Responsibilities:
1. Data Security Governance in Europe – Manage the full lifecycle of data security and privacy compliance across the European region; lead the rollout of the Group's data security strategy, data classification & grading, and access control policies; help build and operate the European data security governance framework and operating mechanisms.
2. European Regulatory Compliance – Track regulatory developments in EU data security and cybersecurity, including GDPR, NIS2 (with Germany's NIS2UmsuCG and the Netherlands' Cbw), the EU AI Act, the Cyber Resilience Act (CRA), and the Data Act. Lead the implementation of compliance requirements such as DPIA and cross-border data transfer assessments. Build and operate dual incident notification mechanisms covering both the GDPR 72-hour and NIS2 24/72-hour timelines.
3. External Audit & Regulatory Engagement – Lead external audit preparation for European security systems (e.g., ISO/IEC 27001, ISO/IEC 27701); maintain audit evidence chains, SOPs, and drill records. Act as the security-side point of contact for Data Protection Authorities (DPAs) and other regulators, responding to inquiries, inspections, and security incident notifications.
4. HQ–Region Collaboration & New Business Security Review – As the European data security interface, collaborate with HQ Security Operations, Data Compliance, and Legal teams to support security review and risk closure for new business rollouts in Europe, such as energy storage & charging stations and smart charging.
1. 欧洲区域数据安全治理:负责欧洲区域数据安全与隐私合规业务的全生命周期管理,承接并落地集团数据安全战略、数据分类分级与权限管控策略,协助建立并运营欧洲区域数据安全治理体系与运营机制。
2. 欧洲法规合规落地:跟踪 GDPR、NIS2(含德国 NIS2UmsuCG、荷兰 Cbw)、欧盟 AI Act、CRA、Data Act 等欧洲数据安全与网络安全监管动态,主导 DPIA、数据跨境传输评估等合规要求落地,建设并运营 GDPR 72 小时与 NIS2 24/72 小时安全事件双通报机制。
3. 迎检与监管应对:负责欧洲区域安全体系迎检工作(ISO/IEC 27001、ISO/IEC 27701 等),维护迎检证据链、SOP 与演练记录;作为安全侧接口人对接各国数据保护机构(DPA)等监管机构,响应问询、检查与安全事件通报。
4. 总部-区域协同与新业务安全评审:作为欧洲数据安全接口人,与总部安全运营、数据合规、法务团队协同,支撑储充站、智能充电等新业务在欧洲落地的安全评审与风险闭环。
Qualifications:
1. Bachelor's degree or above in Computer Science, Information Security, Law, or a related field; 5+ years of experience in data security / cybersecurity; experience across both in-house and consulting/vendor environments is preferred.
2. Solid knowledge of the European data compliance regulatory landscape, with hands-on experience in GDPR, NIS2, cross-border data transfer, DPIA/PIA, and data classification & grading.
3. Familiar with the ISO/IEC 27001 and ISO/IEC 27701 management system frameworks; hands-on experience in external audit preparation or audit response.
4. Solid data security technical background (access control, encryption, data masking, monitoring & auditing, etc.) with the ability to drive technical controls into the European region.
5. Strong cross-functional and cross-cultural communication and coordination skills; able to independently engage with regulators, external law firms, and audit bodies.
6. English as a working language; German language skills are a plus. Able to be based in Europe on a long-term basis or to take short-term overseas assignments.
1. 本科及以上学历,计算机、信息安全、法学等相关专业优先;5年以上数据安全/网络安全相关工作经验,具备甲乙方背景者优先。
2. 熟悉欧洲数据合规法规体系,熟悉GDPR、NIS2 数据跨境传输、DPIA/PIA、数据分类分级并有实际落地经验。
3. 熟悉 ISO/IEC 27001、ISO/IEC 27701 管理体系框架,有外审迎检或审核应对实操经验。
4. 具备数据安全技术基础背景(访问控制、加密、脱敏、监控审计等),能够推动技术措施在欧洲区域落地。
5. 具备较强的跨部门、跨文化沟通协调能力,能够独立对接监管机构、外部律所与审核机构。
6. 英语可作为工作语言,具备德语能力者优先;可适应常驻欧洲或短期外派。
Nice to Have
1. CISSP, CIPP/E, CISM, ISO/IEC 27001 Lead Auditor, or equivalent certifications.
2. Background in automotive, manufacturing, or the energy industry; familiar with UN R155 / CSMS or other automotive cybersecurity regulations; experience in EV charging or energy storage.
3. Prior engagement with regulators such as Germany's BSI, the Netherlands' NCSC, or European DPAs.
【加分项】
1. 持有 CISSP、CIPP/E、CISM、ISO/IEC 27001 Lead Auditor 等认证。
2. 具备汽车、制造或能源行业背景,熟悉 UN R155/CSMS 等车规,或有充电/储充业务经验。
3. 有与德国 BSI、荷兰 NCSC、欧洲 DPA 等监管机构对接经验。
XPENG offers:
- An interesting, unique and very varied job at XPENG
- A job with an incredibly large contact surface both internally and externally
- An attractive salary package incl. pension and with the possibility of a bonus
- To be involved in the growth of an existing EV brand in Europe
Next steps:
For more information on how we process your personal data, please see: https://www.xpeng.com/policy
As part of our application process, certain positions at our company require a pre-employment screening to ensure the reliability and integrity of our employees. This screening is a standard procedure and may include components such as a Criminal Background Check from your current or previous country of residence over the past five years. Additionally, the process may involve an integrity questionnaire, verification of identification, diplomas, work experience, and consultation of the central insolvency register.
We appreciate your understanding and cooperation in this important matter, as it helps us maintain the high standards expected by our team.
Our Commitment to Diversity and Inclusion:
At XPENG, we’re an equal-opportunity employer that values diversity and positively encourages applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, disability status or other applicable legally protected characteristics.