全栈工程师(网络安全):关于CI/CD流程的反馈
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
WHAT WE'RE RESEARCHING
我们正在开展一项关于全栈开发与网络安全实践交叉领域的付费研究。我们的目标是了解工程团队如何将漏洞验证直接集成到他们的 CI/CD 流水线中。此反馈将有助于塑造未来旨在简化安全应用功能所有权的开发者工具。
HOW IT WORKS
在一次远程视频会议中,您将向我们展示一个您负责应用开发和漏洞验证的近期项目。您将被要求描述您当前的 CI/CD 设置,并突出显示您为确保安全部署所采取的具体步骤。随后我们会向您展示一些概念性的工作流程,并征求您对其实用性的坦率反馈。对话将按照标准技术面试的方式进行,重点在于您的日常安全流程。
WHO THIS IS FOR
我们欢迎在网络安全方面有专门关注或深厚背景的全栈工程师。您应具备管理应用功能、配置 CI/CD 流水线以及在生产前验证漏洞的实际经验。我们也欢迎从事类似部署流水线的 DevSecOps 工程师和以安全为重点的后端开发人员。
WHAT YOU'LL DO
- 向我们展示您将漏洞验证集成到 CI/CD 流水线中的流程
- 讨论您如何在应用功能开发与严格的安全要求之间取得平衡
- 对于管理及部署安全全栈应用的新概念做出反应
- 描述您在保护生产流水线时遇到的最近挑战
WHO SHOULD APPLY
- 全栈工程师、DevSecOps 工程师或类似职位的专业经验
- 网络安全和应用安全实践的扎实背景
- 配置和维护 CI/CD 流水线的实际经验
- 能够讨论漏洞验证和安全部署流程
COMPENSATION
每小时 105 美元
READY TO PARTICIPATE?
立即开始您的付费面试 https://terac.com/interview/start/r/905d5706-56a4-4973-9736-73a30a3ca874?utm_source=ashby_listing_description
ABOUT TERAC
Terac 正在构建全球最大的经过审核的人类专家池,用于人工智能。研究人员、AI 实验室和产品团队使用 Terac 在各个行业、语言和技能水平上招募、筛选和支付研究参与者。
了解更多请访问 terac.com https://terac.com 或在 YouTube 上关注 @jointerac https://www.youtube.com/@jointerac.
查看英文原文
WHAT WE'RE RESEARCHING
We're running a paid study on the intersection of full-stack development and cybersecurity practices. Our goal is to understand how engineering teams integrate vulnerability verification directly into their CI/CD pipelines. This feedback will help shape future developer tools designed to streamline secure application feature ownership.
HOW IT WORKS
During a remote video session, you will walk us through a recent project where you owned both application development and vulnerability verification. You will be asked to describe your current CI/CD setup, highlighting the specific steps you take to ensure secure deployments. We will then show you a few conceptual workflows and ask for your candid feedback on their practicality. The conversation flows as a standard technical interview, focusing on your day-to-day security routines.
WHO THIS IS FOR
We welcome full-stack engineers who have a dedicated focus or strong background in cybersecurity. You should have hands-on experience managing application features, configuring CI/CD pipelines, and verifying vulnerabilities prior to production. We also welcome DevSecOps engineers and security-focused backend developers who handle similar deployment pipelines.
WHAT YOU'LL DO
- Walk us through your process for integrating vulnerability verification into CI/CD pipelines
- Discuss how you balance application feature development with rigorous security requirements
- React to new concepts for managing and deploying secure full-stack applications
- Describe a recent challenge you faced while securing a production pipeline
WHO SHOULD APPLY
- Professional experience as a full-stack engineer, DevSecOps engineer, or similar role
- Strong background in cybersecurity and application security practices
- Hands-on experience configuring and maintaining CI/CD pipelines
- Comfortable discussing vulnerability verification and secure deployment workflows
COMPENSATION
$105 per hour
READY TO PARTICIPATE?
Start your paid interview now https://terac.com/interview/start/r/905d5706-56a4-4973-9736-73a30a3ca874?utm_source=ashby_listing_description
ABOUT TERAC
Terac is building the world's largest pool of vetted human experts for AI. Researchers, AI labs, and product teams use Terac to recruit, screen, and pay study participants across industries, languages, and skill sets.
Learn more at terac.com https://terac.com or on YouTube at @jointerac https://www.youtube.com/@jointerac.