阿里巴巴安全工程师
实习兼职阿里国际2026届实习生招聘地点:北京 | 杭州状态:招聘
任职要求
【具备以下任一项即可】 1、了解Linux系统管理和网络管理相关操作,了解Linux系统的安全漏洞,有Linux exploit code/shellcode编写经验; 2、熟知Web安全,了解当前流行的Web漏洞(XSS, SQL Injection, CSRF, etc),了解Java开发框架(Struts, Spring, iBATIS, Hibernate, etc); 3、具备Windows客户端安全攻防的经验,或了解Android/iOS无线客户端安全; 4、熟识计算机网络和路由交换原理,熟悉企业级服务器安全 ; 5、精通SQL,掌握Hadoop、Hive、R或相关大数据工具的使用方法;了解Scrapy、Selenium等爬虫框架的工作原理; 6 、经济学、金融学、统计学等专业,熟悉风控基本理论框架,熟悉常见作弊手法; 7、熟悉密码学基础理论,并具备网络和认证协议的安全建设和加固能力; 【加分项】 内驱力足,学习能力强,对事物保有好奇心,并能快速适应新环境; 良好的沟通能力和团队协同能力,能与他人合作,共同完成目标; 对所在领域有热情,相信方法总比困难多,善于独立思考并反思总结。
工作职责
阿里国际风险管理部,通过先进的安全技术,算法模型和人工智能等技术,确保阿里国际业务全球200+国家/地区的差异化合规 如果你想和我们一起及时响应全球信息保护制度, 如果你想和我们一起制定并落地数据安全保护制度和方案,致力于保障全球消费者信息安全和资金安全,建设防大流量攻击、web应用、系统网络、终端安全防线,挖掘并修复相关安全漏洞,既防范风险于未然,又及时止血扶大厦于将倾; 我们是制定风控策略体系,保障商家和消费者账号、消费者公平性和资金安全的第一人。
包括英文材料
Linux+
https://ryanstutorials.net/linuxtutorial/
Ok, so you want to learn how to use the Bash command line interface (terminal) on Unix/Linux.
https://ubuntu.com/tutorials/command-line-for-beginners
The Linux command line is a text interface to your computer.
https://www.youtube.com/watch?v=6WatcfENsOU
In this Linux crash course, you will learn the fundamental skills and tools you need to become a proficient Linux system administrator.
https://www.youtube.com/watch?v=v392lEyM29A
Never fear the command line again, make it fear you.
https://www.youtube.com/watch?v=ZtqBQ68cfJc
Web+
https://web.dev/learn
Explore our growing collection of courses on key web design and development subjects.
SQL+
https://liaoxuefeng.com/books/sql/introduction/index.html
什么是SQL?简单地说,SQL就是访问和处理关系数据库的计算机标准语言。
https://sqlbolt.com/
Learn SQL with simple, interactive exercises.
https://www.youtube.com/watch?v=p3qvj9hO_Bo
In this video we will cover everything you need to know about SQL in only 60 minutes.
Java+
https://www.youtube.com/watch?v=eIrMbAQSU34
Master Java – a must-have language for software development, Android apps, and more! ☕️ This beginner-friendly course takes you from basics to real coding skills.
开发框架+
[英文] Understanding Modern Development Frameworks: A Guide for Developers and Technical Decision-makers
https://www.freecodecamp.org/news/understanding-modern-development-frameworks-guide-for-devs/
Struts+
[英文] Getting Started
https://struts.apache.org/getting-started/
The framework documentation is written for active web developers and assumes a working knowledge about how Java web applications are built.
https://www.baeldung.com/struts-2-intro
Apache Struts 2 is an MVC-based framework for developing enterprise Java web applications.
Spring+
https://liaoxuefeng.com/books/java/spring/index.html
Spring是一个支持快速开发Java EE应用程序的框架。它提供了一系列底层容器和基础设施,并可以和大量常用的开源框架无缝集成,可以说是开发Java EE应用程序的必备。
https://spring.io/guides/gs/rest-service
https://spring.io/quickstart
Level up your Java code and explore what Spring can do for you.
iBATIS+
[英文] iBATIS Tutorial
https://www.tutorialspoint.com/ibatis/index.htm
Hibernate+
https://hibernate.org/orm/documentation/getting-started/
The following guides are meant to help you getting started with Hibernate ORM in an application.
https://www.baeldung.com/learn-jpa-hibernate
Hibernate is a standard implementation of the JPA specification, with a few additional features that are specific to Hibernate.
https://www.youtube.com/watch?v=xHminZ9Dxm4
Ever looked for a comprehensive tutorial to Hibernate & JPA that is fun and entertaining at the same time?
