Security Analyst - Shanghai
招聘 | Riscure中国诚邀您的加入
Riscure公司成立于2001年,是全球芯片侧信道安全领域的先驱与技术和市场领导者。经历了近20年的发展,Riscure公司的安全测评服务及测试工具经过全球范围广泛客户的使用和验证,具有很高的可靠性、易操作性和成熟稳定性。Riscure为扩展全球业务,于2017年12月在中国设立分部——安试酷信息科技(上海)有限公司。为了更好的为客户提供包括安全工具、评估和认证服务在内的本地化服务,现特招以下职位:
职位:安全分析师
工作地点:上海
工作内容:
- 通过对客户产品的漏洞分析和渗透测试进行安全评估
- 详细的安全报告, 帮助客户了解已识别的威胁并加以修复
- 研究新的攻击和开发新的测试工具方法
技能及要求:
- 计算机科学、计算机工程、通信工程或电气工程学士 (硕士优先)
- 能够独立完成工作, 无需监督
- 流利的中文 (普通话) 和英语, 良好的读写能力
- 有良好的写作技能
- 热爱技术工作,有钻研精神;工作的核心是深入挖掘设备的硬件和软件的技术细节
- 良好的社交和沟通能力
- 可以满足少量的国际和国内出差需求
- 有安全分析师及安全工程师工作经验的,或有芯片嵌入式系统工程师或开发人员经验的优先考虑
其他技能:
应聘者至少需要满足以下技能中的某些要求,
- 编程语言: 至少能够熟练使用C/C++, Python, java, 汇编, VHDL, Verilog其中一个。
- 了解ARM, MIPS 或Intel的源代码并能进行反汇编
- 针对 Android、iOS 或 Linux 的调试和检测。
- 能识别和利用软件漏洞的经验, 无论是否有访问来源。
- 电子、嵌入式系统、芯片设计和密码学方面的基本知识。
- 在芯片安全性和智能卡安全性方面的经验
- 有侧信道分析和故障注入经验
请将您的简历发送到以下邮箱:
Riscure is looking for an experienced Security Analyst to join our office in Shanghai, China.
Tasks:
- Conducting security assessments through vulnerability analysis and penetration testing on the customer’s products.
- Elaborate detailed security reports that will help the customer to understand the identified threats and fix them
- Research new attacks and develop new testing tools/methodologies.
General skills and requirements:
- Bachelor (Master preferred) in Computer Science, Computer Engineering, Telecommunication Engineering or Electrical Engineering.
- Ability to work independently and without supervision.
- Fluently speak in Chinese (mandarin) and English, good in reading and writing.
- Technical writing abilities are required.
- The candidate must love technology and when working, the candidate doesn’t mind getting hands dirty: the core of our work is digging deep into the technical details of both hardware and software of devices.
- Good social and communication skills
- Flexibility and availability for travelling, occasionally international travel
- Experience as security analyst or security engineer is highly recommended. Experience as chip/embedded system engineer or developer will be also considered.
Technical skills:
The candidate does not need to meet all the following skills, but at least some of them are required to be considered for the position.
- Programming languages: at least one of C, Python, Java, Assembly, VHDL, Verilog.
- Experience disassembling and reversing software for ARM, MIPS or Intel.
- Debugging and instrumentation for Android, IOS or Linux.
- Experience identifying and exploiting software vulnerabilities, with and without access to the sources.
- Basic knowledge on electronics, embedded systems, chip design and cryptography.
- Experience on chip security and smartcard security.
- Experience on Side Channel Analysis and Fault Injection.
Interested?
Send your resume and motivation letter to hrCN@riscure.com If you have any hardware project, source code, academic thesis, whitepaper, or anything else that is relevant and that you’re proud of, don’t hesitate add a link to it as well.