理想汽车车联网信息安全工程师-杭州
校招全职信息安全地点:杭州状态:招聘
任职要求
方向1:安全合规、运营与技术 1. 熟悉ISO21434、GB44495、R155等标准法规; 2. 具备一定的信息安全威胁分析和风险评估能力,能够识别和分析安全问题; 3. 熟悉信息安全技术栈,包括密码学、访问控制、身份认证、加密技术等基础安全措施; 4. 熟悉 TCP/IP 网络协议栈,熟悉常见网络应用层协议如HTTP、HTTPS、SSH、FTP等; 5. 有良好的沟通能力和协作能力。 方向2:渗透测试与功能验证 1. 掌握操作系统原理、计算机网络基础、信息安全基础知识等; 2. 熟悉常见二进制漏洞原理,熟悉漏洞利用与对应防御技巧等; 3. 熟悉C/C++,熟练使用至少一种编程或脚本语言(如 Python、C/C++ ); 4. 有信息安全竞赛(CTF)、车联网安全竞赛、开源漏洞复现等相关经历者优先。
工作职责
方向1:安全合规、运营与技术 负责整车项目、自研系统(如座舱/智驾)及委外零部件的安全管理及运营工作,包括不限于: 1. 跟进行业安全法规及标准,结合合规要求支撑企业安全体系及能力建设等管理工作; 2. TARA分析、安全需求设计、方案设计等技术工作; 3. 推动安全需求及方案落地,漏洞管理与推修、应急响应等运营工作。 方向2:渗透测试与功能验证 负责理想汽车从零部件到整车的信息安全功能验证、渗透测试,自动化渗透与检测能力建设。
包括英文材料
TCP/IP+
[英文] What is TCP/IP?
https://www.techtarget.com/searchnetworking/definition/TCP-IP
TCP/IP stands for Transmission Control Protocol/Internet Protocol and is a suite of communication protocols used to interconnect network devices on the internet.
HTTP+
https://developer.mozilla.org/zh-CN/docs/Web/HTTP
超文本传输协议(HTTP)是一个用于传输超媒体文档(例如 HTML)的应用层协议。它是为 Web 浏览器与 Web 服务器之间的通信而设计的,但也可以用于其他目的。
SSH+
https://www.digitalocean.com/community/tutorials/ssh-essentials-working-with-ssh-servers-clients-and-keys#how-to-use-this-guide
SSH is a secure protocol used as the primary means of connecting to Linux servers remotely.
https://www.redhat.com/en/blog/ways-use-ssh
Secure shell (SSH) is one of the most ubiquitous Linux tools.
https://www.youtube.com/watch?v=YS5Zh7KExvE
OpenSSH is the essential tool for secure remote access, and it’s a must-know for anyone in DevOps, cloud computing, system administration, hosting, and IT in general.
C+
https://www.freecodecamp.org/chinese/news/the-c-beginners-handbook/
本手册遵循二八定律。你将在 20% 的时间内学习 80% 的 C 编程语言。
https://www.youtube.com/watch?v=87SH2Cn0s9A
https://www.youtube.com/watch?v=KJgsSFOSQv0
This course will give you a full introduction into all of the core concepts in the C programming language.
https://www.youtube.com/watch?v=PaPN51Mm5qQ
In this complete C programming course, Dr. Charles Severance (aka Dr. Chuck) will help you understand computer architecture and low-level programming with the help of the classic C Programming language book written by Brian Kernighan and Dennis Ritchie.
C+++
https://www.learncpp.com/
LearnCpp.com is a free website devoted to teaching you how to program in modern C++.
https://www.youtube.com/watch?v=ZzaPdXTrSb8
脚本+
[英文] Scripting language
https://en.wikipedia.org/wiki/Scripting_language
https://zhuanlan.zhihu.com/p/571097954
一个脚本通常是解释执行而非编译。脚本语言通常都有简单、易学、易用的特性,目的就是希望能让程序员快速完成程序的编写工作。
Python+
https://liaoxuefeng.com/books/python/introduction/index.html
中文,免费,零起点,完整示例,基于最新的Python 3版本。
https://www.learnpython.org/
a free interactive Python tutorial for people who want to learn Python, fast.
https://www.youtube.com/watch?v=K5KVEU3aaeQ
Master Python from scratch 🚀 No fluff—just clear, practical coding skills to kickstart your journey!
https://www.youtube.com/watch?v=rfscVS0vtbw
This course will give you a full introduction into all of the core concepts in python.
相关职位