Eaton China logo
伊顿中国
Senior Cybersecurity Engineer

Senior Cybersecurity Engineer

发布于 大约 3 小时前

普通员工/个人贡献者

深圳市
高级经验
全职员工
仅现场办公
本科
信息安全
Iec 62443
Iot Security
Kali Linux
Nessus
Ul 2900
Black Duck
Defensics

AI 估算 · 25k–40k

高级网络安全工程师,深圳,跨国巨头,经验要求高,市场紧缺,薪资竞争力强。

职位详情

关于这个职位

作为伊顿中国的产品网络安全工程师,你将负责将网络安全融入产品全生命周期,从概念设计到部署维护

与全球团队协作,进行威胁建模、渗透测试和安全评估,确保产品符合UL 2900和IEC 62443等标准
该职位适合有5年以上经验、熟悉IoT和嵌入式安全的专业人士

最低要求

Bachelor's or master's degree in Cybersecurity, Computer Science, Electronics Engineering, Electrical Engineering, or a related field.

More than 5 years of relevant experience in product cybersecurity, embedded security, IoT security, or application security.
Proven experience across multiple phases of the Secure Product Development Lifecycle, including threat modeling, security testing, and implementation validation.
Strong experience in IoT, embedded, and connected product security.
Hands-on experience in penetration testing and security assessment using tools such as Burp Suite, Kali Linux, Nessus, Coverity, Black Duck, and Defensics.
Solid understanding of common attack vectors and effective mitigations across web, IoT, operating systems, and cloud environments.
Strong knowledge of communication and protocol security, including HTTPS, MQTT, SSH, Wi-Fi, Bluetooth, Zigbee, and ICS protocols.
Proven ability to conduct threat modeling and risk assessments and translate findings into actionable security requirements.
Programming or scripting experience in one or more languages.
Strong collaboration skills and ability to work effectively with global, cross-functional teams.
Fluent in English, able to collaborate and communicate effectively with global teams.

工作职责

Lead threat modeling and risk assessment activities during early design phases, ensuring cybersecurity requirements are identified and integrated in alignment with relevant standards.

Perform vulnerability assessments and penetration testing across Eaton products and solutions, including IoT devices, embedded systems, web/mobile applications, and industrial systems, to identify and validate security risks.
Partner with product and engineering teams to design and implement secure solutions, providing hands-on guidance for complex cybersecurity features.
Deliver cybersecurity training and promote security awareness across engineering, product management, and other business functions.
Continuously monitor the evolving threat landscape, emerging technologies, and industry standards, driving improvements in internal cybersecurity frameworks and processes.
Support product cybersecurity certification activities, ensuring compliance with standards such as UL 2900 and IEC 62443.

优先资格

Knowledge of authentication, access control, applied cryptography, secure boot, firmware integrity, and secure update mechanisms is preferred.

Familiarity with AI-assisted cybersecurity workflows and security considerations for AI-enabled products is a plus.

AI 洞察

优缺点分析

优点

  • 网络安全是高速增长赛道,人才需求旺盛,职业前景广阔
  • 伊顿作为行业巨头,提供全球化工作平台和顶级项目资源
  • 技能积累全面,涵盖IoT、嵌入式、Web等多领域,提升综合竞争力
  • 安全事件响应可能涉及紧急工作,需要一定抗压能力
  • 适合有5年以上网络安全经验、热爱技术钻研、希望在工业/IoT安全领域深耕的专业人士

缺点 / 挑战

  • 工作涉及多类型设备和系统,技术广度要求高,学习压力较大
  • 需与全球团队协作,对英语沟通能力有较高要求

角色解读

  • 深耕产品网络安全,成为领域专家或安全架构师
  • 横向拓展至云安全、应用安全或安全管理岗位
  • 在全球团队中积累经验,向首席安全官(CSO)或安全总监发展
  • 在产品设计初期主导威胁建模和风险评估,确保安全需求融入产品开发
  • 执行渗透测试和漏洞评估,覆盖IoT设备、嵌入式系统、Web/移动应用等
  • 与产品和工程团队合作设计安全解决方案,并提供指导
  • 提供网络安全培训,并推动安全意识提升
  • 熟悉产品安全开发生命周期,包括威胁建模、安全测试和实现验证
  • 精通IoT和嵌入式安全,掌握常见攻击向量和缓解措施
  • 熟练使用渗透测试工具(如Burp Suite、Kali Linux、Nessus等)
  • 了解通信协议安全(如HTTPS、MQTT、Bluetooth、Zigbee等)

申请策略

  • 了解伊顿的“Security by Design”理念,在面试中展现对安全设计的思考
  • 准备一个完整的项目案例,展示从威胁建模到修复的全流程能力
  • 突出在威胁建模、渗透测试和产品安全生命周期中的实际项目经验
  • 列举使用过的安全工具和成功案例(如发现的漏洞及修复方案)
  • 强调对IoT或嵌入式安全的深入理解,以及相关认证(如CISSP、CEH等)
  • 补充AI辅助安全(如AI-driven threat detection)的知识,这是加分项
  • 熟悉IEC 62443和UL 2900标准,为认证活动做好准备

面试指南

  • 使用STRIDE或攻击树等模型进行威胁建模,结合业务场景识别风险,并将结果转化为安全需求
  • 采用案例叙述法(STAR):情景、任务、行动、结果,突出技术细节和量化成果
  • 如何为新IoT产品进行威胁建模?请描述具体步骤和方法
  • 介绍一次你发现的严重安全漏洞及修复过程
  • 如何确保嵌入式设备的安全启动(secure boot)和固件完整性?
  • 你如何跟踪最新的安全威胁和漏洞,并应用到工作中?
  • 请解释IEC 62443中的安全等级(SL)概念及实现要求
  • 复习IoT和嵌入式系统的常见安全漏洞类型(如缓冲区溢出、固件破解)

职位点评

72
综合评分

跨国巨头高级安全岗,技术前沿,发展空间大,但工作地点固定且加班情况未明确。

从薪资福利、成长空间、工作节奏和岗位方向综合评估,方便横向比较。

更适合这类人
最看重技能成长和职业发展,对WLB要求不高的求职者。
表现最好
薪资福利
相对薄弱
工作生活
薪资福利80
成长发展80
工作生活50
使命价值70

薪资福利

80较高

跨国巨头+高级岗位,薪资在深圳具有较强竞争力,但JD未明确提及福利细节。

薪资信号未披露(AI估算:25K-40K/月)

成长发展

80较高

涉及前沿网络安全技术,有培训和认证支持,晋升路径清晰。

技术前沿主流现代技术
技术栈IoT Security、Embedded Security、Penetration Testing、Threat Modeling、IEC 62443、UL 2900
成长机会cybersecurity training、certification activities
业务类型ambiguous

工作生活

50较低

仅现场办公,未提及弹性工作,深圳科技园可能通勤较长。

工作模式仅现场办公
办公地点未明确
加班情况未提及(无法判断)

使命价值

70中等

网络安全对社会具有保护性价值,但JD更侧重技术实现而非使命感。

行业发展高速增长赛道
社会影响中性/一般
使命信号protecting the environment、improving the quality of life
创新程度积极采用新技术
Watch Jobs