Cybersecurity Architect - APAC
江森自控投资有限公司ShanghaiUpdate time: August 26,2019
Job Description
上海市

RESPONSIBILITY LEVEL:


Clarios is
looking for an experienced Cybersecurity Architect with good
communication skills to join our global team of information technology
professionals. This role will be a part of the Information Security team and
will be responsible for assessing, designing, resolving and integrating information
security into information technology solutions. As a Cybersecurity Architect
you will be responsible for increasing security awareness among project teams
and making information technology solutions more robust and secure. You will
work with the Demand office, Enterprise Architecture and IT leadership and be
responsible for mentoring and driving them through the security assessments and
adopting secure solution design principles.


Perform
security assessments for on-going projects: both Architecture and
Implementation/Code Review
Contribute
in building secure architecture for the new projects or making corrections to existing
ones
Consult
on all 3rd-party application security penetration testing
Consult
on vulnerability response process, impact assessments and remediation plans
Recommend
design and code changes to meet product security objectives and remedy security
findings
Perform
unit-test if needed to verify a remediation or provide a proof-of-concept as
evidence of a vulnerability
Work
as a security advisor helping to establish secure development activities during
solution development
Communicate
with customers and teams, be able to convey the message about importance of
security, the ways of establishing it and the wrong ways of enforcing it (e.g.
do pen testing before release)

DUTIES:


Knowledge
of at least one Security Development methodologies (e.g. Microsoft SDL, OWASP
CLASP etc)
Knowledge
of main Security-related activities in development such as Risk and Privacy
Assessment, Threat Modeling, Security Code Review
Deep
understanding of the nature of security threats and their classification
Knowledge
of most common implementations of the Threats (e.g. XSS, SQL Injection, XSRF,
buffer overruns, brute force, rainbow tables, DoS etc) and how they match the
general classification
Understanding
of main security principles, such as multi-layered protection (Defense in
Depth)
Understanding
of main areas of protection (Security, Privacy, Availability) and levels of
defense (networking, infrastructure, OS, Application)
Understanding
of mitigation mechanisms for every type of threats (e.g. validation, sanitizing,
crypto-operations etc)
Good
knowledge of Security Features and Mechanisms provided by at least one OS (e.g.
Windows, Linux, Android, iOS etc) and development platform/technologies (e.g.
Java, .NET Framework, databases etc)
Familiarity
with existing security standards (e.g. PCI DSS, HIPAA, NIST, Common Criteria
etc) and what does it mean to implement compliance with them
Familiarity
with the tools for various security activities: Static Code Analysis, Pen
Testing, Intrusion Detection/Prevention etc
Experience
with VAPT and familiarity with common security vulnerabilities, the lexicon of
findings (CVSS, CVE), ability to assess severity, etc
Understanding
of basic principles of infrastructure security and penetration testing
Ability
to use the tools to perform actual attacks is a plus

REQUIREMENTS/QUALIFICATIONS:


Bachelor’s
degree or related experience in Computer Science, Engineering or related
discipline.
Strong
experience with MS Visio, PowerPoint, MS Word and MS Excel.
Minimum
5 years of experience, designing, implementing and supporting large-scale, information
security environments.
Professional
certification in relevant disciplines preferred: CISSP, CISA, CEH, Etc.
Strong
people management skills with global experience.
Strong
technical and non-technical communication skills.
Ability
to establish and maintain high levels of client trust and confidence.

职能类别:网络信息安全工程师系统架构设计师

微信分享

联系方式

上班地址:上海长宁区福泉北路518号-11


部门信息

所属部门:上海江森自控国际蓄电池有限公司长宁分公司
上海江森自控国际蓄电池有限公司 为江森自控集团于2005年在华投资收购的全资子公司,专业生产并销售汽车用上百种规格的蓄电池产品, 获得多类奖项与荣誉。目前上海江森自控国际蓄电池有限公司拥有中国领先的乘用车配套市场份额,同时经销商网络已经覆盖国内所有区域,以其先进的质量,管理与服务体系领导中国市场。

江森自控集团作为全球知名的蓄电池供应商,其拥有的VARTA品牌创始于1888年德国的汉诺威市,即现今江森自控蓄电池技术研发中心的所在地之一。长久以来VARTA品牌系列都是世界各大著名汽车制造商的首选,以其高端的质量与领先的技术提供适合各类型车辆使用的多种规格的蓄电池产品。目前VARTA品牌为欧洲所有的汽车制造商提供相应的配套服务,2004年在欧洲的配套市场份额高达50 %,同时也是欧洲售后市场的领导者。 2005年,VARTA品牌产品正式在上海江森自控蓄电池有限公司投入生产,将全球蓄电池专家的产品与技术引领进中国。VARTA Asia是江森自控集团针对中国汽车使用特性与需求,在其优良的技术基础上推出的免维护蓄电池产品系列,以期服务中国广大的汽车用户。

Get email alerts for the latest"Cybersecurity Architect - APAC jobs in Shanghai"