Skip to content
← Back to job listings

S&S Senior Security Analyst

UL Solutions · Taiwan

Diagnostics / LaboratoryImported listingfull-timeabout 5 hours ago

About The Role

The Senior Industrial Cybersecurity Assessor is responsible for defining project scope, reviewing technical documentation, conducting gap and risk assessments, coordinating security testing, determining conformity, managing technical findings, and preparing formal assessment reports.
This position serves as a senior technical point of contact for customers and internal stakeholders. The assessor handles complex technical issues, ensures project quality and timely delivery, reviews the work of junior assessors and engineers, and provides technical coaching and training.
Depending on individual qualifications and authorization, the position may act as a Project Handler, Technical Assessor, or Technical Reviewer.

  • Independently manage medium- to high-complexity cybersecurity assessment and certification projects, including project scoping, resource and effort estimation, scheduling, risk management, technical review, testing coordination, conformity determination, customer communication, administrative follow-up, and timely delivery.
  • Conduct assessments and support certification of components, products, and systems in accordance with IEC 62443-4-1, IEC 62443-4-2, IEC 62443-3-2, IEC 62443-3-3, and other applicable standards and schemes, such as ISASecure, UL 2941, UL 2900, the CAP Scheme, the EU Cyber Resilience Act, EN 50742, and ISO/SAE 21434.
  • Review Secure Product Development Lifecycle and SSDLC documentation, cybersecurity plans, threat models, risk assessments, security requirements, system architectures, data flows, requirements traceability, and supporting technical evidence.
  • Evaluate cybersecurity controls and plan, perform, or review applicable security testing, including authentication, access control, cryptography, communication integrity, secure updates, vulnerability and patch management, incident response, vulnerability assessments, penetration testing, fuzz testing, and secure code reviews.
  • Identify technical gaps and nonconformities; manage assessment findings, corrective actions, and closure evidence; determine the technical sufficiency of corrective evidence; and prepare clear, accurate, traceable, and auditable assessment records and formal reports.
  • Serve as a Project Handler, Technical Assessor, or Technical Reviewer within the approved competency and authorization scope, and review the technical decisions, assessment records, and reports prepared by junior assessors and engineers.
  • Provide technical guidance, training, and competency-development support to customers, colleagues, operations personnel, and internal stakeholders, including interpretations of standards, explanations of assessment processes, and clarification of technical findings.
  • Resolve complex, non-standard, or disputed technical issues and collaborate with global technical experts, certification teams, the Software & Security team, and relevant standards organizations when necessary.
  • Support the continual improvement of assessment methodologies, work instructions, report templates, testing capabilities, quality procedures, certification schemes, assurance programs, and related cybersecurity services.
  • Provide pre-sales and sales technical support by clarifying customer needs, identifying applicable standards, defining project scope, estimating technical effort and resources, evaluating feasibility, and supporting complex project opportunities.
  • Monitor cybersecurity standards, regulations, and industry trends, and contribute to technical articles, conferences, customer awareness activities, training, and internal knowledge sharing.
  • Maintain the independence and impartiality required of a third-party conformity assessment body and do not design or implement customer controls that will subsequently be assessed by UL Solutions.
  • Strong attention to detail, accuracy, accountability, and responsiveness to customer needs.
  • Ability to work collaboratively in an international, fast-paced environment.
  • Willingness to travel domestically and internationally based on project requirements.

Minimum Qualifications

  • Bachelor’s degree or higher in Cybersecurity, Electrical Engineering, Electronics Engineering, Instrumentation and Control, Automation, Computer Engineering, Computer Science, Information Technology, or another related technical discipline.
  • At least five years of relevant experience in cybersecurity, OT/IACS security, product security, embedded systems, industrial automation, or a related field.
  • Demonstrated experience independently conducting cybersecurity assessments, audits, certification projects, or technical reviews.
  • Practical project experience with the IEC 62443 series, particularly IEC 62443-4-1, IEC 62443-4-2, IEC 62443-3-2, or IEC 62443-3-3.
  • Knowledge of industrial control system architectures, including PLC, SCADA, DCS, HMI, SIS, IIoT gateways, and common OT communication protocols.
  • Ability to review cybersecurity plans, risk assessments, security architectures, threat models, SSDLC documentation, and security testing reports.
  • Strong knowledge of core cybersecurity disciplines, including risk management, asset security, network security, identity and access management, vulnerability management, and secure product development.
  • Demonstrated ability to prepare formal technical reports, make defensible technical determinations, communicate with customers, and deliver technical presentations.
  • Ability to manage multiple projects simultaneously, address complex technical matters, and coach junior engineers or assessors.
  • Excellent written and verbal English skills, including the ability to lead technical meetings, review technical documentation, and prepare formal reports in English.
  • Strong attention to detail, accuracy, accountability, and responsiveness to customer needs.
  • Ability to work collaboratively in an international, fast-paced environment.
  • Willingness to travel domestically and internationally based on project requirements.

Preferred Qualifications

  • IEC 62443 or ISASecure training, certification, or assessor qualification.
  • Professional certifications such as CSSLP, CISSP, GICSP, Security+, OSCP, or equivalent.
  • Experience in product penetration testing, vulnerability analysis, fuzz testing, secure code review, firmware security, or hardware security analysis.
  • Familiarity with ISO/SAE 21434, UNECE R155/R156, ETSI EN 303 645, the EU Cyber Resilience Act, UL 2900, UL 2941, EN 50742, or other applicable product cybersecurity standards and regulations.
  • Experience working for a certification body, testing laboratory, or conformity assessment body.
  • Experience in critical infrastructure sectors such as energy, water, oil and gas, chemicals, maritime, renewable energy, electric vehicle charging, transportation, telecommunications, smart manufacturing, or similar industries.
  • Experience supporting or developing certification and assurance programs, including ISASecure, the CAP Scheme, and related cybersecurity services.
  • Ability to support business development, lead generation, and the development of new cybersecurity services.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing