亚马逊Security Engineer, AWS Marketplace China, AWS Marketplace China
任职要求
基本任职资格 - 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience - 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience - 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience - Bachelor's degree in computer science or equivalent - Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security 优先任职资格 - 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience - 2+ years of scripting, programming, or …
工作职责
In this role, a commitment to teamwork, customer focus, and strong communication skills (for both technical and business partners) are absolute requirements. Job responsibilities include defining customer use cases and requirements, designing and prototyping security solutions, driving security value into software services, educating customers on product features and best practices, and educating stakeholders on best practices and standards. Successful candidates will be strong leaders who are well versed in vulnerability detection and management, vulnerability remediation tools and practices, and compliance standards and government certifications. Additionally, successful candidates will be excellent communicators, have a history of successful collaboration with development teams, and be experienced prototyping security software solutions.
The Role We’re looking for highly motivated Application Security engineers with an adversarial mindset to help strengthen Tesla’s overall security posture. You'll get hands-on with a wide array of technologies – including websites, robots, and energy systems – and learn how they interconnect, where they fail, and how to make them stronger. In this role, you’ll emulate both internal and external threat actors to uncover weaknesses across our most critical products and infrastructure. From designing real-world attack scenarios to conducting deep technical assessments, your work will directly shape how we defend systems at scale. If you’re passionate about CTFs, vulnerability research, exploit development, or just love “breaking things” to understand them better, this role is for you. Whether it’s writing custom tooling, crafting a successful phishing campaign, or gaining domain admin, you’ll have the freedom to get creative. You’ll be operating in a high-impact, complex environment spanning thousands of systems, services, and endpoints. At Tesla, you’ll use your offensive skills to drive meaningful change and contribute to one of the most ambitious roadmaps in tech today. Responsibilities • Breaking everything you touch and helping us fix it. • Conducting penetration tests against Tesla networks, applications and services. • Conduct proactive Application Security exercises to simulate real-world external adversaries and insider threats, identifying vulnerabilities and assessing the effectiveness of organizational cybersecurity defenses. • Performing security assessments on third-party services and software. • Collaborating cross functionally with engineers to develop secure services. • Auditing source code for security vulnerabilities. • Develop/implement automated systems to help spot known security exposures.
1.负责对研发中心安保公司的日常工作进行管理和考核; 2.评估安防日常运营存在的风险,对发生的安防事件进行追踪调查和后续改进; 3.负责定期举行紧急事故的处理演练及风险评估和应急事件的处理; 4.安防系统进行日常维护; 5.与其他部门的沟通与协作。
• Manage daily operations of enterprise cloud platforms (Tencent Cloud) including resource provisioning, deployment, monitoring and incident resolution to ensure the stability of business systems; • Deploy cloud-native infrastructure components, e.g. VPCs, subnets, routing, computing, storage and load balancing services • Build and manage containerized environments e.g. Tencent TKE • Enforce security best practices across public cloud environments including network segmentation, encryption, IAM and etc. • Maintain access control policies under Tencent CAM and Group Account Management • Ensure compliance with MLPS v2.0
1. 内部数据梳理与标准化:全面梳理公司内部应用系统现状,明确数据流转路径及存储分布;主导内部结构化数据(日志、数据库数据等)与非结构化数据(内部文档、报表等)的收集、整理、清洗及格式化,搭建标准化数据体系; 2. 大模型应用与训练:基于多模态大模型技术,对梳理后的结构化、非结构化数据进行模型训练、调优及迭代,优化模型对内部数据的理解与分析能力,确保模型适配公司内部数据场景; 3. AI异常行为检测与告警智能体搭建:利用训练后的大模型,对内部数据访问、操作行为进行实时监测,落地预警智能体,开展异常行为数据分析,建立精准的告警机制,及时发现数据泄露风险并联动处置; 4. 自动化安全审计:基于AI技术框架,搭建内部自动化审计平台,提高审计效率; 5. 项目管理与交付:具备完整项目管理能力,牵头负责内部数据安全AI防护相关项目,制定项目计划、协调资源,带领内部员工及外部供应商推进项目实施,确保项目按时、按质完成交付,达成数据安全防护目标; 6. 技术跟踪与内部落地:及时跟踪业界AI最新技术、架构及应用案例,定期在内部开展技术分享,传递前沿动态;结合部门业务需求,探索AI技术在部门内部的落地实践,挖掘技术应用价值,助力部门工作效率与技术能力提升。