MediaTek logo

R&D and Information Security Risk Management Engineer

MediaTek

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Job Description

  • Perform internal audits over the IC design R&D cycle, covering product/customer requirements, system specification, architecture design, hardware design, software design, HW/SW integration, verification/validation, tape-out, software release, silicon bring-up, mass production introduction, version maintenance, and customer feedback processes. 2. Evaluate the design and operating effectiveness of key R&D controls 3. Support the development of R&D risk and control matrices, mapping R&D risks to control activities, data sources, audit test rules, and audit evidence to establish a traceable, measurable, and continuously monitorable audit framework. 4. Analyze R&D process and data risks to identify exceptions that may impact product quality, project schedule, customer commitments, intellectual property protection, information security, compliance, and business operations. 5. Conduct audits over R&D data and access controls 6. Design audit test logic and data analytics rules. 7. Collaborate with RD, IT, Information Security, Data Governance, Legal, and process owners to validate data sources, data quality, data lineage, permission boundaries, remediation plans, and issue closure status. 8. Prepare audit workpapers, risk analysis reports, and management reports, summarizing major risks, control effectiveness, remediation progress, repeat issues, overdue actions, and AI implementation results to support audit management, Audit Committee, or Board-level oversight. 9. Assist in developing and Audit Agents, using AI Agents to collect, cleanse, and integrate R&D flow data, and to enable daily risk monitoring, exception detection, evidence creation, and audit workpaper support. 10. Review AI / Audit Agent-generated audit findings to ensure each finding is supported by an evidence ID, data source, test logic, human review record, and sufficient audit evidence, following the principle that AI supports analysis while humans own audit conclusions.

Main Requirements and Qualifications

    1. Solid understanding of internal audit, internal control, risk management, or IT audit methodologies, with the ability to translate process risks into testable controls and audit procedures.
    1. Basic understanding of IC design, semiconductor, electronic product development, or hardware/software R&D processes, including risks from requirement definition, design, verification, release, and production maintenance.
    1. Familiarity with common R&D controls, such as design review, code review, branch protection, bug tracking, coverage review, waiver approval, release gate, and tape-out sign-off.
    1. Strong data analytics skills using SQL, Python, Excel Power Query, Power BI, Tableau, or other analytics tools for data cleansing, reconciliation, exception detection, and visualization.
    1. Ability to understand and analyze data from R&D systems, such as Git / GitLab / GitHub, Jira, bug tracking systems, PLM, release systems, IAM, HRIS, EDA / CAD flow logs, or other engineering data sources.
    1. Knowledge of access control and identity management concepts, including least privilege, JML access control, privileged account review, terminated user access removal, and role-based access control.
    1. Basic knowledge of information security and data protection, including DLP, USB / cloud storage control, source code protection, sensitive data classification, audit trail, and log review.
    1. Understanding of intellectual property and R&D data protection risks, such as High Sensitive IP, third-party IP, open source software, SBOM, EDA / PDK / Foundry data, NDA data, and export control.
    1. Strong process interview and cross-functional communication skills, with the ability to work with RD, IT, Information Security, Data Governance, Legal, project management, and process owners.
    1. Ability to convert business and process risks into data rules, such as translating “release without code review” into data reconciliation logic among commits, pull requests, approvals, and release tags.
    1. Interest or experience in AI, Agent, RPA, or audit automation tools, with the ability to support the design of Audit Agent test rules, data requirements, output formats, and human review workflows.
    1. Strong documentation skills, including the ability to prepare audit workpapers, process flows, risk control matrices, finding descriptions, root cause analysis, remediation recommendations, and management reports.
    1. Strong analytical thinking, problem-solving, and project management skills, with the ability to manage multiple audit assignments, data analytics tasks, issue tracking, and cross-functional communications.
    1. High level of professional ethics, confidentiality awareness, and risk sensitivity when handling R&D confidential information, customer data, IP data, access control data, and audit findings.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at MediaTek was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.