Dida

高级信息安全工程师

Dida  •  Onsite  •  1 month ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

高级信息安全工程师深圳社招全职研发 - 安全职位描述1. 负责公司核心 2B 业务渗透测试与红队演练,包括商家后台、供应商系统、开放 API、交易与支付链路等,重点挖掘越权、逻辑漏洞、数据窃取、金额篡改等高风险安全问题。
2. 复盘高危漏洞,从攻击视角定位防御短板,输出系统性安全改进方案。
3. 建设攻防对抗能力,将实战攻击手法转化为 WAF、API 网关、HIDS、RASP 等安全设备的检测与拦截规则,赋能业务与安全产品。
4. 构建并持续优化 “企业端 - API - 云原生” 威胁检测体系,实现异常登录、批量数据导出、恶意退款等行为可检测、可度量。
5. 跟踪前沿攻防技术与 AI 安全风险(提示注入、模型窃取、数据投毒等),转化为验证脚本与检测规则。
6. 参与安全事件应急响应、溯源分析与处置,输出可落地的防御加固方案。
7. 结合行业黑灰产情报与 ATT&CK 框架,形成主动防御与对抗手段。职位要求1. 本科及以上,计算机、信息安全相关专业,5 年以上安全技术经验(能力优秀可放宽)。
2. 具备独立漏洞挖掘能力,精通漏洞原理与利用,能独立发现 2B 场景复杂逻辑漏洞(多租户越权、批量遍历、业务参数篡改等)。
3. 熟悉甲方安全防御体系,理解 WAF、API 网关、EDR、风控系统原理,能从攻击者视角设计防御方案。
4. 熟练掌握至少一门开发语言(Python/Go/Java/Shell),可独立编写 POC/EXP、自动化检测脚本。
5. 熟悉 ATT&CK 框架,具备入侵检测、应急响应、取证溯源实战能力。
6. 扎实的网络基础,熟悉 TCP/IP、TLS、流量分析等技术。
加分项
1. 有电商、OTA 旅游、2B SaaS 平台攻防经验,熟悉票务、酒店、支付类业务风险。
2. 了解大模型原理,具备 LLM 安全实战经验。
3. 熟悉主流云平台攻防,掌握 IAM、对象存储、Serverless 等云安全风险。
4. 大型攻防演练获奖、SRC 高排名、有独立漏洞研究成果者优先。
如果你愿意,我还能再给你一版更短、更抓眼球的 BOSS 直聘 “一句话简介 + 亮点版”,方便求职者一眼看到价值。 投递
Dida

About Dida

An AI-first travel technology group. Founded in 2012 and headquartered in Shenzhen, Dida combines the scale and innovation of China with the diverse needs of international travel partners. By leveraging advanced AI platforms, automation and data insights, Dida delivers smarter solutions that help partners improve efficiency, strengthen engagement, and accelerate growth.

As the No.1 B2B player in China and a leader across APAC, Dida is uniquely positioned as the premier gateway between China, APAC, and the global travel ecosystem. Through its core business lines - Dida Hotels, Dida Flights, Dida Go and Dida Experiences - The company connects high-quality travel content from hotels, airlines, and ancillary providers to the world’s travel agencies, TMCs, tour operators, OTAs, and wholesalers - integrating deep partnerships with cutting-edge technology.

Guided by its pillars of Travel, Technology, and New Ventures, Dida Holdings is committed to building stronger partnerships and unlocking new opportunities across the global travel industry.

Industry
Unknown
Company Size
201-500 employees
Headquarters
Guangdong, CN
Year Founded
2012
Website
dida.com
Social Media