Alex Yeh
AeroLeads people directory · profile

Alex Yeh Email & Phone Number

經理 at 南山人壽
Location: Taipei, Taipei City, Taiwan, Province of China 9 work roles 1 school
LinkedIn matched
✓ Verified July 2026 3 data sources Profile completeness 100%

Contact Signals

LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
經理
Location
Taipei, Taipei City, Taiwan, Province of China
Company size

Who is Alex Yeh? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Alex Yeh is listed as 經理 at 南山人壽, a with 3264 employees, based in Taipei, Taipei City, Taiwan, Province of China. AeroLeads shows a matched LinkedIn profile for Alex Yeh.

Alex Yeh previously worked as cybersecurity Manager at 南山人壽 and Director at Isc2 Taipei Chapter. Alex Yeh holds Master'S Degree, Infotmation Technology And Management from 實踐大學.

Company email context

Email format at 南山人壽

This section adds company-level context without repeating Alex Yeh's masked contact details.

南山人壽

Review company-level records connected to Alex Yeh before choosing the right outreach path.

Profile bio

About Alex Yeh

I am currently serving as the Director of ISC2 Taipei Chapter, a reputable international cybersecurity certification association based in Taiwan, where I also hold the positions of Media and Public Relations Committee Deputy Chairman, Industry Exchange Committee Deputy Chairman, and Volunteer Committee Deputy Chairman. As the project manager of cybersecurity at a life insurance company, I am passionate about participating in various community events and discussions to promote the importance of cybersecurity.Through my experience as a cybersecurity manager for financial institutions such as banks, life insurance companies, and top enterprises in Taiwan, I have developed a unique perspective combining both technical and managerial aspects of cybersecurity. I have extensive experience in conducting technical assessments, education and training, and developing secure system architectures.Currently, I am focused on providing effective enterprise cybersecurity planning, conducting cybersecurity maturity assessments, and building strong cybersecurity teams. My goal is to help businesses solve their cybersecurity pain points and meet the demands of all stakeholders, ensuring that their cybersecurity practices are on par with industry standards.目前擔任台灣國際認證資安專家協會理事(ISC2 Taipei Chapter Director ),也同時是協會媒體公關委員會副主委、業界交流委員會副主委和志工委員會副主委,任職於人壽保險資安專案經理,喜歡參與社群活動與討論,曾擔任金控、銀行、人壽、產險及台灣百大企業資安主管,兼具資安技術與管理觀點,同時具有豐富之資安技術檢測、技術評估、教育訓練與系統架構安全設計等專案經驗。目前專注服務企業資安藍圖規劃、資安成熟度評估與資安團隊建制,致力解決企業資安痛點,滿足利害相關人需求,讓業務所及之處,資安都能跟得上。CISSP/CISM/CISA/CEH/CHFI/ECSA/PMP/VCP/MCSE/CCNAISO 27001:2013 LAISO 27017:2015 LAISO 27018:2019 LAISO 27701:2019 LA

Listed skills include Computer Networking, Iso 27001 Lead Auditor, Chfi, Project Management, and 9 others.

Current workplace

Alex Yeh's current company

Company context helps verify the profile and gives searchers a useful next step.

南山人壽
南山人壽
經理
taiwan
Employees
3264
AeroLeads page
9 roles

Alex Yeh work experience

A career timeline built from the work history available for this profile.

Cybersecurity Manager

台灣 臺北市

evaluate information security of project.

Director

Isc2 Taipei Chapter

台灣 臺北市

ISC2 Taipei Chapter CouncilMedia and Public Relations Committee Deputy ChairmanIndustry Exchange Committee Deputy ChairmanVolunteer Committee Deputy Chairman

