【岗位职责】
PCI安全工程师-软件方向,需要按标准要求进行金融POS机软件安全测试。有PCI-PTS、xPOC评估经验或POS机软件安全方案设计经验者优先。
The PCI Security Engineer (Software) is required to conduct software security testing ffinancial POS terminals as per standard requirements. Candidates with experience in PCI-PTS, xPOC evaluations, POS terminal software security design is a strong plus.
根据金融POS行业安全标准(如PCI-PTS等)对金融POS产品的软件进行安全测试。
Conduct security testing on the software of financial POS products in accordance with dedicated security standards (e.g., PCI-PTS).
【任职要求】
信息安全、网络安全、密码学、计算机科学与技术、通信工程或相关专业大学本科学历。
熟悉嵌入式系统软硬件调试和编程技能。
熟悉常见的加密算法原理和应用。
具备终端产品硬件安全、和/或物联网(IoT)方面的经验。
良好的英语水平(书面和口语),普通话为母语水平。
善于沟通和团队协作。
Bachelor’s degree in Information Security, Cybersecurity, Cryptography, Computer Science Technology, Communication Engineering, a related field.
Familiar with embedded system software hardware debugging programming skills.
Familiar with the principles applications of common encryption algorithms.
Experience in hardware security of terminal products and/Internet of Things (IoT).
Good at English (written spoken), with native-level Mandarin.
Strong communication teamwork skills.
精通C语言, 能熟练使用C语言、Python或java中的一种编程。
熟悉PCI PTS, ISO9564, ANSI X9.143, ANSI X9.24, TR-34 等标准。
熟悉主流对称和非对称密码学算法的原理和应用,熟悉密钥派生和管理方法。
熟悉Android、Linux等操作系统,了解内存隔离机制的实现,会熟练通过console、debug等接口进行系统安全性分析。
熟悉软件真实性和完整性验证的原理和方法,深刻理解固件和应用签名机制。
熟悉WiFi、Ethernet、Bluetooth 等网络协议,熟练使用数据包捕获、劫持和重放的工具进行测试和漏洞分析。
熟悉至少一款嵌入式芯片的特性和典型应用。
熟悉PKI原理和实际应用。
熟悉金融POS机的软件保护方案。
熟悉故障注入、模糊测试等原理和方法。
熟悉产品开发和生产过程的安全管控措施及过程文档审核。
了解POS机硬件安全的保护原理和方案。
Proficient in C language can program in one of the following: C, Python, Java.
Familiar with standards such as PCI-PTS, ISO9564, ANSI X9.143, ANSI X9.24, TR-34.
Familiar with the principles applications of mainstream symmetric asymmetric cryptographic algorithms, knowledgeable about key derivation management methods.
Familiar with operating systems such as Android Linux, understanding memory isolation mechanisms, skilled in conducting system security analysis via console, debugging interfaces, etc.
Familiar with the principles methods of software authenticity integrity verification, with a deep understanding of firmware application signing mechanisms.
Familiar with network protocols such as Wi-Fi, Ethernet, Bluetooth, proficient in using tools fpacket capture, hijacking, replay vulnerability analysis.
Familiar with the characteristics of at least one embedded chip.
Familiar with Public Key Infrastructure.
Familiar with software protection solutions ffinancial POS terminals.
Familiar with the principles methods of fault injection fuzzing.
Familiar with security control measures process documentation review during product development production.
Understanding of the protection principles solutions fPOS machine hardware security.