关于职位
1.Lead product and application security reviews, threat / risk / vulnerability analyses, investigations of security-related incidents, and assessment of the security level based on meaningful metrics.
2.Document security findings, outline remediation options, and oversee mitigation.
...
3.Evaluation, specification, implementation, introduction, and maintenance of cybersecurity-oriented development, engineering, and testing tools.
4.Actively engage with product development teams to facilitate secure product design addressing security requirements for new and existing products.
5.Translate cybersecurity governance policies and controls into customized implementation measures, helping to develop and implement security architectures and solutions for embedded systems, ICS, and cloud services.
Establish Product Cybersecurity Framework
6.Evaluate the existing product ecosystem and propose product changes to security leadership and engineering.
7.Facilitate or run internal education and training sessions, with a focus on product security principles.
技能和经验要求
1.Proficiency in both English and Standard Chinese (Mandarin) for effective communication and translation.
2.Highly technical and analytical experience, with a proven deep background in software engineering.
3.Experience with a combination of one or more in embedded software, ICS and OT technology, public cloud providers (AWS, Azure, GCP) and IoT service architectures and cybersecurity aspects of it.
4.Experience with development and testing cybersecurity tools such as SAST/ DAST.
5.Knowledge of international or national standards and regulations for IT/OT Security Standards, Legal issues
6.Experiences in risk-based methodologies and approaches (e.g. Threat and Risk Analysis)
7.Bachelor’s degree preferred in information assurance, computer science, engineering, or related field.
Experience Requirements
8.Five-plus years of professional experience with a combination of one or more in secure product development, application security and engineering or secure development lifecycle.
Certification Requirements
9.Preferably one or more SANS certifications (GWAPT, GWEB, GCSA), CISSP, CSSLP.