成都 - 信息安全分析师(安全运营), ITS SOC
kpmg · Wuhou, Sichuan, China
About The Role
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world. Service Line Overview Information Technology Services (ITS) is a single, integrated service organization with global, national and practice-based components that work together to meet service expectations and deliver priority projects to KPMG China. About The Role As a part of the Security Operations Centre, you will work with a team of SOC analysts to deliver professional cyber security services, which spans the full range of security monitoring, incident investigation, response and reporting, threat intelligent and vulnerability management, and other security analytics functions. Key Responsibilities 主要职责 Ensuring timely incident identification, assessment, containment, and recovery. 负责网络安全事件的识别、评估、遏制与恢复全流程处置工作; Act as incident response specialist for cyber security incidents when required and coordinate resources and teams across the firm to adequately respond to security threats. 紧急事件发生时担任应急响应分析师,统筹协调跨部门资源与团队协助,高效处置各类安全威胁; Develop and enhance incident response processes or playbooks. 梳理、搭建并持续优化应急响应流程与标准化处置预案(playbook); Provide cyber security guidance on operational topics such as security incident response, vulnerability management, data breach prevention, security alert monitoring, etc. 针对安全事件处置、漏洞管理、数据泄露防护、安全告警监控等日常运营工作,提供专业安全指导; Prompt response to latest cyber security news or vulnerability updates. 实时跟进行业最新安全动态、高危漏洞通告,并同步落地对应防护应对措施; Perform threat management, threat modelling, identify threat actors and develop security monitoring use cases. 开展威胁管理与威胁建模工作,梳理攻击者画像,输出检测规则与用例; Measure SOC performance metrics – ensuring compliance to policies and SLA, process adherence and process optimization. 统计SOC安全运营核心指标,保障各项工作符合内部制度、服务SLA,跟进流程落地执行情况并推进持续优化; Ensure compliance with internal standards, international standard like ISO27001 and regulatory requirements in China. 落实内部安全规范、ISO27001等国际体系标准及国内相关法律法规、监管合规要求。 Experience & Background 任职要求 Bachelor’s degree, with a major in IT or other relevant disciplines. 本科及以上学历,计算机、信息技术、网络安全等相关专业; 5+ year experience in IT Security / SOC / incident detection and response field. 拥有5年及以上信息安全、SOC安全运营、安全检测与应急响应相关从业经验; Holder of CISSP, CISM and/or CISA preferred. 持有CISSP、CISM、CISA等安全资质证书者优先; Experience in network security, cloud security and container security. 掌握网络安全、云安全、容器安全相关技术,具备落地实操经验; Proven experience in incident detection & response in multi-cloud and hybrid-cloud environments. 具备多云、混合云架构场景下安全检测、应急响应实战经验; Experience in data analytics, process automation, and application development will be an advantage. 具备数据分析、安全流程自动化、简易开发能力者优先考虑; Proven experience in SIEM, SOAR and TIP tools, develop and enhance IR playbook, security solutions evaluation and recommendations. 熟练使用SIEM、SOAR、威胁情报平台(TIP)等安全工具,可独立编写优化应急处置预案(IR playbook),完成安全产品测评、选型及方案推荐; Technical knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST. 熟悉MITRE ATT&CK框架、Cyber Kill Chain、NIST等主流安全模型; Experience with endpoint security products, firewall technologies, threat intelligence, penetration tests, information security principles and practices will be an advantage. 了解终端安全产品、防火墙技术、威胁情报运营、渗透测试及信息安全基础理论与实操者优先; Experience with China brand security vendors will be an advantage. 熟悉国产主流安全厂商产品与方案者优先; Strong desire to develop and follow standards and procedures. 具备较强的体系规范搭建意识,习惯遵循并落地标准化流程制度。 About KPMG At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level. We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients. To lead by example, we launched Our Impact Plan (OIP) which includes our ESG commitments and progress across four key pillars – Planet, People, Prosperity and Governance. We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information. Please note that all information in this form has been voluntarily supplied and will be used by KPMG for selection purposed only.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring