阿里云阿里云智能-PaaS 产品安全SDL专家-北京/杭州
社招全职技术类-安全地点:北京状态:招聘
任职要求
1. 有安全攻防经验,熟悉常见的web或二进制安全漏洞原理以及对应的修复方法; 2. 熟悉白盒代码审计,有开源框架漏洞挖掘经验,熟悉java开发框架(Struts,spring,ibatis,hibernate,etc) 者尤佳; 3. 精通Java\Python\Shell\Go\C/C++中至少一种编程语言; 4. 有良好的沟通和团队合作能力; 5. 有过企业SDL实践经验者优先。 加分项 1. 在代码审计或二进制漏洞挖掘方面有较为深厚的积累,有高质量的漏洞产出; 2. 先知、补天、漏洞盒子、HackerOne、BugCrowd、ASRC、TSRC等平台有高质量漏洞提交的白帽子。
工作职责
1. 负责阿里云云产品顶层安全架构的设计和落地; 2. 负责云产品的安全运营工作,深度参与和推进云产品SecDevOps流程建设; 3. 负责云产品代码安全审计和安全规范制定,并及时跟踪和响应云产品最新的安全漏洞。
包括英文材料
Web+
https://web.dev/learn
Explore our growing collection of courses on key web design and development subjects.
Java+
https://www.youtube.com/watch?v=eIrMbAQSU34
Master Java – a must-have language for software development, Android apps, and more! ☕️ This beginner-friendly course takes you from basics to real coding skills.
开发框架+
[英文] Understanding Modern Development Frameworks: A Guide for Developers and Technical Decision-makers
https://www.freecodecamp.org/news/understanding-modern-development-frameworks-guide-for-devs/
Struts+
[英文] Getting Started
https://struts.apache.org/getting-started/
The framework documentation is written for active web developers and assumes a working knowledge about how Java web applications are built.
https://www.baeldung.com/struts-2-intro
Apache Struts 2 is an MVC-based framework for developing enterprise Java web applications.
Spring+
https://liaoxuefeng.com/books/java/spring/index.html
Spring是一个支持快速开发Java EE应用程序的框架。它提供了一系列底层容器和基础设施,并可以和大量常用的开源框架无缝集成,可以说是开发Java EE应用程序的必备。
https://spring.io/guides/gs/rest-service
https://spring.io/quickstart
Level up your Java code and explore what Spring can do for you.
iBATIS+
[英文] iBATIS Tutorial
https://www.tutorialspoint.com/ibatis/index.htm
Hibernate+
https://hibernate.org/orm/documentation/getting-started/
The following guides are meant to help you getting started with Hibernate ORM in an application.
https://www.baeldung.com/learn-jpa-hibernate
Hibernate is a standard implementation of the JPA specification, with a few additional features that are specific to Hibernate.
https://www.youtube.com/watch?v=xHminZ9Dxm4
Ever looked for a comprehensive tutorial to Hibernate & JPA that is fun and entertaining at the same time?
Python+
https://liaoxuefeng.com/books/python/introduction/index.html
中文,免费,零起点,完整示例,基于最新的Python 3版本。
https://www.learnpython.org/
a free interactive Python tutorial for people who want to learn Python, fast.
https://www.youtube.com/watch?v=K5KVEU3aaeQ
Master Python from scratch 🚀 No fluff—just clear, practical coding skills to kickstart your journey!
https://www.youtube.com/watch?v=rfscVS0vtbw
This course will give you a full introduction into all of the core concepts in python.
Bash+
[英文] The Bash Guide
https://guide.bash.academy/
A quality-driven guide through the shell's many features.
https://www.youtube.com/watch?v=tK9Oc6AEnR4
Understanding how to use bash scripting will enhance your productivity by automating tasks, streamlining processes, and making your workflow more efficient.
Go+
https://www.youtube.com/watch?v=8uiZC0l4Ajw
学习Golang的完整教程!从开始到结束不到一个小时,包括如何在Go中构建API的完整演示。没有多余的内容,只有你需要知道的知识。
C+
https://www.freecodecamp.org/chinese/news/the-c-beginners-handbook/
本手册遵循二八定律。你将在 20% 的时间内学习 80% 的 C 编程语言。
https://www.youtube.com/watch?v=87SH2Cn0s9A
https://www.youtube.com/watch?v=KJgsSFOSQv0
This course will give you a full introduction into all of the core concepts in the C programming language.
https://www.youtube.com/watch?v=PaPN51Mm5qQ
In this complete C programming course, Dr. Charles Severance (aka Dr. Chuck) will help you understand computer architecture and low-level programming with the help of the classic C Programming language book written by Brian Kernighan and Dennis Ritchie.
C+++
https://www.learncpp.com/
LearnCpp.com is a free website devoted to teaching you how to program in modern C++.
https://www.youtube.com/watch?v=ZzaPdXTrSb8
SDL+
[英文] SDL Tutorials
https://wiki.libsdl.org/SDL2/Tutorials
There are a number of SDL tutorials available from different sources.
相关职位
社招5年以上云智能集团
1. 负责阿里云云产品顶层安全架构的设计和落地; 2. 负责云产品的安全运营工作,深度参与和推进云产品SecDevOps流程建设; 3. 负责云产品代码安全审计和安全规范制定,并及时跟踪和响应云产品最新的安全漏洞。
更新于 2025-09-11
社招8年以上腾讯云销售、服务
1.负责腾讯云PaaS产品,大数据、数据库、安全、音视频产品在渠道销售通路的商业化策略; 2.如商业合作模式设计及优化(代理、经销、SI、ISV、服务伙伴等),商务策略制定,产品营销计划(市场热点、行业赛道、产品组合)等,助力渠道业绩的增长; 3.承接产品在渠道销售通路的整体业务增长指标; 4.基于产品在渠道的增长目标,跨团队协同及推动产品营销专项以及合作伙伴合作模式的落地。
更新于 2025-09-30
社招5年以上云智能集团
1、对所负责的公安客户业务需求和痛点能够进行深度分析和洞察,可以有效挖掘相关客户业务需求、痛点及挑战。 2、针对客户业务痛点能够设计出符合需求并且具有领先性的AI、大数据、云计算解决方案。 3、对政府用户的信息化建设能够提出有效的建议,可以对标杆客户进行轻咨询类规划引导,形成更加针对性的客户解决方案。 4、熟悉阿里巴巴相关AI、IaaS、PaaS产品能力和竞争优势,掌握各类技术方案的相应技术参数指标,负责组织相应的POC进行方案支持,保证产品方案的可落地性,并推动产品不断成熟完善。
更新于 2025-09-04