Wei-Chu Hsiao
Security Program Manager at Splashtop Inc.- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
-
English Native or bilingual proficiency
-
Chinese Native or bilingual proficiency
-
Hokkien Professional working proficiency
Topline Score
Bio
Credentials
-
Certified Ethical Hacker (CEH)
EC-CouncilAug, 2019- Nov, 2024 -
Advanced Certification of Marketing
France Business School -
BS 10012 Lead Auditor
BSI -
ISO 17025 testing and calibration laboratories lead auditor
SGS -
ISO 27001 Lead Auditor - Information Security Certification
SGS -
ISO 27701:2019 Privacy Information Management Lead Auditor
SGS
Experience
-
Splashtop Inc.
-
United States
-
Software Development
-
200 - 300 Employee
-
Security Program Manager
-
Aug 2021 - Present
- Lead the vulnerability management program, which includes liaising with external and internal stakeholders, coordinating penetration tests, and driving the remediation efforts.- In charge of ISO 27001 project, conduct gap analysis and risk assessment, and manage the progress of implementing security procedures and mitigation actions.- Establish a comprehensive cybersecurity awareness training programs and initiate phishing stimulation testing to all offices.- Support the GRC team in GDPR compliance by assessing personal data and create data map and data flow diagrams for EU customers.
-
-
-
資誠 (PwC Taiwan)
-
Business Consulting and Services
-
500 - 600 Employee
-
Senior Cybersecurity and Privacy Consultant
-
Jul 2018 - Aug 2021
• Experience in planning and managing project with accountability and support the overall risk and delivery activities for projects up to NTD$3M and 6-15 months in duration; served as Lead to oversee and direct work of junior level consultants who are assigned to the project activity. • Perform security assessments and provide advisory services for 15+ institutions in accordance to cybersecurity related guidelines or regulations (e.g. HKMA C-RAF, HKMA ICA, Cyber Security Management Act, FSC InfoSec Assessment, SWIFT CSP) and achieve satisfactory security compliance.• Develop cybersecurity policies, procedures and training to minimize risk and ensure business continuity for clients; assist 10+ clients to successfully acquire or maintain certification.• Restructure client’s privacy management programme to meet privacy and data regulatory compliance in Taiwan and implement BS10012:2017 PIMS framework to secure or maintain certification for 5+ international clients and government agencies.• Conduct security testing through use of security tools (e.g. Burp Suite), analysis its risk and collaborate with clients to ensure closure of reported vulnerabilities.
-
-
Associate Cybersecurity Consultant
-
Feb 2017 - Jun 2018
Key areas of expertise include IT governance, IT security framework, security and privacy compliance, process optimization, and system auditPROJECT EXPERIENCE INCLUDES: IT project risk management Security regulatory compliance for Taiwan and Hong Kong banking industry Development of policies and proceduresImplementation of ISO 27001 Information Systems Management SystemsImplementation of BS 10012 Personal Information Management SystemsIT Audit over financial reporting------------* Provide data security and privacy compliance consultation services, identify areas of improvement by gap analysis, and recommend security solutions for clients. * Minimize risk and ensure business continuity for clients by implementing ISO27001 Information Security Management System (ISMS) framework for client and assist clients to successfully acquire ISO certification.* Restructure client’s current privacy management programme to meet privacy and data regulatory compliance in Taiwan and implement BS10012 Personal Information Management System (PIMS) framework to secure certification for several major clients.* Perform security regulatory compliance assessment for banking institutions based in Hong Kong accordance to HKMA security guidelines requirements on Cybersecurity (e.g. C-RAF).* Conduct Independent Compliance Assessment of technology risk management process & IT controls for banks, and led those banks to achieve satisfactory security compliance from HKMA. * Responsible for carrying out the execution of the planned audit procedures either through walkthrough on the processes, analytical procedures, substantive procedures, and testing of controls with clients from banking and manufacturing industries. Qualification: BS 10012:2017 Lead Auditor ISO 27001 Lead Auditor
-
-
-
-
Associate Relationship Manager
-
May 2015 - Dec 2016
• Held multifaceted responsibilities, including relationship management, market research, recruitment, and employment training.• Evaluated business proposals through analyzing the profit potential, market value, and the barriers to entry.• Assist with translation and act as point of contract for local officials and lawyers. • Held multifaceted responsibilities, including relationship management, market research, recruitment, and employment training.• Evaluated business proposals through analyzing the profit potential, market value, and the barriers to entry.• Assist with translation and act as point of contract for local officials and lawyers.
-
-
-
Accenture
-
Ireland
-
Business Consulting and Services
-
700 & Above Employee
-
Associate Software Engineer/Analyst
-
Oct 2014 - Apr 2015
• Conducted current state process analytics and improved the project estimation process to a more streamlined process that saved on average 7-10 days solely on project estimation• Managed the estimation submission process for Service Assurance team and maintained a perfect on-time submission record with accurate project forecasts • Responsible for developing and presenting weekly client-level performance metrics and analytic reports used to influence decisions• Developed a resource management tool with Excel VBA and SharePoint for the head of PM that enable her to forecast resource capacity and allocate resources from project to project • Facilitated client meetings where the team had reviewed more than 100 projects’ scope, schedule, and budget• Created over 10 job aids and instruction manuals to ensure that tasks are completed error-free and complied with the protocol. Also assisted in the transition of the new resource for the analyst role
-
-
Education
-
University of West Georgia
Bachelor of Business Administration (B.B.A.), Management Information Systems, Business Management -
Ecole Supérieure de Commerce Et Management
Bachelor of Arts (B.A.), International Business -
University of Ottawa
Special Topic Research summer program: Canadian Studies