岗位职责 1.隐私合规框架搭建 - 主导企业GDPR及其他全球隐私法规(如CCPA、中国《个人信息保护法》)合规体系建设,制定隐私政策、数据处理协议(DPA)及内部合规流程。 - 针对车企业务场景(如车联网、自动驾驶、用户APP),设计车辆端数据采集、存储、传输的全生命周期合规方案。 2.车辆端隐私安全服务 - 深入分析车载系统,识别隐私风险点,提出技术改进方案(如匿名化处理、加密传输)。 - 协同产品、研发团队,将隐私保护设计(Privacy by Design)嵌入车辆硬件/软件开发流程。 3. 合规审计与响应 - 定期开展隐私影响评估(PIA/DPIA),应对监管机构审查及用户数据主体权利请求(如删除权、访问权)。 - 处理车辆数据泄露事件,制定应急预案并协调跨部门执行。 4. 培训与生态协作 - 为车企客户及内部团队提供GDPR合规培训,推动供应链上下游(如零部件供应商)的隐私合规联动。 - 任职要求 1. 核心能力 - 精通GDPR条款及汽车行业隐私合规要点,熟悉UNECE R155/R156等国际车载安全法规。 - 具备从技术视角解读隐私问题的能力,能独立完成代码审计、数据流图谱绘制。 2. 经验背景 - 3年以上隐私合规/数据安全经验,有车企、Tier 1供应商或智能硬件企业从业经历者优先。 - 参与过整车厂GDPR合规项目,或主导过至少1个车载系统的隐私保护方案落地。 3. 技术资质 - 持有IAPP认证(CIPP/E/CIPM)、CISSP或同等安全资质者优先。 - 熟悉车载通信协议(CAN/LIN/以太网)及OTA升级安全机制。 4. 软性素质 - 优秀的跨部门沟通能力,能用中英双语撰写合规文档并与海外团队协作。 - 对智能汽车技术趋势敏感,能快速应对新兴场景(如车路协同、V2X)的合规挑战。
At TÜV Rheinland’s Industry Service & Cybersecurity division, we are looking for talented individuals who are ready to help shape the future of industry and drive technological progress. Our focus is on digitalization and connectivity in industry, as well as on the further international expansion of our services in the field of renewable energy and our support for major infrastructure projects.
Equal opportunities are particularly important to us at TÜV Rheinland. We are committed to breaking down barriers and creating an inclusive working environment characterised by respect, diversity and genuine participation. We therefore particularly welcome applications from people with severe disabilities.
Join a team that drives innovation and makes the world safer and more connected. With us, you can apply and expand your knowledge and actively help shape the industry of the future—in an environment that fosters learning and diversity.