崗位職責(zé):
Job Title: 網(wǎng)絡(luò)安全工程師 Engineer of Cybersecurity
Department: Data Center (DC), Information Technology Department (ITD), HKUST(GZ)
Job ID:
Job Posting Details
Formally established in June 2022, the Hong Kong University of Science and Technology (Guangzhou)(HKUST(GZ)) is a cooperatively-run university between the Chinese mainland and the Hong Kong Special Administrative Region. HKUST(GZ) has obtained approval from the Ministry of Education (MoE) and become the first legally-independent educational institution co-established by the Mainland and Hong Kong since the announcement and implementation of the “Outline Development Plan for the Guangdong-Hong Kong-Macao Greater Bay Area” and the “Overall Plan for Deepening Globally Oriented Comprehensive Co-operation amongst Guangdong, Hong Kong and Macao in Nansha of Guangzhou”. With a spirit of pioneering innovation, HKUST(GZ) charts new territories in cross-disciplinary education and explores new frontiers in pedagogies, aiming to serve as a role model of the mainland-Hong Kong integrated educational development and become a world-famous high-level university, endeavoring to nurture future-oriented, high-level and innovative talents.
In response to the increasingly complex challenges faced by the rapidly changing world, HKUST(GZ) adopts a brand-new and cross-disciplinary academic structure featuring “Hub” and “Thrust” to substitute the conventional one characterized by “school” and “department”, facilitating cross-disciplinary integration while vigorously developing emerging and frontier disciplines. This is a groundbreaking move in the higher education community across the globe.
HKUST(GZ) comprises four Hubs, namely Function Hub, Information Hub, Systems Hub, Society Hub and 16 thrusts. The admission of undergraduate students begins in 2023, with the first batch of programs covering artificial intelligence, data science and big data technology and smart manufacturing engineering.
HKUST(GZ) is located at No.1 Duxue Road, Qingsheng Hub Cluster, Nansha District, Guangzhou. The campus covers an area of about 1,669 mu (111.3 hectares) and is divided into two construction phases. The first phase covers an area of about 716 mu (47.7 hectares) with a floorage of about 636,000 square meters (63.6 hectares), which had been officially put into use in September 2022. The design of the campus blends natural scenery with architecture, with key cutting-edge technologies for energy conservation and environmental protection adopted during the design and construction process, in a bid to establish the campus as a new benchmark of green, smart and sustainable development.
Duties
1. 信息安全制度建設(shè):負(fù)責(zé)制定和完善學(xué)校的信息安全制度體系,不斷提升網(wǎng)絡(luò)和數(shù)據(jù)安全的管理水平和防護(hù)能力。
2. 安全策略設(shè)計(jì)與實(shí)施:設(shè)計(jì)、實(shí)施和維護(hù)網(wǎng)絡(luò)安全策略,以防御惡意攻擊和數(shù)據(jù)泄露,保護(hù)學(xué)校網(wǎng)絡(luò)和系統(tǒng)安全。
3. 制度落實(shí)與監(jiān)督:檢查、監(jiān)督和指導(dǎo)安全管理制度的執(zhí)行情況。
4. 策略執(zhí)行審核:負(fù)責(zé)安全策略執(zhí)行情況的審核,確保合規(guī)性。
5. 日志管理與分析:收集和分析信息系統(tǒng)日志及審計(jì)記錄,對關(guān)鍵設(shè)備進(jìn)行日志檢查和審核,并及時(shí)報(bào)告潛在問題。
