远程工作雷达

高级/负责人安全研究员

Senior/ Lead Security Researcher

开发工程限定地区(需当地身份)
公司V-Key Pte Ltd
薪资未公开
工作地点India
地域资格限定地区(需当地身份)
时区要求日间重叠约 6 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 India 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位描述
V-Key 是全球领先的移动网络安全深度科技公司。我们专利技术 V-OS 已被顶级银行、移动支付提供商和政府部署,用于保护软件解决方案并为全球超过 5 亿用户提供安全保障。
我们正在快速进入新市场和新客户群体。除了为所有人保障数字交易安全,我们还通过为银行、政府和智能家居等众多领域提供网络安全基础设施,推动新一代技术的发展。
在 V-Key,我们致力于打造一个技术用户可以享受前所未有的安全与便利的未来。
我们正在寻找一名(高级或团队负责人)安全研究员,加入产品安全团队。您的主要职责是与团队合作,开展移动设备上威胁的前沿研究与开发(R&D),以开发创新的产品和解决方案来应对这些威胁。
职责和要求

  • 研究移动操作系统和应用中的威胁(如 Root/越狱及其隐藏、应用篡改、运行时篡改等),涉及 Android / iOS / Harmony OS Next。
  • 与团队合作,通过逆向工程、漏洞研究、利用和缓解技术以及移动/嵌入式开发,开发防护机制。
  • 与团队合作,对 V-Key 的产品和应用进行渗透测试。
  • 与团队合作,编写针对移动设备和移动应用的一般性攻击和防御脚本。
  • 开发面向客户的网络安全攻击和防御演示。
  • 与团队合作,设计涉及不仅移动设备,还包括其他联网组件的安全解决方案架构,利用认证协议(OAuth2、FIDO2 等),并根据需要理解和评估加密协议和算法。

要求

  • 具备 5 年以上相关领域经验。
  • 熟悉操作系统内部原理(Android、iOS、Harmony OS Next、Linux 等之一或多个)和应用开发(尤其是移动应用)。
  • 熟悉 Root/越狱、运行时篡改、应用篡改以及可用于隐藏这些行为的工具。
  • 熟悉攻击和逆向工程工具,如 Frida、Theos、Ghidra 和 IDA Pro。
  • 熟悉 Web VAPT 工具,如 Burp Suite。
  • 熟悉各种工具和方法论的工作原理,能够实现创新和创意解决方案。
查看英文原文

Summary of Role
V-Key is one of the world’s leading deep-tech companies in mobile cyber-security. Our patented technology V-OS has been deployed by top banks, mobile payment providers, and governments to secure software solutions and protect more than 500 million users globally.
We are rapidly expanding into new markets and new customer segments. Apart from securing digital transactions for everyone, we are also enabling new generation technology by providing the cyber-security infrastructure for banking, government and smart homes, among many others.
At V-Key, we are building towards a future where technology users can enjoy unprecedented security and convenience.
We are looking for a (Senior or Lead) Security Researcher, as part of the Product Security Team. Your primary focus will be to work with the team on cutting-edge Research and Development (R&D) of threats on mobile phones to develop innovative products and solutions to defend against such threats.
Duties and Responsibilities

  • Research into threats (such as root/jailbreak and hiding thereof, app tampering, runtime tampering, etc.) in mobile phone operating systems and applications on Android / iOS / Harmony OS Next.
  • Work with the team to develop protection mechanisms through reverse engineering, vulnerability research, exploitation and mitigation techniques and mobile/embedded development.
  • Work with the team to perform penetration test on V-Key’s products and applications.
  • Work with the team to script attacks and defences for mobile devices in general and for mobile applications.
  • Develop customer-facing security attack and defense demonstrations.
  • Work with the team on security solutions architectures involving not just the mobile device, but also other networked components, leveraging authentication protocols (OAuth2, FIDO2, etc.), and understanding and assessing cryptographic protocols and algorithms as needed.

Requirements

  • Should have 5+years of experience into this relevant field.
  • Good understanding of operating system internals (one or more of Android, iOS, Harmony OS Next, Linux, etc.) and app development (especially mobile).
  • Familiar with rooting/jailbreaking, runtime tampering, app tampering, and tools that can be used to hide them.
  • Familiar with attack and reverse engineering tools such as Frida, Theos, Ghidra, and IDA Pro.
  • Familiar with web VAPT tools like Burp Suite.
  • Familiar with how various tools/methodologies work, allowing innovation and creative solutions, not just comfortable using the tools as is.
  • Good understanding of threat modelling, including familiarity with at least one threat modelling framework.
  • A strong self-starter and able to work with minimal supervision, while still receptive to suggestions and ways to improve.
  • Project ownership on selected projects.
  • Guidance/mentorship of junior security researchers.
  • Detail oriented with a strong focus on quality.
  • Systematic and methodical in research and testing, while being creative and innovative.
  • Ability to work in a dynamic, fast moving and growing environment.
  • Positive work attitude, proactive and highly driven.
  • Critical thinker and problem-solving skills.
  • Team player with great interpersonal and communication skills.

Nice to have

  • Degree in Computer Science, Information Systems, Math (especially related to cryptography) or related field.
  • Certifications related to information security, ethical hacking, security solution design.
  • Have built tools/scripts to help with various security research tasks.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位