安全评测工程师
Core
Conduct security assessments, vulnerability research, and penetration testing for core products, business systems, and infrastructure, with a focus on AI system security and automated toolchain development.
Role type
Senior IC security assessment engineer (AI & cloud-native focus)
Builds
Security assessment reports, PoC/EXP tools, and automated vulnerability scanning capabilities
Domain
Cybersecurity, AI security, Cloud-native security
Required skills
Red team experience, vulnerability analysis, penetration testing, AI vulnerability research (prompt injection, model over-privilege), RASP mechanisms, cloud security architecture, tool development (Go/Python/PHP/JAVA/.NET), 0day/Nday tracking
Preferred skills
Experience with EDR/WAF/NDR products, innovation in security methodologies, system thinking
Technologies
Go, Python, PHP, JAVA, .NET, RASP, EDR, WAF, NDR, Cloud platforms
Responsibilities
Perform vulnerability mining, penetration testing, and security assessments across Web, binary, and cloud-native scenarios; Research and validate AI-specific vulnerabilities and defense mechanisms; Develop and optimize security assessment toolchains using AI; Track industry攻防 trends and top-tier conference research to build team methodologies.
