
智能互联阿里云智能-安全专家(应急响应攻防)-杭州/北京
社招全职5年以上地点:北京 | 杭州状态:招聘
任职要求
1. 深入理解安全攻防技术体系,熟悉ATT&CK框架、渗透测试、安全漏洞利用等攻防技术细节,具备实战化对抗经验; 2. 具备较好的数据分析能力,熟悉Flink/Hive/Splunk/ES或其他大数据分析平台,能独立完成异常流量/安全日志的分析; 3. 掌握Linux/Windows系统安全机制,能独立完成系统安全取证;熟悉防火墙/IDS/WAF等安全设备基本原理; 4. 掌握Python/Java/Go中至少一门编程语言,能编写自动化工具或进行脚本开发; 5. 具备良好的协调沟通及任务…
登录查看完整任职要求
微信扫码,1秒登录
工作职责
团队介绍: 我们是阿里云网络安全团队,负责阿里云反入侵,包括网络安全架构、入侵检测、应急响应以及云平台管控。 我们正在寻找一位高级安全工程师,负责建设应对安全事件的应急响应能力,参与安全事件响应与溯源调查,确保公司业务的安全性。 主要职责: 1. 持续追踪分析前沿APT攻击手法、黑灰产动态及全球重大安全事件,设计应对各类威胁场景的应急响应方案与能力,提升反入侵水位; 2. 深入研究新型攻击技术和入侵手法,推动止血对抗、溯源取证等核心能力的体系化建设和能力落地; 3. 参与入侵事件的应急响应处置,独立完成事件溯源调查与报告。
包括英文材料
数据分析+
[英文] Data Analyst Roadmap
https://roadmap.sh/data-analyst
Step by step guide to becoming an Data Analyst in 2025
Flink+
https://nightlies.apache.org/flink/flink-docs-release-2.0/docs/learn-flink/overview/
This training presents an introduction to Apache Flink that includes just enough to get you started writing scalable streaming ETL, analytics, and event-driven applications, while leaving out a lot of (ultimately important) details.
https://www.youtube.com/watch?v=WajYe9iA2Uk&list=PLa7VYi0yPIH2GTo3vRtX8w9tgNTTyYSux
Today’s businesses are increasingly software-defined, and their business processes are being automated. Whether it’s orders and shipments, or downloads and clicks, business events can always be streamed. Flink can be used to manipulate, process, and react to these streaming events as they occur.
Hive+
[英文] Hive Tutorial
https://www.tutorialspoint.com/hive/index.htm
Hive is a data warehouse infrastructure tool to process structured data in Hadoop. It resides on top of Hadoop to summarize Big Data, and makes querying and analyzing easy.
https://www.youtube.com/watch?v=D4HqQ8-Ja9Y
ElasticSearch+
https://www.youtube.com/watch?v=a4HBKEda_F8
Learn about Elasticsearch with this comprehensive course designed for beginners, featuring both theoretical concepts and hands-on applications using Python (though applicable to any programming language). The course is structured in two parts: first covering essential Elasticsearch fundamentals including index management, document storage, text analysis, pipeline creation, search functionality, and advanced features like semantic search and embeddings; followed by a practical section where you'll build a real-world website using Elasticsearch as a search engine, working with the Astronomy Picture of the Day (APOD) dataset to implement features such as data cleaning pipelines, tokenization, pagination, and aggregations.
Linux+
https://ryanstutorials.net/linuxtutorial/
Ok, so you want to learn how to use the Bash command line interface (terminal) on Unix/Linux.
https://ubuntu.com/tutorials/command-line-for-beginners
The Linux command line is a text interface to your computer.
https://www.youtube.com/watch?v=6WatcfENsOU
In this Linux crash course, you will learn the fundamental skills and tools you need to become a proficient Linux system administrator.
https://www.youtube.com/watch?v=v392lEyM29A
Never fear the command line again, make it fear you.
https://www.youtube.com/watch?v=ZtqBQ68cfJc
还有更多 •••
相关职位
社招5年以上云智能集团
1. 掌握和跟踪大模型、数据安全等方面的国内国际法律、政策、技术标准,结合业务实际产出具有洞察力的分析报告; 2. 识别并处理公司在研发或经营活动中的系统性风险,提出系统性解决建议和合规方案并组织协同团队落实合规方案。 3. 与主管机关的合作,包括但不限于算法备案、大模型备案、APP合规、算法检查、各类调研与问询等; 4. 大模型服务的数据安全的全盘设计与实施,包括但不限于制度、机制、分类分级能力等的建设。
更新于 2026-01-21杭州|上海
社招5年以上云智能集团
1. 风险运营闭环管理:针对阿里云用户常见安全风险(密钥泄漏、弱口令、漏洞利用等),设计从发现、触达、处置的全流程运营机制,提升客户风险处置率; 2. 建设智能监控体系:通过新事件和用户反馈分析,建立风险趋势洞察和预警能力,及时发现新型攻击模式并推动策略优化; 3. 处理外部安全举报:负责接收和响应针对阿里云用户的安全举报(对外扫描、攻击等),制定标准化研判流程,总结共性风险问题,协同内部团队高效治理; 4. 沉淀最佳实践:总结典型风险案例与解决方案,输出可复用的安全指南、工具或建议,推动云产品安全能力演进,并协同内部团队开展用户安全教育培训,帮助客户理解风险、主动加固,提升整体安全意识。
更新于 2026-01-23杭州
社招5年以上云智能集团
1. 针对阿里云重点客户开展渗透测试和红蓝对抗服务,帮助客户发现安全风险,提升安全水位; 2. 配合国家监管机构,开展针对关键基础设施单位的大型实网攻防演练活动,促进行业安全发展; 3. 参与阿里云蓝军武器库能力建设&安全运营,通过自动化技术和AI能力提升攻防效能,落地实战化攻防工具。
更新于 2026-04-08北京|杭州