Assistant Manager

台灣 臺北市

As an information security management expert, I have optimized ISMS policies and strengthened endorsement mechanisms to meet regulatory requirements. I verified operations and clarified credit card scope definitions for PCIDSS certification to maintain validity. I ensured compliance with legal requirements and mitigated cross-border security risks for overseas corporate security reviews. I evaluated, tracked, and improved vulnerability management operations and processes for the vulnerability system strengthening project. I conducted effective audits to verify internal and external information security management for security assessments. I led the organizational operation continued management project by conducting BIA, BCP management, and disaster drills, including off-site backup and staff evacuation drills. Lastly, I evaluated and expanded the internal employee's zero-trust verification mechanism for the zero-trust FIDO evaluation project, introducing FIDO authentication to enhance our security posture.負責公司資訊安全,包含但不限於弱點管理(PT/Web Security/Source code Scan/Host vulnerability)、ISMS、資訊安全評估、DLP,並協助公司滿足台灣法規要求及Global/Region總公司的定期查核。以下針對工作期間經歷主要大專案業務列舉說明:1. ISMS:協助公司驗證作業,並重新整併集團、跨公司流程,並輔以政策規範,優化資訊安全要求、明確文件化及強化簽核機制。2. PCIDSS 認證:協助公司驗證作業,除了例行SAQ(Self-Assessment Questionnaire)自我評估問卷、ASV(Approved Scanning Vendor)認證網路弱點掃描、無線溢波偵測及內外部滲透測試;並協助釐清信用卡Scoping範圍界定、信用卡資料流分析,滿足6 個安全原則及12 項的安全領域要求,持續維持PCIDSS認證有效性。3. 海外總公司資安查核:協助查核海外總公司「保險業作業委託他人處理應注意事項」及「費用合理性分攤」議題,確保資安及個資安全滿足國內法令法規要求,及跨境傳輸之安全風險。4. 弱點制度強化專案:協助組織評估、追蹤及改善弱點管理作業及流程,現有每週/每月/每季定期進行相關弱點檢視,包含但不限於PT、Web Security、Source code Scan、Host vulnerability。5. 資訊安全評估及相關查核:透過查核與驗證,有效並完善檢視公司內外相關資訊安全管理及風險,遵循法規要求,依系統分級分類,執行相關資訊安全評估作業,並納入海外總公司託管系統範圍。6. 資訊安全整體執行情形報告7. 組織營運持續管理專案:每年配合組織及Global/Region總公司的要求,進行BIA、BCP管理、規劃,實施實際災難演練、異地備援及員工逃生演練。8. 零信任FIDO評估專案:配合業務單位遠距投保專案,評估導入FIDO認證,並擴大內部員工零信任驗證機制。

Feb 2022 - Oct 2023

Head Of Department

Hotains

Taipei City, Taiwan

As the department head of the Information Security Department, I have successfully implemented and planned for the ISMS (Information Security Management System) and PIMS (Personal Information Management System) to ensure compliance with data protection regulations. In addition, I implemented the TMS (Ticket Management System) to the SOC (Security Operations Center) with careful planning and system requirements analysis, as well as process design. This enabled our company to maintain a secure environment in real-time.Furthermore, I have implemented the VMS (Vulnerability Management System) to the vulnerability scanner tools, leading a successful planning phase and conducting thorough system requirements analysis and process design. This resulted in the effective monitoring of our company's overall security posture, which allowed us to identify and address potential threats promptly.擔任公司資訊安全暨個資保護專責最高主管。負責公司資訊安全暨個資保護管理,以整體規範治理並輔以技術監控檢視,包含ISMS、PIMS、弱點掃描、DLP、SOC、資訊安全評估等資安治理查核業務。帶領團隊一起維護公司資訊安全相關業務。初期透過每月一對一深度訪談了解同仁們的需求及好惡個性,並適度予以反饋提醒解惑相關互動情形;中期因人因事因時適時調整、介入相關工作進度及作業,讓單位專案進度持續依規劃進行,同仁也得以調整、從中學習相關視野的差異;後期已讓同仁得以獨自因應組織要求進行調整及反饋相關需求、建議。以下針對工作期間經歷主要專案業務列舉說明:摘要相關資安專案如下:1. ISMS專案:重新檢視公司現有流程,並輔以政策規範,優化資訊安全要求、明確文件化及強化簽核機制。2. PIMS專案:規劃並導入ISO27701,以提升公司及同仁個資保護制度意識,結合現有ISMS,簡化同仁作業重工。3. SOC事件暨風險弱點管理平台專案:評估並委外SOC機制,導入弱點掃描工具,搭配事件單管理及弱點管理平台,串接基本資產及人員資訊,以滿足系統化、自動化及簽核軌跡,結合事件通報機制,有效控管風險範疇。4. DLP強化專案:檢視現有個資控管技術系統,依計畫分階段進行強化防禦漏洞。5. APT/MDR專案:檢視現有資安防禦機制,評估相關APT、EDR及MDR相關產品,進行相關測試及導入。6. 辦理資訊安全防護自律規範評估專案及相關查核:透過金控及銀行經驗應用於保險業,透過日常資安查核與驗證,有效並完善檢視公司內外相關資訊安全管理及風險,遵循法規要求,依系統分級分類,執行相關資訊安全評估作業。7. 資安教育訓練講師及主持規劃桌面演練:透過2020年金融資安高階主管儲訓計畫CISE訓練及公司內部講師課程訓練,主要製作及規劃公司資安課程並主持授課資安課程,及公司相關個資外洩暨資安事故桌面演練情境流程規劃主持。8. 資訊安全整體執行情形報告暨資訊安全聲明書

May 2020 - Jan 2022

Manager

Taipei City, Taiwan

Manager, Information Security Department• Implement & Optimize Vulnerability Management by PowerShell and Excel VBA.• Implement & Optimize the reporting of employee online behavior monitoring by PowerShell and Excel VBA• Implement VMS(Vulnerability Management System) to Vulnerability Scanner Tools with planning, System Requirements Analysis / Process Design.• Implement Service of Anti-Fraud, Anti-phishing and Rogue mobile app detection.• Implementation of the Measures for the Information Security Evaluation of Computer Systems by Financial Institutions.• Information security system operation (With Arcsight SIEM, OfficeScan, WinMartix, Forcepoint WCG & DLP, Tenable SecurityCenter etc.)負責全行資訊安全管理,包含弱點掃描、員工上網行為管控、資訊安全評估、物聯網資安、滲透測試、釣魚網站偵測、數位鑑識等資安治理查核業務,後期轉任富邦金控監管各子公司資訊安全執行狀況。以下針對工作期間經歷主要大專案業務列舉說明:1. Tenable弱點掃描作業優化:兩萬多筆弱點,透過不斷精進之Excel公式、搭配Powershell等技巧,有效讓追蹤比對效率從6-8小時作業縮短至兩小時內。2. ForcePoint員工上網行為監控通報作業優化:透過Websense Web Security及 DLP Function 模組有效控管及監控全行上網連線及個資外洩風險。並透過有效之Excel與資料夾整理,達到一定之服務水準。3. 風險弱點管理平台專案:評估並導入風險弱點管理平台,以滿足系統化、自動化及稽核軌跡,並結合事件通報機制,有效控管風險範疇。4. 反釣魚網站及偽冒行動軟體偵測暨關閉服務:評估並導入偽網站偵測服務平台,有效偵測及關閉偽網站,以確保公司形象、品牌受到保護。5. 資訊安全評估及相關查核:透過查核與驗證,有效並完善檢視國內外相關分行之資訊安全管理及風險,遵循法規要求,依系統分級分類,執行相關資訊安全評估作業,如下。(約200套系統,近600台主機)。5.1 資訊架構檢視:檢視網路架構之配置、資訊設備安全管理規則之妥適性等,以評估可能之風險,採取必要因應措施及單點故障最大衝擊與風險承擔能力。5.2 網路活動檢視:檢視網路設備、伺服器之存取紀錄及帳號權限,識別異常紀錄與確認警示機制。5.3 網路設備、伺服器、端末設備及物聯網等設備檢測:弱點掃描與惡意程式檢測。5.4 外部網路服務設備檢測:進行滲透測試、程式原始碼掃描或黑箱測試。5.5 安全設定檢視:相關設定及紀錄是否符合規範。5.6 合規檢視:檢視是否符合相關法令法規。5.7 社交工程演練。5.8 Swift CSP查核:檢視並確認是否符合Swift CSP相關控制項目。5.9 資安事件應變演練:包含但不限於DDoS演練、ATM攻防演練、SWIFT Alliance系統事件回應演練、釣魚網站事件回應演練、數位鑑識事件演練。5.10 ISO 27001內部查核5.11 海外分子行資安評估6. 資訊安全整體執行情形報告暨資訊安全聲明書:因應內稽內控規定,檢視同業公會所訂資訊安全相關規範及執行狀況。6.1 檢視資安組織暨架構、權責6.2 檢視資安規範相關執行狀況6.3 檢視資訊安全相關管理規範及專案規劃事宜7. 資訊安全系統維運:7.1 ArcSight SIEM 資訊安全SOC通報7.2 OfficeScan和WinMartix防毒暨週邊管制機制7.3 ForcePoint 員工上網管制暨DLP監控機制