Windows+
[英文] Windows 10 Tutorial
https://www.tutorialspoint.com/windows10/index.htm
This tutorial gives you all the indepth information on this new operating system and its procedures.
Android+
https://roadmap.sh/android
Step by step guide to becoming an Android developer .
https://www.youtube.com/playlist?list=PLQkwcJG4YTCSVDhww92llY3CAnc_vUhsm
iOS+
https://www.youtube.com/watch?v=UNH0bE4zPtY&list=PLSzsOkUDsvdu5Mm67aBYs2YPu2OM4mFzt
Hadoop+
https://www.runoob.com/w3cnote/hadoop-tutorial.html
Hadoop 为庞大的计算机集群提供可靠的、可伸缩的应用层计算和存储支持,它允许使用简单的编程模型跨计算机群集分布式处理大型数据集,并且支持在单台计算机到几千台计算机之间进行扩展。
[英文] Hadoop Tutorial
https://www.tutorialspoint.com/hadoop/index.htm
Hadoop is an open-source framework that allows to store and process big data in a distributed environment across clusters of computers using simple programming models.
Hive+
[英文] Hive Tutorial
https://www.tutorialspoint.com/hive/index.htm
Hive is a data warehouse infrastructure tool to process structured data in Hadoop. It resides on top of Hadoop to summarize Big Data, and makes querying and analyzing easy.
https://www.youtube.com/watch?v=D4HqQ8-Ja9Y
R+
[英文] R Tutorial
https://www.w3schools.com/r/
R is often used for statistical computing and graphical presentation to analyze and visualize data.
大数据+
https://www.youtube.com/watch?v=bAyrObl7TYE
https://www.youtube.com/watch?v=H4bf_uuMC-g
With all this talk of Big Data, we got Rebecca Tickle to explain just what makes data into Big Data.
Selenium+
https://www.youtube.com/watch?v=j7VZsCCnptM
Learn Selenium by building a web scraping bot in Python.
https://www.youtube.com/watch?v=mOAXEQevCAE&list=PLhW3qG5bs-L_s9HdC5zNshE5Ti8jABwlU
相关职位
社招5-10年安全工程师岗
1. 负责安全托管客户的安全风险监测与安全事件的及时处置,定期向客户提交详尽的安全报告,确保客户的安全需求得到满足; 2. 根据客户项目的具体需求,提供专业的渗透测试、应急响应等安全服务,确保服务质量达到客户预期; 3. 实施并持续优化网络安全产品与服务,确保客户的安全服务结果质量,提升客户满意度; 4. 与客户建立并维护良好的沟通机制,确保客户需求能够被准确理解和高效执行,促进客户关系的长期稳定发展。
更新于 2025-06-18
社招8年以上A41531
1. 负责策划项目施工全过程的安全、保密和文明施工方案,并推动其落地实施,配合支持项目建设快速推进; 2. 负责引导、监督和考核项目各参建单位在安全、保密和文明施工的工作开展; 3. 参与总承包单位涉及的危大工程施工方案审核,并监督危大工程及危险源的施工过程管控; 4. 负责监督检查项目总承包单位安全制度、应急预案的建立及实施演练情况; 5. 负责协调制定项目各施工单位与设备工艺施工交叉作业的管控方案,做好现场工程与工艺设备施工交叉作业的管理工作; 6. 负责项目竣工备案前后,现场安全管理向工厂运维团队的移交及过渡管理工作; 7. 负责牵头项目的外联处置工作,对接各级监管机构的检查及监督整改工作。
更新于 2024-10-14
实习安全技术类
1. 负责信息系统安全风险评估并持续跟踪管管理; 2. 负责安全事件的实时响应、处理、调查及取证; 3. 参与团队基础架构、业务安全的风险评估,安全体系的建设。
更新于 2024-03-01