崗位職責(zé):
1. Security System Planning and Management:
· Develop and refine the university's cybersecurity management systems and processes to ensure effective implementation.
· Oversee the planning, execution, and optimization of cybersecurity projects to maintain the security and stability of the network environment.
2. Security Monitoring and Emergency Response:
· Monitor the cybersecurity status, promptly detect and handle security incidents, and conduct emergency response and forensic investigations.
· Develop emergency response plans for security incidents and organize regular drills to enhance the ability to respond to unexpected events.
3. Risk Assessment and Hardening:
· Conduct regular cybersecurity risk assessments to identify potential vulnerabilities and implement hardening measures.
· Perform security configuration and optimization of network devices, servers, and application systems.
4. Technical Support and Training:
· Provide cybersecurity technical support to faculty and students, addressing daily issues.
· Organize cybersecurity training programs to enhance the security awareness and skills of faculty and students.
5. Security Device Management:
· Be responsible for the installation, debugging, maintenance, and upgrade of cybersecurity devices (such as firewalls, intrusion detection systems, vulnerability scanning tools, etc.).
6. Compliance and Auditing:
· Ensure that the university's cybersecurity operations comply with relevant laws, regulations, and standards.
· Assist in completing cybersecurity-related audit tasks.
7. Other Duties:
· Complete other temporary tasks assigned by the leadership.
1、安全體系規(guī)劃與管理:
· 制定和完善大學(xué)的網(wǎng)絡(luò)安全管理制度和流程,推動網(wǎng)絡(luò)安全體系的落地執(zhí)行。
· 負(fù)責(zé)網(wǎng)絡(luò)安全項目的規(guī)劃、實施和優(yōu)化,確保網(wǎng)絡(luò)環(huán)境的安全性和穩(wěn)定性。
2、安全監(jiān)控與應(yīng)急響應(yīng):
· 監(jiān)控網(wǎng)絡(luò)安全狀態(tài),及時發(fā)現(xiàn)并處理安全事件,進(jìn)行應(yīng)急響應(yīng)和調(diào)查取證。
· 制定安全應(yīng)急預(yù)案,定期組織演練,提升應(yīng)對突發(fā)事件的能力。
3、風(fēng)險評估與加固:
· 定期開展網(wǎng)絡(luò)安全風(fēng)險評估,發(fā)現(xiàn)潛在漏洞并進(jìn)行加固。
· 對網(wǎng)絡(luò)設(shè)備、服務(wù)器、應(yīng)用系統(tǒng)等進(jìn)行安全配置和優(yōu)化。
4、技術(shù)支持與培訓(xùn):
· 為師生提供網(wǎng)絡(luò)安全技術(shù)支持,解決日常遇到的問題。
· 組織網(wǎng)絡(luò)安全培訓(xùn),提升師生的安全意識和技能。
5、安全設(shè)備管理:
· 負(fù)責(zé)網(wǎng)絡(luò)安全設(shè)備(如防火墻、入侵檢測系統(tǒng)、漏洞掃描工具等)的安裝、調(diào)試、維護(hù)和升級。
6、合規(guī)與審計:
· 確保大學(xué)的網(wǎng)絡(luò)安全工作符合相關(guān)法律法規(guī)和標(biāo)準(zhǔn)要求。
· 協(xié)助完成網(wǎng)絡(luò)安全相關(guān)的審計工作。
7、其他工作:
· 完成上級領(lǐng)導(dǎo)交辦的其他臨時性工作任務(wù)。
任職要求:
Educational background: Bachelor degree or above
Major: Computer Science, Network Engineering, Telecommunications, Information Security, or related fields
Language preference: Possess strong English listening, speaking, reading, and writing skills.
Others:
1. At least 8 years of relevant work experience in university network security, with experience in the implementation and management of network security projects.
2. Familiar with network security technologies, including firewalls, intrusion detection, vulnerability scanning, and Web application protection.
3. Proficient in the configuration and management of mainstream operating systems (such as Linux, Windows) and network security devices.
4. Knowledgeable in network security attack and defense techniques, and familiar with common attack methods (such as SQL injection, XSS, DDoS attacks) and their prevention methods.
5. Familiar with information security management systems (such as ISO27001) and cybersecurity regulations.
6. Strong problem analysis and resolution skills, with the ability to handle sudden security incidents.
7. Good communication skills, teamwork spirit, and a strong sense of responsibility.
8. Preference will be given to candidates holding relevant professional certifications (such as CISP, CISSP).
This position requires an English interview and a written test.
學(xué)歷要求:大學(xué)本科及以上
專業(yè)要求:計算機(jī)、網(wǎng)絡(luò)、通信、信息安全等相關(guān)專業(yè)
語言要求:具備良好的英語聽說讀寫能力。
其他:
1、至少8年以上高校網(wǎng)絡(luò)安全相關(guān)工作經(jīng)驗,具備網(wǎng)絡(luò)安全項目實施、管理經(jīng)驗;
2、熟悉網(wǎng)絡(luò)安全技術(shù),包括防火墻、入侵檢測、漏洞掃描、Web應(yīng)用防護(hù)等
3、熟悉主流操作系統(tǒng)(如Linux、Windows)和網(wǎng)絡(luò)安全設(shè)備的配置與管理
4、掌握網(wǎng)絡(luò)安全攻防技術(shù),了解常見的攻擊手段(如SQL注入、XSS、DDoS攻擊)及防范方法
5、熟悉信息安全管理體系(如ISO27001)和網(wǎng)絡(luò)安全法規(guī)
6、具有較強(qiáng)的問題分析和解決能力,能夠應(yīng)對突發(fā)安全事件
7、具備良好的溝通能力、團(tuán)隊合作精神和責(zé)任心
8、持有相關(guān)專業(yè)認(rèn)證(如CISP、CISSP)者優(yōu)先
此崗位需要英文面試+筆試。