Back to search
艾普拉斯(上海)质量检测有限公司 Linkedin · Posted 2mo ago

PCI软件安全测试工程师

Shenzhen

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

该职位来源于猎聘 【岗位职责】 PCI安全工程师-软件方向,需要按标准要求进行金融POS机软件安全测试。有PCI-PTS、xPOC评估经验或POS机软件安全方案设计经验者优先。 The PCI Security Engineer (Software) is required to conduct software security testing for financial POS terminals as per standard requirements. Candidates with experience in PCI-PTS, xPOC evaluations, or POS terminal software security design is a strong plus.

  • 根据金融POS行业安全标准(如PCI-PTS等)对金融POS产品的软件进行安全测试。
  • Conduct security testing on the software of financial POS products in accordance with dedicated security standards (e.g., PCI-PTS). 【任职要求】
  • 信息安全、网络安全、密码学、计算机科学与技术、通信工程或相关专业大学本科学历。
  • 熟悉嵌入式系统软硬件调试和编程技能。
  • 熟悉常见的加密算法原理和应用。
  • 具备终端产品硬件安全、和/或物联网(IoT)方面的经验。
  • 良好的英语水平(书面和口语),普通话为母语水平。
  • 善于沟通和团队协作。
  • Bachelor’s degree in Information Security, Cybersecurity, Cryptography, Computer Science and Technology, Communication Engineering, or a related field.
  • Familiar with embedded system software and hardware debugging and programming skills.
  • Familiar with the principles and applications of common encryption algorithms.
  • Experience in hardware security of terminal products and/or Internet of Things (IoT).
  • Good at English (written and spoken), with native-level Mandarin.
  • Strong communication and teamwork skills.
  • 精通C语言, 能熟练使用C语言、Python或java中的一种编程。
  • 熟悉PCI PTS, ISO9564, ANSI X9.143, ANSI X9.24, TR-34 等标准。
  • 熟悉主流对称和非对称密码学算法的原理和应用,熟悉密钥派生和管理方法。
  • 熟悉Android、Linux等操作系统,了解内存隔离机制的实现,会熟练通过console、debug等接口进行系统安全性分析。
  • 熟悉软件真实性和完整性验证的原理和方法,深刻理解固件和应用签名机制。
  • 熟悉WiFi、Ethernet、Bluetooth 等网络协议,熟练使用数据包捕获、劫持和重放的工具进行测试和漏洞分析。
  • 熟悉至少一款嵌入式芯片的特性和典型应用。
  • 熟悉PKI原理和实际应用。
  • 熟悉金融POS机的软件保护方案。
  • 熟悉故障注入、模糊测试等原理和方法。
  • 熟悉产品开发和生产过程的安全管控措施及过程文档审核。
  • 了解POS机硬件安全的保护原理和方案。
  • Proficient in C language and can program in one of the following: C, Python, or Java.
  • Familiar with standards such as PCI-PTS, ISO9564, ANSI X9.143, ANSI X9.24, and TR-34.
  • Familiar with the principles and applications of mainstream symmetric and asymmetric cryptographic algorithms, and knowledgeable about key derivation and management methods.
  • Familiar with operating systems such as Android and Linux, understanding memory isolation mechanisms, and skilled in conducting system security analysis via console, debugging interfaces, etc.
  • Familiar with the principles and methods of software authenticity and integrity verification, with a deep understanding of firmware and application signing mechanisms.
  • Familiar with network protocols such as Wi-Fi, Ethernet, and Bluetooth, and proficient in using tools for packet capture, hijacking, and replay and vulnerability analysis.
  • Familiar with the characteristics of at least one embedded chip.
  • Familiar with Public Key Infrastructure.
  • Familiar with software protection solutions for financial POS terminals.
  • Familiar with the principles and methods of fault injection and fuzzing.
  • Familiar with security control measures and process documentation review during product development and production.
  • Understanding of the protection principles and solutions for POS machine hardware security.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search