工作內容:
1. Maintain and secure Git server infrastructure, including access control and vulnerability management.
維護Git 伺服器基礎架構,包括存取控制與漏洞管理。
2. Manage network security, ensuring firewall, VPN, and IDS/IPS configurations are optimized for protection.
管理網路安全
3. Assess and improve application security (AppSec) by conducting vulnerability scans, penetration testing, and implementing secure coding practices.
透過漏洞掃描、滲透測試及安全編碼實踐,評估並改進應用安全(AppSec)。
4. Oversee data storage and retrieval security, ensuring encryption, backup, and recovery processes are in place.
監督資料儲存與存取安全,確保加密、備份及復原機制的有效實施。
5. Deploy and manage cybersecurity tools, such as SIEM, EDR, and threat intelligence platforms.
部署與管理資安工具
6. Monitor system logs and security alerts, responding to potential incidents in a timely manner.
監控系統日誌與安全警報,並及時回應潛在安全事件。
7. Collaborate with RD teams to implement security best practices in development and deployment workflows.
與研發團隊合作,在開發與部署流程中落實資訊安全。
8. Stay up to date with emerging cybersecurity threats and recommend security enhancements.
了解最新的資安威脅並提供強化建議。
9. Ensure compliance with ISO 27001 security standards and best practices.
確保符合 ISO 27001 資安標準。
徵求條件:
1. 英文能力佳- English speaker
2. 資訊工程/ 相關系所畢業
3. 2-3年經驗
4. Security certificate
(ISC2 or SSCP, CSSLP)
*也歡迎新鮮人,具備英文溝通能力,有志向往資安專家發展*
有興趣者,請填寫以下問卷,謝謝!
https://forms.gle/Z8HSXzwxvJMvXieZ8
Introduction:
As a Red Team Specialist focused on MITRE evaluations, you will be part of a dedicated team tasked with enhancing our solution by simulating sophisticated cyber-attacks based on the MITRE evaluations scopes. You will help prepare, conduct, and analyze controlled red team exercises aimed at testing and improving our solutions before the official MITRE evaluations.
Key Responsibilities:
- Design, deploy and maintain the cyber range using AWS or Azure cloud, based on the scope of tests published by MITRE
- Manage, configure, and troubleshoot Windows environment, including Active Directory.
- Develop and execute realistic cyber-attack scenarios based on the MITRE evaluation scopes to identify the gaps and test the effectiveness of our solutions.
- Conduct several dry runs leading up to the MITRE evaluations, ensuring thorough preparation and refinement of tactics and strategies.
- Collaborate with other solution teams to assess the impact of simulated attacks and refine defensive strategies.
- Document findings and provide detailed feedback to enhance our threat detection and response capabilities.
- Participate in post-exercise debriefings and contribute to continuous improvement initiatives.
- Stay updated with the latest cybersecurity trends and updates to the MITRE ATT&CK framework.
Required Skills and Qualifications:
- Strong knowledge of Windows administration and Active Directory management.
- Familiarity with cloud integration and hybrid environments.
- Proven experience in red team operations and familiarity with tools and techniques used in offensive cybersecurity.
- In-depth knowledge of the MITRE ATT&CK framework and experience in applying it to real-world scenarios.
- Strong ability to develop and simulate complex cyber-attack scenarios and manage red team exercises.
- Excellent analytical and problem-solving skills, with the ability to think like both an attacker and a defender.
- Strong communication and collaboration skills, capable of working effectively with cross-functional teams.
Preferred Qualifications:
- Certifications such as OSCP, CEH, or other relevant cybersecurity certifications.
- Experience with scripting and programming languages such as Python, PowerShell, or Bash.
- Prior experience participating in MITRE ATT&CK evaluations or similar cybersecurity assessment frameworks.
- Experience with multi-cloud or hybrid environments.
***若無資訊相關正職工作經驗請統一至R0006775 【新鮮人募集!】 Cloud Engineer 投遞履歷(連結:
https://www.104.com.tw/job/8j3ec?jobsource=bing)***