Skip to main content

Security Analyst 信息安全分析师

Technology
梅赛德斯-奔驰租赁有限公司
北京市, 中国¥15,000 - ¥40,000 /月1周前截至 2026/10/31
全职

职位描述

该职位来源于猎聘 Beijing Objective of job (abbreviated) To protect organizational assets and maintain business continuity by driving end-to-end incident management—rapidly detecting, triaging, containing, and remediating cybersecurity incidents, minimizing impact, and leveraging post-incident root cause analysis to continuously strengthen resilience.

  • Lead and support security incident investigation, including digital forensics, malware analysis, root cause analysis, and threat remediation activities.
  • Proactively identify, investigate, and mitigate security threats through log analysis, threat hunting, vulnerability assessment, and security analytics.
  • Develop, optimize, and maintain security detection use cases, correlation rules, and response playbooks based on threat intelligence, attack techniques, and security requirements.
  • Enhance the security operations to ensure continuous monitoring, threat detection, and timely response to security events.
  • Continuously improve security operational efficiency through automation, process optimization, and adoption of security best practices and industry frameworks.

    Qualification Technical Skills and Knowledge: -Comprehensive experience in cyber security incident response process and handling. -Hands-on experience with at least one SIEM platform, such as: Splunk, IBM QRadar, Elastic Stack for rapid event correlation, threat containment, and remediation. -Experience with one or more of the following security tools: EDR, IDS / IPS, WAF, Firewalls. -Strong log analysis skills, including: Windows Event Logs, EDR Logs, Network traffic logs, Cloud security logs.

  • Better with experience in digital forensics to determine root cause. -Proficiency in scripting languages such as Python or Shell for security automation. -Relevant certifications, GCIH, GCFA, GREM, OSCP > 3 years experience in security operations, incident response, threat detection and analysis, or similar roles Education: Bachelor's degree and above in Computer Science encompassing Information Security 信息安全分析师(Security Analyst) 工作地点:北京 通过推动端到端的安全事件管理,保护组织资产并保障业务连续性,包括快速发现、分级、遏制和处置网络安全事件,将业务影响降至,并通过事件后的根因分析持续提升组织的安全韧性。 主要职责 主导并支持安全事件调查工作,包括数字取证(Digital Forensics)、恶意软件分析(Malware Analysis)、根因分析(Root Cause Analysis)以及威胁处置与修复活动。 通过日志分析、威胁狩猎(Threat Hunting)、漏洞评估(Vulnerability Assessment)和安全分析,主动识别、调查并缓解安全威胁。 基于威胁情报、攻击技术及安全需求,设计、优化和维护安全检测用例(Use Cases)、关联分析规则(Correlation Rules)以及响应预案(Response Playbooks)。 持续提升安全运营能力,确保对安全事件进行全天候监控、威胁检测和及时响应。 通过自动化建设、流程优化以及采用行业实践和安全框架,不断提升安全运营效率。 任职资格 技术能力与专业知识 具备全面的网络安全事件响应(Incident Response)流程及处置经验。 熟悉并具备至少一种 SIEM(安全信息与事件管理)平台的实操经验,例如: Splunk IBM QRadar Elastic Stack 能够利用相关平台进行快速事件关联分析、威胁遏制和安全事件处置。 具备以下一种或多种安全工具的使用经验: EDR(终端检测与响应) IDS / IPS(入侵检测/防御系统) WAF(Web 应用防火墙) 防火墙(Firewalls) 具备较强的日志分析能力,包括但不限于: Windows 事件日志(Windows Event Logs) EDR 日志 网络流量日志(Network Traffic Logs) 云安全日志(Cloud Security Logs) 具备数字取证经验者优先,能够开展安全事件根因分析。 熟练掌握 Python、Shell 等脚本语言,并能够用于安全自动化开发。 持有以下相关安全认证者优先: GCIH(GIAC Certified Incident Handler) GCFA(GIAC Certified Forensic Analyst) GREM(GIAC Reverse Engineering Malware) OSCP(Offensive Security Certified Professional) 工作经验 3年以上以下领域相关工作经验: 安全运营(Security Operations) 事件响应(Incident Response) 威胁检测与分析(Threat Detection & Analysis) 或类似网络安全岗位 教育背景 计算机科学相关专业本科及以上学历,专业方向涵盖信息安全(Information Security)领域。

Keywords
monthsOfExperience: 36MongodbElasticsearchWafPythonVulnerabilityXcasMalwareShell script

对这个职位感兴趣吗?