职位详情

登录

Technical Lead, Vulnerability Management
2.6-3.5万·14薪
人 · 本科 · 5-10年工作经验 · 性别不限2024/12/24发布
五险一金补充医疗保险子女医疗保险带薪年假带薪病假员工旅游年终奖金专业培训定期体检

中山大学深圳产学研大楼2楼

公司信息
深圳香港马会技术开发有限公司

非营利组织/150-500人

该公司所有职位
职位描述
You will:
· Perform threat assessment and patch management advisory operations via analysis of open and commercial security intelligence feeds, and ensure business and IT patch management teams comply with defined Service Level Agreements (SLAs) for security patch deployment
· Work with IT infrastructure, network operations teams and other IT stakeholders to review and assess new setups, changes, and upgrades to the organisation’s network infrastructure and network components to ensure any move and change will not introduce security risks to the organisation
· Perform vulnerability scanning across the Club’s technology landscape work with key stakeholders to identify, govern and mitigate identified vulnerabilities
· Work with assigned Project Manager to drive small- to mid-size IS initiatives to evaluate, acquire and deploy new IS technologies and capabilities, and ensure initiatives get completed on time and within budget
· Work closely with business and IT stakeholders to schedule and perform system and network vulnerability scanning, classify and prioritise risks, and guide relevant stakeholders to ensure that systems and services that are either developed in-house or acquired commercially are secured against known attack vectors and prevalent threats
· Conduct the web scanning and automated code testing of in-house applications, and guide developers and IT colleagues on coding best practices and mitigations prior to production release to ensure that systems are resistant to known attack vectors, e.g. OWASP Top 10, when deployed
· Support the closure of key cyber security threats and vulnerabilities (e.g. zero-day vulnerabilities or during the Project Development Lifecycle)
· Support the reviews and updates of applicable cyber defence policies, regulations, and compliance documents specifically related to Threat Vulnerability Management and Security Testing
· Undertake other duties assigned by Cyber Security Management. Confidential
· Participate, contribute and help shape a diverse and inclusive culture with trust and respect. Play an active role to support cross-team/division/department efforts and model collaborative behaviours
You should have:
· University Degree in computer science, engineering or related discipline
· Minimum of 5 years of practical experience in IT Security Operations, Network infrastructure in a corporate environment with large-scale transaction websites and complex IT infrastructures and operations
· Cybersecurity certifications such as GCIH, GSOC, CISSP, CISA, CISM, OSCP, MITRE ATT&CK Defender etc. would be desirable
· Experience in Threat and Vulnerability Management
· Technical background, particularly in web application development, infrastructure & networking
· Able to manage the execution of action plans for ensuring the safety and security of all information system assets
· Excellent interpersonal
· Must demonstrate effective oral and written communication skills, with the ability to communicate technical topics to management and non-technical audiences
· Must possess analytical, problem solving and documentation skillsExpertise in security testing, threat and vulnerability management tools and techniques, particularly around vulnerability scanning, patch management and penetration testing
· In-depth experience in secure coding practices, source code review, and Internet threat vectors such as the OWASP top 10
· Deep knowledge of secure networking infrastructure, Firewall, IDS/IPS, WAF, Secure MTA, Load Balancer, Internet Proxy as well as End-Point security
· Working knowledge of security data analytics and incident handling
· Working knowledge in ISO27001/2 or regulatory compliance standard

相关职位
Senior Security Engineer2-4万
网络安全专家2.5-3.5万
逆向工程师2-3.5万·14薪
大小周不加班
Technical Lead, Certificate Management2.6-3.5万·14薪
五险一金补充医疗保险子女医疗保险
Senior ICT Network & Firewall Engineer--瑞士公司30-45万/年
培训方案五险一金
查看所有职位
51米多多提醒你:在招聘、录用期间要求你支付费用的行为都必须提高警惕。 以招聘为名的培训、招生,许诺推荐其他工作机会,甚至提供培训贷款,或者支付体检 、服装、押金和培训等费用后才能录用工作的,都属于违法行为,应当提高警惕。一经发现,请立即举报,并向当地公安机关报案。

举报

招聘信息 > 深圳招聘 > 运维/技术支持招聘 > 深圳网络安全工程师招聘

收藏

热门职位热门城市周边城市