{"id":1333452,"url":"https://alion.io/job/ul-ss-senior-security-analyst","title":"S&S Senior Security Analyst","company":{"id":1754684,"name":"UL Solutions","domain":"ul.com","url":"https://alion.io/company/ul-com","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"A","score":89,"open_postings":54,"ghost_share":0,"stale_share":0.259,"repost_share":0,"time_to_fill_p50_days":62,"computed_at":"2026-10-07T05:47:15Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Taiwan"],"countries":["TW"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":19000,"max_usd":44000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1567},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[],"status":"live","first_seen_at":"2026-09-20T21:27:13Z","employer_posted_date":"2026-09-20","last_verified_at":"2026-10-07T22:28:31Z","board_verified":true,"closed_at":null,"days_open":17,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":17},"description":"The Senior Industrial Cybersecurity Assessor is responsible for defining project scope, reviewing technical documentation, conducting gap and risk assessments, coordinating security testing, determining conformity, managing technical findings, and preparing formal assessment reports.\nThis position serves as a senior technical point of contact for customers and internal stakeholders. The assessor handles complex technical issues, ensures project quality and timely delivery, reviews the work of junior assessors and engineers, and provides technical coaching and training.\nDepending on individual qualifications and authorization, the position may act as a Project Handler, Technical Assessor, or Technical Reviewer.\n Independently manage medium- to high-complexity cybersecurity assessment and certification projects, including project scoping, resource and effort estimation, scheduling, risk management, technical review, testing coordination, conformity determination, customer communication, administrative follow-up, and timely delivery.\nConduct assessments and support certification of components, products, and systems in accordance with IEC 62443-4-1, IEC 62443-4-2, IEC 62443-3-2, IEC 62443-3-3, and other applicable standards and schemes, such as ISASecure, UL 2941, UL 2900, the CAP Scheme, the EU Cyber Resilience Act, EN 50742, and ISO/SAE 21434.\nReview Secure Product Development Lifecycle and SSDLC documentation, cybersecurity plans, threat models, risk assessments, security requirements, system architectures, data flows, requirements traceability, and supporting technical evidence.\nEvaluate cybersecurity controls and plan, perform, or review applicable security testing, including authentication, access control, cryptography, communication integrity, secure updates, vulnerability and patch management, incident response, vulnerability assessments, penetration testing, fuzz testing, and secure code reviews.\nIdentify technical gaps and nonconformities; manage assessment findings, corrective actions, and closure evidence; determine the technical sufficiency of corrective evidence; and prepare clear, accurate, traceable, and auditable assessment records and formal reports.\nServe as a Project Handler, Technical Assessor, or Technical Reviewer within the approved competency and authorization scope, and review the technical decisions, assessment records, and reports prepared by junior assessors and engineers.\nProvide technical guidance, training, and competency-development support to customers, colleagues, operations personnel, and internal stakeholders, including interpretations of standards, explanations of assessment processes, and clarification of technical findings.\nResolve complex, non-standard, or disputed technical issues and collaborate with global technical experts, certification teams, the Software & Security team, and relevant standards organizations when necessary.\nSupport the continual improvement of assessment methodologies, work instructions, report templates, testing capabilities, quality procedures, certification schemes, assurance programs, and related cybersecurity services.\nProvide pre-sales and sales technical support by clarifying customer needs, identifying applicable standards, defining project scope, estimating technical effort and resources, evaluating feasibility, and supporting complex project opportunities.\nMonitor cybersecurity standards, regulations, and industry trends, and contribute to technical articles, conferences, customer awareness activities, training, and internal knowledge sharing.\nMaintain the independence and impartiality required of a third-party conformity assessment body and do not design or implement customer controls that will subsequently be assessed by UL Solutions.\nStrong attention to detail, accuracy, accountability, and responsiveness to customer needs.\nAbility to work collaboratively in an international, fast-paced environment.\nWillingness to travel domestically and internationally based on project requirements.\n Minimum Qualifications\nBachelor’s degree or higher in Cybersecurity, Electrical Engineering, Electronics Engineering, Instrumentation and Control, Automation, Computer Engineering, Computer Science, Information Technology, or another related technical discipline.\nAt least five years of relevant experience in cybersecurity, OT/IACS security, product security, embedded systems, industrial automation, or a related field.\nDemonstrated experience independently conducting cybersecurity assessments, audits, certification projects, or technical reviews.\nPractical project experience with the IEC 62443 series, particularly IEC 62443-4-1, IEC 62443-4-2, IEC 62443-3-2, or IEC 62443-3-3.\nKnowledge of industrial control system architectures, including PLC, SCADA, DCS, HMI, SIS, IIoT gateways, and common OT communication protocols.\nAbility to review cybersecurity plans, risk assessments, security architectures, threat models, SSDLC documentation, and security testing reports.\nStrong knowledge of core cybersecurity disciplines, including risk management, asset security, network security, identity and access management, vulnerability management, and secure product development.\nDemonstrated ability to prepare formal technical reports, make defensible technical determinations, communicate with customers, and deliver technical presentations.\nAbility to manage multiple projects simultaneously, address complex technical matters, and coach junior engineers or assessors.\nExcellent written and verbal English skills, including the ability to lead technical meetings, review technical documentation, and prepare formal reports in English.\nStrong attention to detail, accuracy, accountability, and responsiveness to customer needs.\nAbility to work collaboratively in an international, fast-paced environment.\nWillingness to travel domestically and internationally based on project requirements.\nPreferred Qualifications\nIEC 62443 or ISASecure training, certification, or assessor qualification.\nProfessional certifications such as CSSLP, CISSP, GICSP, Security+, OSCP, or equivalent.\nExperience in product penetration testing, vulnerability analysis, fuzz testing, secure code review, firmware security, or hardware security analysis.\nFamiliarity with ISO/SAE 21434, UNECE R155/R156, ETSI EN 303 645, the EU Cyber Resilience Act, UL 2900, UL 2941, EN 50742, or other applicable product cybersecurity standards and regulations.\nExperience working for a certification body, testing laboratory, or conformity assessment body.\nExperience in critical infrastructure sectors such as energy, water, oil and gas, chemicals, maritime, renewable energy, electric vehicle charging, transportation, telecommunications, smart manufacturing, or similar industries.\nExperience supporting or developing certification and assurance programs, including ISASecure, the CAP Scheme, and related cybersecurity services.\nAbility to support business development, lead generation, and the development of new cybersecurity services.","description_format":"text","description_chars":7035,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Energy & Utilities","Professional Services","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-27T13:31:16Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.901,"p_room":1,"age_days":16,"expected_fill_days":62,"reasons":["conf:0","velocity","win:early","comp:brand"],"computed_at":"2026-10-07T05:47:15Z"},"pay":null,"html_url":"https://alion.io/job/ul-ss-senior-security-analyst","json_url":"https://alion.io/job/ul-ss-senior-security-analyst.json","meta":{"generated_at":"2026-10-08T00:23:53Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":471,"day_limit":5000,"remaining_today":4529,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":1754684},"rest":"https://alion.io/mcp/rest/get_company?id=1754684"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Ful-ss-senior-security-analyst"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Ful-ss-senior-security-analyst"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Ful-ss-senior-security-analyst"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/ul-ss-senior-security-analyst\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Ful-ss-senior-security-analyst"}]}