Skip to main content

安全运维(Security Operation )

Technology
梅赛德斯-奔驰租赁有限公司
北京市, 中国¥20,000 - ¥40,000 /月1周前截至 2026/10/28
全职

职位描述

该职位来源于猎聘 Objective of job To safeguard the organization's information assets by proactively managing security risks, effectively responding to incidents, and continuously improving the overall security posture. -Protect the organization's information assets by maintaining confidentiality, integrity, and availability. -Proactively identify, assess, and mitigate security risks and vulnerabilities. -Lead and coordinate effective responses to security incidents, minimizing impact and ensuring timely recovery. -Continuously improve the organization's security posture through proactive monitoring, analysis, and implementation of security best practices. -Ensure compliance with relevant security standards, regulations, and policies. Job designation

  • Security Incident Management
  • Monitor and respond to security incidents in alignment with incident response protocols. -Lead incident response efforts to ensure timely containment, eradication, and recovery from security threats. -Conduct thorough investigations of security incidents, including log analysis, host-based and network forensic investigations, to determine the root cause and impact. -Develop incident analysis and findings reports for management, including gap identification and recommendations for improvement. -Coordinate investigation, containment, and other response activities with business stakeholders and groups.
  • Vulnerability Management -Conduct vulnerability assessments and manage remediation efforts. -Continually identify, assess, report on, manage, and remediate vulnerabilities across endpoints, workloads, and systems.
  • Security Operations
  • Fine-tune incident detection and alert-triggering rules to minimize false positives and improve detection accuracy. -Analyze and improve security measures by assessing and updating policies, configurations, and procedures. -Maintain situational awareness by tracking emerging threats, attack patterns, and tactics, techniques, and procedures -Develop and maintain documentation, playbooks, and standard operating procedures. -Perform onboarding of new team members and facilitate smooth integration. -Help develop processes used for internal and external planning and collaboration. -Provide technical and administrative support for day-to-day operations.
  • Collaboration and Communication
  • Collaborate with IT and RD application teams to ensure security is integrated into all stages of the software development lifecycle. -Provide security training and awareness programs for employees. -Communicate security status, risks, and incidents to executive leadership and other key stakeholders. Qualification
  • Technical Skills and Knowledge: -Strong understanding of security operations concepts, incident response methodologies, and vulnerability management principles. Hands-on experience administering and configuring security tools such as SIEM, SOAR, firewalls, intrusion detection/prevention systems, and vulnerability scanners. -Familiarity with scripting languages (e.g., Python, PowerShell) for task automation and tool customization. -Knowledge of cloud platforms such as AWS, Azure, Ali Cloud or other cloud platform. -Strong analytical and troubleshooting skills for rapid issue resolution under pressure. -Excellent communication skills, both written and verbal, for technical and executive audiences. -Adaptability and resilience in the face of evolving cyber threats.
  • Proficiency in security frameworks and various compliance standards like ISO 27001, SOC, NIST, etc.
  • Relevant certifications, CISA, CISSP, CISM
  • > 5 years experience in security operations, incident response, threat detection and analysis, or similar roles
  • Education: Bachelor's degree and above in Computer Science encompassing Information Security 职位目标(Objective of Job) 通过主动管理安全风险、有效响应安全事件,并持续提升整体安全能力,保障组织的信息资产安全。 通过确保机密性、完整性和可用性(CIA)来保护组织的信息资产 主动识别、评估并缓解安全风险和漏洞 牵头并协调安全事件响应,降低影响并确保及时恢复 通过持续监控、分析及实践实施,不断提升整体安全水平 确保符合相关安全标准、法规及公司政策 岗位职责(Job Designation) 1. 安全事件管理(Security Incident Management) 按照事件响应流程监控并处理安全事件 主导安全事件响应,确保威胁得到及时遏制、清除并完成恢复 对安全事件进行深入调查,包括日志分析、主机取证及网络取证,定位根因并评估影响 编写事件分析报告,输出问题差距及改进建议 与业务相关团队协作,协调调查、遏制及应对工作 2. 漏洞管理(Vulnerability Management) 执行漏洞评估并推动漏洞修复工作 持续识别、评估、报告并管理终端、系统及工作负载中的漏洞 3. 安全运营(Security Operations) 优化告警规则及检测机制,减少误报,提高检测准确率 通过评估并更新策略、配置与流程来提升安全防护能力 跟踪新兴威胁、攻击模式及攻防技术(TTPs),保持态势感知 编写并维护安全文档、操作手册(Playbook)及标准流程(SOP) 负责新成员的入职培训及团队融入 支持内部及外部协作流程建设 提供日常运营所需的技术和管理支持 4. 协作与沟通(Collaboration and Communication) 与IT及研发团队协作,将安全融入软件开发全生命周期(SDLC) 为员工提供安全培训及意识提升项目 向管理层及关键利益相关方汇报安全状态、风险及事件 任职资格(Qualification) 技术能力与知识 深入理解以下领域: 安全运营(Security Operations) 事件响应方法论(Incident Response) 漏洞管理(Vulnerability Management) 具备以下安全工具实际操作经验: SIEM、SOAR 防火墙 入侵检测/防御系统(IDS/IPS) 漏洞扫描工具 熟悉脚本语言(如 Python、PowerShell)用于自动化与工具定制 熟悉云平台(如 AWS、Azure、阿里云等) 具备较强的分析与故障排查能力,能在压力下快速解决问题 出色的沟通能力(书面及口头),可覆盖技术及管理层场景 能适应快速变化的网络安全威胁环境 标准与认证 熟悉安全框架及合规要求,如 ISO 27001、SOC、NIST 等 持有相关认证优先:CISA、CISSP、CISM 工作经验 5年以上安全运营、事件响应、威胁检测与分析或相关领域经验

Keywords
monthsOfExperience: 60ArcSDEPowershellPythonVulnerabilityAWS

对这个职位感兴趣吗?