Skip to content

On-Site Security Service Engineer

TIP

Send the file in Word or PDF format to admin@ckcsec.com. File naming format: interview position + name + work experience.

Penetration Testing Engineer (Long-Term On-Site)

Work content: penetration testing

Base: Shanghai

Salary: 13-16k

Position requirements: bachelor's degree, three years of experience

  1. Familiar with common security attack and defense methods, penetration testing processes, and security protection practices; familiar with common security vulnerabilities and technical principles; rich attack-defense experience.

  2. Rich hands-on experience and able to independently complete penetration testing work; proficient in common Internet-facing foothold techniques and internal-network attack ideas; familiar with common internal-network attack methods.

  3. Proficient with penetration testing tools such as Burp Suite, AWVS, Nmap, Nessus, OpenVAS, Metasploit, Kali Linux, Cobalt Strike, and others.

  4. Familiar with common system, network, and application attack techniques, including SQL injection, XSS, CSRF, OWASP TOP 10, DDoS, and others, and understand their defense and hardening methods.

  5. Familiar with mainstream security detection systems such as Linux, Tomcat, Nginx, WebLogic, and able to write vulnerability-exploitation POCs.

On-Site Operations Engineer (Long-Term On-Site)

Base: Shanghai

Salary: 14-16k

Position requirements: bachelor's degree, more than three years of formal work experience in information security technology

  1. Understand the technical principles and functions of common security products, and have participated in at least one on-site security operations project.

  2. Familiar with various mainstream security attack techniques and their corresponding defensive measures.

  3. Proficient in operating and using Linux and Windows operating systems, as well as security configuration.

  4. Familiar with security detection and hardening technologies for mainstream databases and application systems.

  5. Have your own understanding of security operations, be willing to work in security operations, be willing to provide valuable services to customers, and persist in doing valuable work.

Data Security Engineer (Long-Term On-Site)

Base: Shanghai

Salary: 14-17k

Position requirements: bachelor's degree, more than four years of formal work experience in information security technology

  1. Understand the technical principles and functions of common security products; have participated in or been responsible for cybersecurity attack-defense drills or major event security duty.

  2. Expert in various mainstream security attack techniques and their corresponding defensive measures, and proficient in using various security tools.

  3. Proficient in operating and using Linux and Windows operating systems, as well as security configuration.

  4. Expert in security detection and hardening technologies for mainstream databases and application systems.

  5. Have experience in security architecture design and security solution design capabilities; have worked on large-scale security service projects and be familiar with mainstream security standards.

Security Operations Engineer (Long-Term On-Site)

Base: Beijing

Salary: 17-22k

Position requirements: bachelor's degree, more than four years of formal work experience in information security technology

  1. Incident response capability: familiar with common attack techniques such as APT attacks, ransomware, and phishing attacks, and able to locate threat sources through log analysis and traffic analysis (such as Wireshark).

  2. Experience independently handling security incidents, such as data leaks or malicious programs implanted in web systems, and familiarity with incident response processes.

  3. Understand penetration testing methods, be able to reproduce vulnerability exploitation chains such as Log4j2 and EternalBlue, and be familiar with firewall, IDS/IPS, and WAF configuration policies.

  4. Able to write security reports and translate security analysis into business risk descriptions that management can understand.

  5. Participated in red-blue team drills or attack-defense exercises such as HW operations, and familiar with attackers' lateral movement techniques.

Released under the MIT License