about the company
We are an innovative biotechnology and pharmaceutical R&D enterprise with a collaborative strategic layout across China and the US. Our core assets encompass critical research and development milestones, including drug targets, biological sequences, experimental data, and formulation processes.
about the team.
This position reports directly to the CTO. As the company’s first dedicated Data Security Expert, you will be responsible for building the data security and privacy governance framework from scratch, while promoting a cross-border collaborative culture that emphasizes autonomy, rigor, and a balanced focus on both technology and compliance.
...
about the job.
- As the first dedicated data security hire at the company, you will build the data security and privacy governance function from the ground up. Reporting to the CTO, you will own our data protection framework across China and US sites, working independently. Our most critical assets are R&D data — drug targets, biological sequences, experimental results, formulations, process parameters, and research reports. You will ensure these assets are classified, protected, monitored, and governed throughout their lifecycle, answering four core questions: what sensitive data do we have; who can access, download, and share it under what conditions; is data shared with hospitals, CROs, overseas partners, or cloud platforms compliant and secure; and how do we detect, respond to, and trace misdelivery, unauthorized access, leakage, or ransomware incidents.
- Data Classification & Asset Inventory:Establish a data classification framework for biotech R&D; catalog critical assets (targets, sequences, experimental data, formulations, process parameters, research reports) across both sites; define data ownership and cross-border data flow mapping.
- Access Governance & Control:Define and enforce RBAC policies governing who can access, download, export, and share sensitive data; drive least-privilege, periodic access reviews, and DLP/encryption/DRM controls consistently across China and US.
- Third-Party & Cross-Border Data Transfer:Ensure compliant and secure data transfers to hospitals, CROs, overseas collaborators, and cloud platforms; lead TIAs/PIAs, negotiate DPAs/SCCs, and manage cross-border data flows between China and US under PIPL/DSL, GDPR, and HIPAA.
- Incident Detection, Response & Traceability:Build incident response capability for misdelivery, over-privileged access, data leakage, and ransomware; implement monitoring, alerting, and audit logging for full traceability; lead forensics, root cause analysis, and regulatory reporting in both jurisdictions.
- Governance, Policy & Compliance:Develop and enforce data security policies, standards, and training; ensure compliance with China CSL/DSL/PIPL, GDPR, HIPAA, and GxP data integrity (ALCOA+); support audits and certifications (ISO 27001/27701, SOC 2); embed security-by-design into systems, cloud, and AI/ML initiatives.
skills and experience required.
- Bachelor's degree or above in Information Security, Computer Science, Cybersecurity, Law, or related field.
- 5 years of experience in data security, information security, or privacy governance, with hands-on responsibility in a pharmaceutical, biotechnology, or life sciences company.
- Experience protecting R&D data (targets, sequences, experimental data, formulations, process parameters) is highly preferred; MNC / foreign-invested enterprise background is a plus.
- Solid knowledge of data classification, RBAC/ABAC, DLP, encryption, IAM/PAM, cloud security (CASB/CSPM), and security monitoring.
- Familiar with key regulations: China PIPL/DSL/CSL, GDPR, HIPAA, GxP (ALCOA+); experience with cross-border data transfers and third-party risk management.
- Fluent in English and Chinese; able to collaborate across China–US. Highly self-driven and comfortable working independently as the first dedicated hire — must be able to define priorities, build the function from scratch, and drive execution without an existing team. Strong communication, analytical, and project management skills; certifications (CISSP/CISM/CIPP/CISA/CISP) are desirable.