Position impact:
The Information Security Engineer will play a critical role in maintaining and enhancing the organization's security posture by managing our complex security infrastructure. This position will be responsible for ensuring the integrity, availability, and confidentiality of our systems and data across multiple security tools and platforms. The engineer will support business operations by identifying, mitigating, and responding to security threats while maintaining compliance with industry standards and best practices.
Responsibilities:
Security Infrastructure Management
• Administer and maintain security infrastructure components including Vulnerability
Management systems, and SIEM solutions.
• Configure, optimize, and troubleshoot log collection systems including Firewall, VPN, and Web security logs.
• Maintain and enhance data flow between security tools.
Monitoring and Incident Response
• Monitor security events and alerts across the environment using SIEM, and other security tools.
• Investigate security incidents, perform initial triage, and escalate as necessary.
• Collaborate with EDR tool on security breaches and incident response.
• Maintain and improve detection capabilities for IDS, and other NDR components.
Vulnerability Management
• Administer vulnerability scanning tools and assist in remediation efforts
• Support the vulnerability management lifecycle
• Coordinate with development teams to implement security controls and patches
• Perform security assessments of systems and applications
Security Tool Integration & Maintenance
• Integrate open-source security tools with existing security infrastructure
• Maintain storage solutions supporting security platforms (NAS, GDrive)
• Ensure proper backup and availability of security data and configurations
• Document security architectures, procedures, and configurations
Compliance and Reporting
• Generate security metrics and reports for stakeholders
• Assist in maintaining compliance with relevant regulations and standards
• Develop and maintain security policies, standards, and procedures
• Participate in security awareness initiatives
工作內容:
1. Maintain and secure Git server infrastructure, including access control and vulnerability management.
維護Git 伺服器基礎架構,包括存取控制與漏洞管理。
2. Manage network security, ensuring firewall, VPN, and IDS/IPS configurations are optimized for protection.
管理網路安全
3. Assess and improve application security (AppSec) by conducting vulnerability scans, penetration testing, and implementing secure coding practices.
透過漏洞掃描、滲透測試及安全編碼實踐,評估並改進應用安全(AppSec)。
4. Oversee data storage and retrieval security, ensuring encryption, backup, and recovery processes are in place.
監督資料儲存與存取安全,確保加密、備份及復原機制的有效實施。
5. Deploy and manage cybersecurity tools, such as SIEM, EDR, and threat intelligence platforms.
部署與管理資安工具
6. Monitor system logs and security alerts, responding to potential incidents in a timely manner.
監控系統日誌與安全警報,並及時回應潛在安全事件。
7. Collaborate with RD teams to implement security best practices in development and deployment workflows.
與研發團隊合作,在開發與部署流程中落實資訊安全。
8. Stay up to date with emerging cybersecurity threats and recommend security enhancements.
了解最新的資安威脅並提供強化建議。
9. Ensure compliance with ISO 27001 security standards and best practices.
確保符合 ISO 27001 資安標準。
徵求條件:
1. 英文能力佳- English speaker
2. 資訊工程/ 相關系所畢業
3. 2-3年經驗
4. Security certificate
(ISC2 or SSCP, CSSLP)
*也歡迎新鮮人,具備英文溝通能力,有志向往資安專家發展*
有興趣者,請填寫以下問卷,謝謝!
https://forms.gle/Z8HSXzwxvJMvXieZ8
1.負責專案之溝通、整合及規劃與執行。
2.維護及推行國際認證(ISO 27001)持續有效。
3.網路安全相關設備(如:APT、IPS、Firewall...等)維護。
4.制定公司整體安全性原則、安全標準、安全技術框架,完善公司安全體系。
5.分析資安弱點、風險事件,通報並追蹤處理狀況。
Job Description
1.Responsible for project communication, integration, planning, and execution.
2.Maintain and ensure the ongoing effectiveness of international certifications (ISO 27001).
3.Maintain network security-related equipment (such as APT, IPS, Firewall, etc.).
4.Develop company-wide security principles, standards, and technical frameworks to enhance the company's security system.
5.Analyze cybersecurity vulnerabilities and risk incidents, report them, and track the resolution status.