信息安全架构师【IT Security】 40-60k
上海-浦东新区 5-10年 本科
收藏
五险一金 公司规模大 弹性工作 定期体检 加班强度较低
avator
吴先生 1天前在线 已认证
聊一聊
职位介绍
1、客户是摩根士丹利,工作地点在浦东嘉里城 2、长期人力驻场职位,有正式的headcount可以逐步convert至甲方 3、五险一金足额缴纳,补充医疗保险,15天年假 4、主要负责安全架构设计,解决方案设计工作【网络/Microsoft/存储/云/app应用 安全方向均可】 5、CISSP CISM证书; 6、英文沟通流利 The SecArch Analysts work with global IT groups to ensure IT projects are executed in a secure manner. Key responsibilities include: • Working with Infrastructure and Development teams in an architecture design and review session to provide specific security expertise. • Identifying areas of cyber risk and ensuring that these risks are appropriately managed e.g., mitigated or risk accepted. • Providing cybersecurity guidance to the Technology Department and helping with documenting security blueprints and cybersecurity position papers. The SecArch team is split into different areas of expertise and the SecArch Analyst is expected to have in-depth knowledge and practical experience in at least one of the following domains (preference for a domain depend on project demands and a current gaps in the team): • Application Security • Infrastructure Security • Cloud Computing Security • Mobile Security • Electronic Trading QUALIFICATIONS • Educated to degree level in a relevant subject • Strong interpersonal skills. • Ability to multi-task and handle multiple projects. • Strong oral and written communication skills. • Knowledge of the common application layer vulnerabilities (eg. OWASP 10), ability to explain these risks and recommend countermeasures to mitigate these risks. • Ability to evaluate technical and functional specifications and identify possible threats or areas of weakness. • Ability to review code of enterprise applications and identify possible security vulnerabilities. • Knowledge of at least one primary operating system (UNIX or Windows), the configuration and management of that platform on an enterprise scale, the security risks to that platform, and how to mitigate those risks. • Understanding of OSI network model and the risks present at each layer. • Knowledge of the functions of network equipment such as switches, routers, firewalls, proxies, VPN, and load-balancers, and an understanding of network architecture. • Familiarity and ability to explain security-related topics such as authentication, entitlements, identity management, data protection, data leakage prevention, validation checking, encryption, hashing, principle of least privilege, software attack methodologies, secure data transfer, secure data storage, etc. • Understanding of Single Sign On technologies such as SAML, Kerberos, and Siteminder. • Industry certifications (i.e., ISC2, ISACA, SAN), though not essential, will help differentiate the candidates.
其他信息
语言要求:英语
行业要求:全部行业

公司简介

中电金信,是中国电子旗下成员企业,通过持续研发创新,参与国家重大工程,依托行业场景,构建金融级数字底座,打造全栈全域解决方案,提供软件产品及开发、质量安全保障及运营服务,为金融及重点行业数智化转型及安全发展提供强大动能。我们推崇开放包容的文化。在中电金信,你将和同样拥有热情和梦想的优秀队友一起合作、交流和学习,稳扎稳打不断提升,和团队一起助力国家重大工程项目。我们为你提供清晰的职业路径和不设限的发展机会,你将通过不同类型的项目不断成长,获得荣耀感和使命感,和我们一起去创造数字时代的美好未来。
查看全部

猎聘温馨提示:

1. 如您发现平台内招聘方存在以下违规行为的,请立即举报
  • a. 扣押您的身份证件或者其他证件;
  • b. 要求您提供担保人、担保金或者以其他名义向您收取财物( 如培训费、体检费、资料费、置装费、押金等);
  • c. 强迫您入股或者向您集资;
  • d. 以招聘名义牟取不正当利益;
  • e. 发布虚假招聘广告信息;
  • f. 工作时长违反劳动法规定;
  • g. 存在其他损害您的合法权益的行为。
2. 如您应聘的岗位属于涉外劳务合作/海外岗位的,请务必核实招聘方对外劳务合作资质取得情况,同时注意自身资金安全,防范招聘欺诈。
查看全部

猜你喜欢

1 2 3 4