6. 操作行為監(jiān)控:監(jiān)督管理員的操作行為,檢查安全職責(zé)落實(shí)情況。
7. 安全控制設(shè)計(jì)與實(shí)施:設(shè)計(jì)和實(shí)施安全控制措施,包括防火墻、入侵檢測系統(tǒng)和防病毒軟件等,確保網(wǎng)絡(luò)安全。
8. 風(fēng)險(xiǎn)評估與漏洞掃描:進(jìn)行網(wǎng)絡(luò)安全風(fēng)險(xiǎn)評估和漏洞掃描,及時(shí)發(fā)現(xiàn)并解決潛在安全問題。
9. 業(yè)務(wù)系統(tǒng)安全測試:負(fù)責(zé)學(xué)校業(yè)務(wù)系統(tǒng)的安全測試與加固,指導(dǎo)開發(fā)人員修復(fù)安全漏洞。
10 .滲透測試與漏洞挖掘:負(fù)責(zé)線上環(huán)境的滲透測試和Web漏洞挖掘,保障系統(tǒng)安全。
11. 安全事件應(yīng)急處理:跟蹤和分析安全事件,包括APT攻擊、木馬和病毒等,并進(jìn)行緊急處理。
12. 跨部門協(xié)作:與其他部門合作,確保網(wǎng)絡(luò)安全政策和流程的落實(shí)和持續(xù)改進(jìn)。
13. 技術(shù)前沿跟蹤:關(guān)注國內(nèi)外安全技術(shù)前沿,積極開展技術(shù)交流和分享。
14. 用戶支持:解決師生關(guān)于網(wǎng)絡(luò)安全的問題和咨詢。
Qualification Requirements
1. 學(xué)歷背景:碩士及以上學(xué)歷,計(jì)算機(jī)相關(guān)專業(yè),信息安全或網(wǎng)絡(luò)安全專業(yè)優(yōu)先。
2. 工作經(jīng)驗(yàn):10年以上信息安全工程師或相關(guān)崗位經(jīng)驗(yàn),具備豐富的網(wǎng)絡(luò)安全實(shí)戰(zhàn)經(jīng)驗(yàn);有5年世界五百強(qiáng)或同等企業(yè)單位相關(guān)信息安全崗位工作經(jīng)驗(yàn)者優(yōu)先。
3. 威脅情報(bào)分析能力:具有深入的安全威脅情報(bào)分析能力,能識別并應(yīng)對高級持續(xù)性威脅(APT)。
4. 網(wǎng)絡(luò)安全知識:熟悉網(wǎng)絡(luò)體系結(jié)構(gòu)、TCP/IP協(xié)議,掌握常見網(wǎng)絡(luò)攻擊方法、原理及防范措施,具備扎實(shí)的信息安全理論基礎(chǔ)。
5. 安全產(chǎn)品知識:熟悉安全態(tài)勢感知平臺、防火墻、日志審計(jì)、WAF、IPS、主機(jī)安全、抗DDoS等主流安全產(chǎn)品的工作原理和配置。
6. 日志分析經(jīng)驗(yàn):具備IPS/IDS、防火墻、操作系統(tǒng)和應(yīng)用程序日志的分析經(jīng)驗(yàn),能夠從日志中發(fā)現(xiàn)異常。
7. 滲透測試技能:熟練使用SQLmap、BurpSuite、AWVS、Kali等常見滲透測試工具,能進(jìn)行手動或結(jié)合工具的安全測試。
8. 編程能力:熟練掌握J(rèn)ava、Python或Shell等一種或多種主流編程語言,能夠開發(fā)簡單的安全工具。
9. 文檔撰寫:具備文檔編寫能力,能夠獨(dú)立完成系統(tǒng)評估報(bào)告和安全漏洞驗(yàn)證報(bào)告。
10. 漏洞挖掘經(jīng)驗(yàn):具有真實(shí)漏洞挖掘和利用經(jīng)驗(yàn),在安全平臺提交過漏洞或發(fā)表原創(chuàng)技術(shù)文章者優(yōu)先。
11. 法規(guī)與標(biāo)準(zhǔn):熟悉ISO 27001、《網(wǎng)絡(luò)安全法》《數(shù)據(jù)安全法》《個(gè)人信息保護(hù)法》及等級保護(hù)相關(guān)標(biāo)準(zhǔn)和規(guī)范。
12. 認(rèn)證及實(shí)戰(zhàn)經(jīng)驗(yàn):持有CISSP、CISP、CISA或CISM認(rèn)證者優(yōu)先,有CTF或攻防演練比賽經(jīng)驗(yàn)者優(yōu)先。
13. 語言能力:良好的中英文書寫和口語能力。
This is a Mainland appointment, and the appointee will be offered a contract by HKUST(GZ) entity in accordance with the Mainland labor laws and regulations. Starting salary will be commensurate with qualifications and experience.
Application Procedure
In support of a green work environment, we accept applications submitted online only. To apply, please register and log in via this link: https://career.hkust-gz.edu.cn/en/career and search for the opening by Job ID or Job Title. Applicants should include a Resume in their applications, and could check their application status via the recruitment website. We thank applicants for their interest but advise only shortlisted candidates will be notified of the result of the application. In exceptional circumstances, for example unsuccessful application, please contact Human Resources Department at gzhr@hkust-gz.edu.cn.
(Information provided by applicants will be used for recruitment and other employment-related purposes only.)
HKUST (GZ) is an equal opportunities employer and is committed to our core values of inclusiveness, diversity, and respect.
廣州 - 黃埔
SGS廣州 - 天河
廣州紫旭信息技術(shù)有限公司廣州 - 黃埔
廣州仁合時(shí)創(chuàng)信息技術(shù)有限公司廣州 - 黃埔
廣州仁合時(shí)創(chuàng)信息技術(shù)有限公司廣州 - 天河
北京天融信網(wǎng)絡(luò)安全技術(shù)有限公司廣州 - 黃埔
SGS