远程工作雷达

信息安全部门

InfoSec

开发工程限定地区(需当地身份)
公司Hexaware Technologies Limited
薪资$80 - $85
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位 :: 威胁建模师
费率 - C2C 每小时 80-85 美元

地点 :: 远程

职责:

  • 开发培训材料,说明如何使用威胁管理服务、利用技术并解读发现的问题。
  • 通过支持开发人员为其应用程序创建威胁模型并修复潜在威胁,推动业务中的安全改进,平衡风险与业务需求。
  • 支持安全架构团队,通过定义流程、程序、控制措施、关键风险指标(KRI)/关键绩效指标(KPI)等,发展和成熟应用威胁建模计划,从而在开发早期识别威胁,降低部署前的风险。
  • 与信息安全部门合作制定信息安全战略和路线图,包括以威胁建模为重点;与企业架构、IT及业务部门保持联络,提供持续输入和意识提升。
  • 提供建议并参与战略和路线图的制定。

资格要求:

  • 5-7 年网络安全、内部威胁、情报机构、联邦执法或相关领域的相关经验
  • 对访问控制和认证机制、PKI 和密码学有深入理解
  • 有开发技术威胁模型的实际经验
  • 有进行安全代码审查并向项目团队解释结果的实际经验
  • 对协议、网络、防火墙、缓存、VIP、代理、Web 应用和数据库系统有深入了解
  • 有 AWS 使用经验
  • 熟悉以下几种编程语言之一:Java、C#、Python、C++、Node.JS、JavaScript
  • 熟悉以下前端框架之一:React、Angular、Ember、Vue
  • 至少 2 年作为信息安全威胁建模专家的高级经验
  • 至少 2 年作为信息安全专业人员的经验,最好是在架构或工程领域

期望具备:

  • 能够提供 CVE 已提交的参考、漏洞赏金用户名或 GitHub 仓库
  • 拥有与 AWS、GCP 或 Azure 相关的安全认证之一
  • CISSP(+ ISSAP)、CCSP、CEH、OSCP、CSSLP

成功胜任此职位的关键因素:

  • 强大的书面和口头沟通能力
  • 能够指导和培养团队成员
  • 自主性强,候选人必须能够预判任务并采取行动
  • 出色的演示能力、项目管理能力
查看英文原文

Role :: Threat Modeler
Rate - $80-85/hr. on C2C

Location :: Remote

Responsibilities:

  • Develop training material for how to engage the Threat Management service, make use of technologies, and interpret findings.
  • Drive beneficial security change into the business through supporting Developers with creation of threat models for their applications and remediation of potential threats, balancing risk against business need.
  • Support the Security Architecture team to develop and mature an Application Threat Modeling Program by defining processes, procedures, controls, KRI’s/KPI’s, etc., that identify threats early in the development process reducing risks prior to deployment.
  • Work with the InfoSec functional teams in the development of the Information Security strategy and roadmap, including and with focus on Threat Modeling; liaison and consult with Enterprise Architecture, IT and the business for ongoing input and awareness
  • Advise and Contribute to Strategy and Roadmaps

Qualifications:

  • 5-7 years related experience in Cyber Security, Insider Threat, Intelligence Community, Federal Law Enforcement, or a related field
  • Strong understanding of access controls and authentication mechanisms, PKI, and cryptography
  • Demonstrated experience developing technical threat models
  • Demonstrated experience performing security code reviews and explaining results to project teams
  • Strong understanding of protocols, networking, firewalls, caching, VIPs, proxies, web applications, and database systems
  • Experience with AWS
  • Knowledge of several of the following programming languages; Java, C#, Python, C++, Node.JS, JavaScript
  • Knowledge in one or several of the following Frontend frameworks; React, Angular, Ember, Vue
  • Minimum of 2 years’ experience working as an Information Security Threat Modeling subject matter expert at a senior level
  • Minimum of 2 years’ experience working as an Information Security Professional, preferably within the architecture or engineering disciplines

Desirable:

  • Able to provide references to CVEs filled, Bug Bounty Username, or GitHub repositories
  • One or more security-related certifications associated with AWS, GCP, or Azure
  • CISSP (+ ISSAP), CCSP, CEH, OSCP, CSSLP

Keys to Success in this Role:

  • Strong written and verbal communication skills
  • Able to mentor and guide team members
  • Self-starter, candidate must be able to anticipate tasks and take action
  • Excellent presentation, program management and relationship management skills

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位