职位详情

登录

信息安全主管
1.8-2.4万
人 · 本科 · 5年及以上工作经验 · 性别不限2024/12/30发布
五险一金补充医疗保险员工旅游餐饮补贴专业培训绩效奖金弹性工作定期体检

铭丰广场 25F

公司信息
友邦资讯科技(广州)有限公司

外资(非欧美)/1000-5000人

该公司所有职位
职位描述
Position Objective:
Uplift and transform Security Assessments practices, tools and processes within local business unit. Review application security design and manage DevSecOps gating.


Roles and Responsibilities:
61 Application Security testing
- Guide application teams to fulfill SAST, DAST and Penetration Test (with external vendor) requirements per AIA procedures
- Provide assistance to the technology teams in the resolution of identified risk and vulnerabilities identified through control assessment and/or security testing.

61 Secure SDLC & DevSecOps
- Advise and assist the development team on the Secure Software development lifecycle activities.
- Study and promote the DevSecOps practice, including CI/CD pipeline security set up, container security scanning, and dashboarding configuration, monitoring and reporting.

61 Security champion
- Support and maintain the regional application inventory together with system support team.
- Work with local application team to address the issues.

61 App Risk Assessment
- Perform Security design reviews and application threat modelling on new applications.
- Conduct Application Security Risk assessment on existing applications based on security controls defined by the Group following AIA Security Tollgate process.
- Ensure the risks identified are clearly defined and documented with appropriate evidence.

Minimum Job Requirements:
61 Degree holder in Computer Science or majoring in Information Systems, or related discipline.
61 5 years+ experience in Security\Risk Assessments with a security focus, gained in another sizable organization
61 Previous experience in app development (Java, C#, Objective-C, etc.) is highly advantageous.
61 Previous experience in DevOps/DevSecOps and Container security is highly advantageous.
61 Previous experience in penetration testing services and techniques is highly advantageous.
61 Ability to define, prioritize and execute process in a structured manner.
61 Excellent knowledge of SDLC practices and common security requirements within web and mobile applications.
61 Desirable: Previous experience in WAF (Web App Firewall) and/or anti-DDoS solutions.
61 Certified professional preferred, e.g. CISSP, CISA, ISO 270xx, CRISC, CISM, GWAPT, GPEN.
61 Strong technical skills in application development security practices
61 Practical experience assessing new technologies and applications
61 Excellent understanding of application security best practices, defensive programming techniques
61 Excellent team working and collaborative skills
61 Be adaptable, able to interact and build strong relationships with people from a diverse range of backgrounds.

相关职位
软件需求工程师(J10178)1.4-2.7万·15薪
软件工程师1.5-3万·18薪
六险一金团队氛围好晋升空间大
软件架构工程师1.5-2.5万·15薪
周末双休
软件需求工程师-底盘产品1.5-2.5万·15薪
技术研发岗-钙基产品研发1.5-3万
六险二金带薪假期探亲路费报销
查看所有职位
51米多多提醒你:在招聘、录用期间要求你支付费用的行为都必须提高警惕。 以招聘为名的培训、招生,许诺推荐其他工作机会,甚至提供培训贷款,或者支付体检 、服装、押金和培训等费用后才能录用工作的,都属于违法行为,应当提高警惕。一经发现,请立即举报,并向当地公安机关报案。

举报

招聘信息 > 广州招聘 > 后端开发招聘 > 广州GIS工程师招聘

收藏

热门职位热门城市周边城市