Job Description
Responsibilities
1. Responsible for emergency response and incident tracing for security incidents on the Alibaba Cloud platform side, covering both the office network and the production network.
2. Responsible for the detection, emergency response, and tracing of internal and external DDoS attack incidents against Alibaba Cloud; formulate and drive the implementation of mitigation plans; and govern botnet and DDoS issues on the cloud.
3. Effectively manage and defend against tenant-side attack incidents on the Alibaba public cloud platform, continuously strengthen defense capabilities, and prevent large-scale security incidents or systemic security risks from occurring on the public cloud platform.
4. Responsible for building product-level security defense capabilities: develop, deploy, and operate security defense tools; help business teams raise the default security baseline and reduce their security exposure surface.
5. Vulnerability tracking and emergency response: track and analyze newly disclosed vulnerabilities in the industry, assess their impact scope, and drive emergency response; design remediation plans and mitigation measures; and provide general-purpose security technical support and solutions for cloud products.
6. Responsible for security approval of routine configuration changes to cloud products, and provide security guidance and recommendations.
7. Responsible for building information-security capabilities and enforcing security policies for the office network, including anti-virus protection, vulnerability remediation, access control, and endpoint security for employees' computers, so as to guard against cyber attacks and data-leak risks.
8. Support routine security inspections and technical assistance work required by local regulators.
Position Requirement
Qualifications
1. Possess a solid foundation in computer networking, with a thorough understanding of the layers of the TCP/IP protocol suite (such as IP, TCP, UDP, ICMP, etc.); able to precisely analyze the structure of network packets, transmission flows, and anomalies; and well-versed in key networking principles such as routing algorithms at the network layer and connection establishment/termination mechanisms at the transport layer.
2. Proficient in the mechanisms and principles of common DDoS attack types, including network-layer flood attacks such as SYN Flood, UDP Flood, and ICMP Flood; application-layer resource-exhaustion attacks such as HTTP Flood and DNS Query Flood; as well as emerging hybrid attack patterns and DDoS techniques that exploit vulnerabilities.
3. Familiar with DDoS defense technologies and with the underlying principles of techniques such as traffic scrubbing and blackholing; able to design effective defense strategies to safeguard the business.
4. Proficient in at least one mainstream programming language such as Python or C/C++, with the ability to develop custom detection, defense, and operations scripts.
5. Familiar with the fundamentals of big-data technologies; hands-on experience using such technologies to mine DDoS attack patterns and anomalous features from network traffic data is a plus.
6. Familiar with the network architecture and security mechanisms of cloud computing / cloud platforms or large-scale network environments; prior experience in DDoS defense design, deployment, and defense-policy operations on a cloud platform or a large offline network (with more than 5,000 nodes) is a plus.
7. Familiar with common security offense-and-defense techniques and the principles of common vulnerabilities, with in-depth research and demonstrable results in at least one specialized area, such as web security, host security (Windows / Linux / Mobile OS, etc.), deep learning (e.g., natural language processing), container security, vulnerability analysis and exploitation, network-traffic security, or cloud security.
The pay range for this position at commencement of employment is expected to be between $104,400 and $171,000/year. However, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience.
If hired, employee will be in an "at-will position" and the Company reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.