信息安全部门
InfoSec
开发工程限定地区(需当地身份)
公司Hexaware Technologies Limited
薪资$80 - $85
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
职位 :: 威胁建模师
费率 - C2C 每小时 80-85 美元
地点 :: 远程
职责:
- 开发培训材料,说明如何使用威胁管理服务、利用技术并解读发现的问题。
- 通过支持开发人员为其应用程序创建威胁模型并修复潜在威胁,推动业务中的安全改进,平衡风险与业务需求。
- 支持安全架构团队,通过定义流程、程序、控制措施、关键风险指标(KRI)/关键绩效指标(KPI)等,发展和成熟应用威胁建模计划,从而在开发早期识别威胁,降低部署前的风险。
- 与信息安全部门合作制定信息安全战略和路线图,包括以威胁建模为重点;与企业架构、IT及业务部门保持联络,提供持续输入和意识提升。
- 提供建议并参与战略和路线图的制定。
资格要求:
- 5-7 年网络安全、内部威胁、情报机构、联邦执法或相关领域的相关经验
- 对访问控制和认证机制、PKI 和密码学有深入理解
- 有开发技术威胁模型的实际经验
- 有进行安全代码审查并向项目团队解释结果的实际经验
- 对协议、网络、防火墙、缓存、VIP、代理、Web 应用和数据库系统有深入了解
- 有 AWS 使用经验
- 熟悉以下几种编程语言之一:Java、C#、Python、C++、Node.JS、JavaScript
- 熟悉以下前端框架之一:React、Angular、Ember、Vue
- 至少 2 年作为信息安全威胁建模专家的高级经验
- 至少 2 年作为信息安全专业人员的经验,最好是在架构或工程领域
期望具备:
- 能够提供 CVE 已提交的参考、漏洞赏金用户名或 GitHub 仓库
- 拥有与 AWS、GCP 或 Azure 相关的安全认证之一
- CISSP(+ ISSAP)、CCSP、CEH、OSCP、CSSLP
成功胜任此职位的关键因素:
- 强大的书面和口头沟通能力
- 能够指导和培养团队成员
- 自主性强,候选人必须能够预判任务并采取行动
- 出色的演示能力、项目管理能力
查看英文原文
Role :: Threat Modeler
Rate - $80-85/hr. on C2C
Location :: Remote
Responsibilities:
- Develop training material for how to engage the Threat Management service, make use of technologies, and interpret findings.
- Drive beneficial security change into the business through supporting Developers with creation of threat models for their applications and remediation of potential threats, balancing risk against business need.
- Support the Security Architecture team to develop and mature an Application Threat Modeling Program by defining processes, procedures, controls, KRI’s/KPI’s, etc., that identify threats early in the development process reducing risks prior to deployment.
- Work with the InfoSec functional teams in the development of the Information Security strategy and roadmap, including and with focus on Threat Modeling; liaison and consult with Enterprise Architecture, IT and the business for ongoing input and awareness
- Advise and Contribute to Strategy and Roadmaps
Qualifications:
- 5-7 years related experience in Cyber Security, Insider Threat, Intelligence Community, Federal Law Enforcement, or a related field
- Strong understanding of access controls and authentication mechanisms, PKI, and cryptography
- Demonstrated experience developing technical threat models
- Demonstrated experience performing security code reviews and explaining results to project teams
- Strong understanding of protocols, networking, firewalls, caching, VIPs, proxies, web applications, and database systems
- Experience with AWS
- Knowledge of several of the following programming languages; Java, C#, Python, C++, Node.JS, JavaScript
- Knowledge in one or several of the following Frontend frameworks; React, Angular, Ember, Vue
- Minimum of 2 years’ experience working as an Information Security Threat Modeling subject matter expert at a senior level
- Minimum of 2 years’ experience working as an Information Security Professional, preferably within the architecture or engineering disciplines
Desirable:
- Able to provide references to CVEs filled, Bug Bounty Username, or GitHub repositories
- One or more security-related certifications associated with AWS, GCP, or Azure
- CISSP (+ ISSAP), CCSP, CEH, OSCP, CSSLP
Keys to Success in this Role:
- Strong written and verbal communication skills
- Able to mentor and guide team members
- Self-starter, candidate must be able to anticipate tasks and take action
- Excellent presentation, program management and relationship management skills
Originally posted on Himalayas
本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。
本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。