台北市中正區3年以上大學以上
We’re looking for a Security Engineer to join our DevOps team and secure our cloud infrastructure, web apps, and databases. You’ll use static and dynamic analysis tools to detect and fix vulnerabilities, working closely with DevOps, DBAs, and external experts. This role focuses on integrating security into CI/CD pipelines, combining automated scans with manual checks, and staying up to date with gaming industry security trends.
#Responsibilities
1. Develop and maintain security measures for AWS infrastructure, including Identity and Access Management (IAM), Virtual Private Cloud (VPC), Security Groups, and Web Application Firewall (WAF).
2. Ensure the security of NodeJS and ReactJS applications by implementing best practices for web application security, such as secure coding and vulnerability mitigation.
3. Optimize Cloudflare settings to enhance CDN security, protect against Distributed Denial-of-Service (DDoS) attacks, and mitigate other threats.
4. Use Static Application Security Testing (SAST) tools, such as SonarQube, Micro Focus Fortify, Veracode Static Analysis, and Semgrep, to analyze source code for vulnerabilities during development, ensuring early detection of issues in NodeJS and ReactJS applications.
5. Leverage Dynamic Application Security Testing (DAST) tools, such as Burp Suite, OWASP ZAP, Netsparker, and Acunetix, to test running applications for runtime vulnerabilities, simulating real-world attacks.
6. Incorporate SAST and DAST tools into continuous integration/continuous deployment (CI/CD) pipelines to enable continuous security monitoring and automated vulnerability detection.
7. Work closely with DevOps engineers and DBAs to integrate security into deployment pipelines and ensure robust database security across multiple environments.
8. Partner with external consultants and penetration testers to identify vulnerabilities and implement remediation strategies.
9. Manage automated security tools for continuous threat detection, compatible with AWS and Cloudflare.
10. Stay updated on security threats and trends, especially in gaming (e.g., anti-cheat, gambling compliance).
11. Provide training and guidance to internal teams on security best practices and compliance requirements.
12. Maintain adherence to industry regulations, including those specific to online gaming and gambling, to protect sensitive data and ensure operational integrity.
#Qualifications
1. Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
2. Minimum of 3 years of experience as a Security Engineer or in a related role.
3. Strong expertise in AWS security services, including IAM, VPC, Security Groups, and WAF.
4. Proficiency in securing web applications built with NodeJS and ReactJS.
5. Experience with Cloudflare or similar CDN security configurations.
6. Knowledge of static and dynamic scanning tools for vulnerability assessment, including SAST tools (e.g., SonarQube, Fortify) and DAST tools (e.g., Burp Suite, ZAP).
7. Familiarity with database security principles and practices.
8. Excellent problem-solving skills with a keen attention to detail.
9. Strong communication and collaboration skills to work effectively within a team.
10. Ability to manage multiple priorities in a fast-paced environment.
#Preferred Qualifications
1. AWS Security Specialty, CCSP, or OWASP-related certs.
2. Familiar with DevOps tools (CI/CD, Docker, Kubernetes).
3. Knowledge of gaming platform compliance/regulations.
4. Experience with anti-cheat and gaming environment security.
5. Skilled in SAST tools (e.g., SonarQube, Fortify, Veracode, Semgrep).
6. Proficient with DAST tools (e.g., Burp Suite, ZAP, Netsparker, Acunetix).
7. Integrated SAST/DAST in CI/CD pipelines.
8. Experience with AWS Inspector for cloud vulnerability management.
9. Skilled in SIEM (Splunk, ELK), WAFs, and tools like Metasploit, Nessus.
10. Knowledge of OWASP Top 10, NIST, or ISO 27001 frameworks.