Apr 2018 - May 2020

Senior Engineer

Taipei City, Taiwan

Senior Engineer, Infrastructure System Department • Implement Project of group with Planning, System Requirements Analysis / architecture Design.(With VMWARE & Microsoft Virtualization technology, Storage, NBU Backup System, SLB, WAF, VDI)• Information security system operation.(With Rapid7 Nexpose, Tenable SecurityCenter, Hp Webinspect, Forcepoint DLP, Splunk SIEM etc.)負責公司加值系統維運,包含資安相關、VMware與Hyper-V虛擬化平台管理、新專案建置、AD管理、防毒管理、備份管理、網路管理、集團系統間接與交接,相關SOP撰寫以下針對工作期間經歷專案列舉說明:1. 新專案建置規劃:協助使用單位了解需求,並規劃整理相關流程需求。2. VMWARE 升級規劃:調整現有架構與設備,從vCenter 5.5升級至vCenter 6.5,並使用vDS機制,以應付複雜的網路架構。3. AFA Storage 評估規劃專案:調整現有架構與設備,配合備份與虛擬化平台需求,規劃、建置AFA Storage。4. 備份備援規劃專案(NBU & EMC Networker):配合現有架構與設備,規劃兩地機房備份設計,並執行相關規劃與專案執行。5. 資安Web VA專案:評估並導入、執行HP Web Inspect弱掃與報告解讀,確保公司各開發專案品質。6. 資安System VA專案:執行McAfee System VA與Rapid7 nexpose弱掃功能與報告解讀,以確保公司各系統安全品質。7. 資安APT專案:導入Check Point APT方案,確認設計架構與規則符合公司政策。8. 資安DLP專案:導入WebSense DLP方案,確認設計架構與規則符合公司政策。9. 資安SIEM & LOG專案:調整現有Splunk架構,以符合資安SIEM需求。10. 資安網路環境架構調整:因應資安需求,調整各網段與各機房之間的網路架構與跳板機規劃。

Feb 2014 - Apr 2018

Information Technology Specialist

Excelsior Bio-System

Taipei City, Taiwan

Specialist. • Implement Project with Planning, System / Network Design.(With VMWARE Virtualization technology, Google Workspace (G Suite), ERP)負責公司資訊相關業務,包含:ERP疑難排解設定修改、產線資安維護、網路規劃、防火牆管理、機房VMware虛擬化管理、網站規劃、資訊採購、資產管理、軟體專案管理、相關SOP撰寫、協助ISO、GMP相關導入事宜,並負責整理、監督相關文件之進度與規劃、GMP文件相關管理與發行。初任職於『凌越生醫股份有限公司』時,公司總人數還不到20人,三年後已70多人,隨著人數的快速增加,工作形式從單純的單機管理轉變成複雜的系統規劃。以下針對資訊相關專案列舉說明:1. 雲端Google Apps導入:為建立統一的公司公告、訊息交流的地方,亦整合了公司信箱、公司行事曆與協作文件、影音功能。2. Kaspersky病毒防護與管理規劃:評估公司防毒軟體規劃管理,評估防毒軟體的有效性、誤判率和附加功能上,而Kaspersky提供了可靠的數據與功能。實務上,可以利用Kaspersky進行遠端控制桌面、提供系統訊息、裝置控制,最新版甚至提供WSUS功能。3. ERP導入專案:導入初期通知各單位並整理確認公司流程;中期上線時,協助各單位導入疑難狀況排除;後期優化流程操作並將ERP流程文字化,將ERP所有正向、逆向流程文件化;未來更將規劃進一步解譯出ERP資料庫結構與流程操作在資料庫的相關指令。4. 公司廠房擴建:因人員增加,公司擴充辦公區域,管理相關委外廠商,並主導整體佈線規劃、監工、管理與驗收。5. 機房伺服器虛擬化:因應經費限制與管理便利性,漸進式導入vmware虛擬化技術,從vmware server虛擬化軟體直至 vSphere硬體虛擬化,並從單台至全服務虛擬化,更進階導入vCenter,集中化管理並啟用vMotion、High Availability功能,以靈活運用硬體資源並避免硬體毀損造成服務中斷。6. 儀器設備跨樓層獨立網路規劃:為預防重要儀器設備電腦因病毒或外來入侵造成不可預知的災害,因此封鎖了隨身碟與公司內部網路連結,並設計跨樓層與區域之無線網路規劃,避免破壞或影響原無塵室與實驗室規劃,並透過網路芳鄰以更安全與便利的方式,讓同事交換檔案。7. 公司網站更新計畫:配合商務需求,委外網站設計,並協助商務部同仁更新公司網站資訊與架構。8. 軟體專案計畫:作為計畫PM,負責公司特定軟體開發。跨部門討論內部需求,並委外開發儀器軟體。目前已完成初版軟體,並陸續開發第二版加強功能。9. Vmware view導入計畫:利用桌面虛擬化,讓使用者可以不論任何電腦、行動裝置,皆可以存取屬於自己的電腦桌面。不僅可以減少一般使用者硬體採購的評估與預算,更可以一致性的使用體驗。

