Job description
1. Core Responsibilities
1.1 Governance and access control of production network permissions
1.1.1 Establish a panoramic view of accounts and permissions for production platforms/business systems/cloud resources: cloud accounts (IAM), K8s (RBAC/ServiceAccount), databases/middleware, API gateways, CI/CD, artifact repositories, etc.
1.1.2 Develop and implement a production access control architecture: partition isolation, least privilege, strong authentication (SSO/MFA), fine-grained authorization (RBAC/ABAC), high privilege access (PAM/JIT/JEA)
1.1.3 Organize permission convergence and governance: permission application/approval, regular permission review (Access Review), automatic recovery of permissions upon resignation/transfer/temporary access, permission drift and overreach detection
1.1.4 Build key and credential security: AK/SK, Tokens, certificates, K8s Secrets, CI/CD variable unified management and rotation, key scanning and leak interception
1.1.5 Establish abnormal access detection and coordinated blocking: implement abnormal alerts based on audit logs, full-link access logs, and behavior analysis, and coordinate with gateways/WAF/firewalls/cloud ACL/account freezing for blocking
2. Governance of office network permissions and zero trust operations
2.1 Plan and continuously optimize the zero trust office network: device access (MDM), identity (IAM+SSO+MFA), dynamic access control (SDP/NG-SWG/IAP), achieving triad authorization of “person-device-application”
2.2 Establish governance of office system permissions: sorting out permission models for IM/email, code repositories, ticket/knowledge bases, SaaS applications, etc., permission classification, minimizing authorization, and periodic review
2.3 Build account and endpoint security operations: full coverage of office endpoint EDR/XDR (macOS/Windows/Linux), monitoring abnormal logins, abnormal downloads, sensitive data exfiltration, etc. using UEBA/SIEM
2.4 Promote convergence of data and access risks: implement DLP/CASB policies, discover and govern shadow IT, handle security alerts and close the loop
2.5 Promote security awareness building: training and drills focused on permission and account risks (phishing, social engineering, MFA fatigue attacks, etc.), reducing human risks
3. Permission security platform and automation
3.1 Build capabilities for permission governance platform: asset and permission discovery, owner attribution, risk scoring, alert and ticket closure, audit reports and compliance proof
3.2 Develop an “emergency bleeding control toolkit”: one-click offline Pod/container/host/account/certificate/AK/SK, one-click block IP/domain, one-click rollback high-risk policies
3.3 Create a visual security dashboard: permission convergence progress, risk item trends, remediation SLA, abnormal access and blocking statistics, MTTR, and other operational metrics
4. Security incident response and tracing
4.1 Lead emergency response and deep tracing of permission-related incidents in production and office networks (account theft, permission abuse, key leaks, overreach access, supply chain poisoning, etc.)
4.2 Establish and continuously operate a threat hunting model (Sigma/YARA/SPL), focusing on unknown backdoors, covert C2, lateral movement, and privilege escalation links
2. Technical Requirements
1. Production network direction (mainly Alibaba Cloud/AWS)
1.1 Proficient in identity and permission models: RAM/SSO/MFA, RBAC/ABAC, K8s RBAC, PAM, JIT/JEA, capable of independently designing and implementing permission governance solutions
1.2 Familiar with production link authentication and risk control: API gateways, inter-service access control, key and certificate systems, auditing and tracing
1.3 Familiar with cloud-native security and supply chain security: image signing, SBOM, secret management and rotation, runtime security and micro-segmentation
1.4 Possess security incident response and tracing capabilities, able to restore attack chains based on audit logs + full traffic + endpoint and other multidimensional data
2. Office network direction
2.1 Proficient in zero trust frameworks, with experience in implementing IAP/SDP/NG-SWG from 0 to 1, capable of integrating identity, device, and application permission governance
2.2 Familiar with NAC/MDM, SWG/CASB, EDR/XDR, SIEM/UEBA products and policy orchestration, able to achieve alert linkage handling and automatic blocking
2.3 Master phishing drills, account risk governance (abnormal logins/MFA fatigue/credential leaks), DLP/IRM, SaaS shadow IT discovery and governance
2.4 Familiar with macOS/Windows endpoint security hardening, patch and configuration baseline management
3. General capabilities
3.1 Proficient in security tool development or engineering implementation capabilities, able to automate the “discovery-alert-block-rollback-audit” closed loop
3.2 Excellent cross-department communication and documentation skills, able to produce permission baselines, process specifications, audit reports, and review materials.
3. Qualifications
1. Over 3 years of security operations experience in large internet/financial production networks, over 3 years of enterprise-level office network zero trust construction experience
2. Led the implementation of security systems for production or office networks from 0 to 1
3. Served as the main tracing role in intrusion incidents (ransomware, APT, supply chain poisoning, exchange theft), successfully locating the initial entry point, attacker profile, or fund flow