, compliance, and supply chain teams to ensure continuous improvement of supplier risk management programs. • Track, monitor, and verify closure of remediation actions through follow-up assessments or evidence reviews. • Contribute to the development and enhancement of standardized assessment frameworks, methodologies, and automation tools. • Provide training and knowledge-sharing sessions for suppliers and internal stakeholders to improve overall security maturity. • Maintain awareness of evolving global cybersecurity regulations, threats, and best practices relevant to the manufacturing and supply chain ecosystem.
You will be responsible for one of the following areas: Order Fulfillment: Coordinate sales forecasts with order entry; optimize supply resource allocation; manage order commitments, demand changes, and logistics shipments; resolve supply exceptions. Supply Planning: Evaluate market demand and project progress; develop production and delivery plans; identify material supply risks to ensure readiness and on-time delivery. Procurement Execution: Place purchase orders and track supplier schedules; identify delivery risks and close supply-demand gaps. Logistics Management: Design and implement logistics solutions; optimize international logistics networks and warehouse layouts to improve efficiency. Customs Compliance: Coordinate with internal teams and customs brokers; adjust trade strategies to enhance operational efficiency and compliance. Regional Supply Chain Management: Oversee production allocation and demand fulfillment in overseas markets; manage inventory turnover and logistics networks, bridging global supply chain and regional operations.