Dec 2009 - Feb 2014

Engineer

Ivy Science

Taipei City, Taiwan

Site Engineer, Taipei City Teachers' In-Service Education Center. • Computer Facilities Network wiring• Network and Firewall Troubleshooting• Wireless Network Maintenance• Computer Classroom Construction期間外派駐點於臺北市教師研習中心,主要工作內容,為維護機房規劃管理與故障排除。期間歷經幾項重大事件:1. 機房網路佈線工程:負責監督、協助、處理相關事宜,配合廠商將機房線路全換成CAT6規格,並作好相對應之標示。2. 重大網路與防火牆故障:協助建置windows 2003軟體路由,以4 port路由(學術網路、市府專線、LAN、DMZ)暫時維持網路正常。3. 無線網路維護查線整理工程:協助盤點與維護全中心60台D-link AP 設定與管理,注意維持每台機器正常,並管理與建置無線基地台主管理伺服器(m0m0wall),作無線網路網頁認證、DHCP管理、路由管理等設定。4. 電腦教室建置計畫:電腦教室網路環境更新與電腦汰換專案,協助規劃與佈置網路走線、switch設定與人員動線配置,汰換成CAT6網路線與全新電腦佈建。其他工作事項:1. 配合每次大活動舉辦時,周邊軟硬體維護與管理。2. 協助通過每年政風處與市政府定期與不定期資安檢查。3. 協助每年資訊資產盤點與每次資訊採購。

Mar 2007 - Dec 2009
Team & coworkers

Colleagues at 南山人壽

Other employees you can reach at nanshanlife.com.tw. View company contacts for 3264 employees →

1 education record

Alex Yeh education

FAQ

Frequently asked questions about Alex Yeh

Quick answers generated from the profile data available on this page.

What company does Alex Yeh work for?

Alex Yeh works for 南山人壽.

What is Alex Yeh's role at 南山人壽?

Alex Yeh is listed as 經理 at 南山人壽.

Where is Alex Yeh based?

Alex Yeh is based in Taipei, Taipei City, Taiwan, Province of China while working with 南山人壽.

What companies has Alex Yeh worked for?

Alex Yeh has worked for 南山人壽, Isc2 Taipei Chapter, Chubb Life, Hotains, and 富邦銀行.

Who are Alex Yeh's colleagues at 南山人壽?

Alex Yeh's colleagues at 南山人壽 include 陳曼麗Mendy, 吳筱婷, 李金水, 翁璽濠, and Emmanuel Cheng.

How can I contact Alex Yeh?

You can use AeroLeads to view verified contact signals for Alex Yeh at 南山人壽, including work email, phone, and LinkedIn data when available.

What schools did Alex Yeh attend?

Alex Yeh holds Master'S Degree, Infotmation Technology And Management from 實踐大學.

What skills is Alex Yeh known for?

Alex Yeh is listed with skills including Computer Networking, Iso 27001 Lead Auditor, Chfi, Project Management, Ecsa, Pims, Cissp, and 資訊安全.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.

People with similar names

Check these profiles if this is not the Alex Yeh you were looking for.

View similar profiles