
Cybersecurity Engineer
minimum requirements:
1. Bachelor's degree or above in related security majors such as computer science, software, information security, cryptography, network security technology and engineering, artificial intelligence, mathematics, etc., Prefer network security related majors.
2. Familiarity with related fields such as network security and information security: for example, port, service vulnerability scanning, program vulnerability analysis and detection, permission management, intrusion and attack analysis, etc.
3. Solid and comprehensive knowledge of computer and network (TCP/IP) fundamentals.
4. Familiarity with mainstream programming languages: Java/Python/C/C++/C#/Shell and scripting languages, knowledge of Linux systems and mainstream databases, understand mainstream internet security technologies and security products such as network security, host security, application security, cryptography, as well as security products like firewalls, intrusion detection, and antivirus.
5. Prefer candidates with project experience in security offense and defense, penetration testing (such as DDOS attack and defense, privilege escalation, etc.), and relevant industry network security certificates
6. Prefer experience in network security internships or participation in network security competitions (such as CTF)
expected responsibilities:
Product safety development lifecycle related tasks (50%)
1. Responsible for vulnerability analysis of product requirements and participate in formulating project plans and milestones.
2. Participate in product system design, output maintainable and scalable security system architecture.
3. Responsible for source code scanning and manual audits during the development process.
4. Responsible for penetration testing, assessing security, privacy, and other risks to improve product security performance.
5. After product release, conduct emergency analysis, locate, and propose solutions for potential security issues.
Security Laboratory (40%)
1. Provide security training to the development team to enhance the security awareness, knowledge, and spread security best practices and relevant standards among personnel.
2. Improve the company's security system, including designing and developing the internal security system's related architecture, as well as DevSecOps deployment and support.
3. Undertake the liaison of security-related affairs between global MT and the China region; conduct audits related to cross-team project security implementations.
4. Participate in the daily operations of the security testing laboratory, develop security testing tools, empower relevant testing personnel with technical skills, and liaise with third-party certifications.
Introduction of new security technologies (10%)
Continuously follow up on cutting-edge security issues and explore their integration with business implementations.