Discover Great Companies Discover Great Clients
Companies Salaries Jobs
Jobs |
Jobs Companies Salary Majors

安全分析师岗位职责

  • 安全分析师 岗位职责来自 中资网络信息安全科技有限公司

    򀀇
    岗位职责:
    1.负责客户网络安全运营分析工作,基于全流量日志、SOC 日志、DNS 日志、通联日志、威胁情报等多源数据,开展攻击事件发现、告警研判、失陷线索排查、攻击路径还原、应急响应支撑及上机处置,形成从发现、分析到处置的安全运营闭环。
    2.参与威胁检测规则与分析模型建设,围绕暴力破解、弱口令登录、异常通信、僵木蠕外联行为、DDOS、疑似失陷主机等场景,设计检测思路和研判逻辑,提升未知威胁、可疑网络行为及高风险资产异常的发现能力。
    3.参与安全运营智能化体系建设,设计并落地基于 AI 的安全分析架构,支撑日志聚合、数据清洗、告警降噪、告警研判、样本分析、交付审查及分析辅助等能力建设,提升安全运营分析效率与告警处置质量。
    岗位要求:
    1、3年以上信息安全相关工作经验,重点本科以上学历,计算机或相关专业优先。
    2、熟悉TCP/IP和HTTP协议、路由与交换技术等,熟悉网络及操作系统基础原理;
    3、熟悉网络攻击的攻击原理、攻击手段、攻击检测方法等;
    4、熟悉各类漏洞的原理、利用方式、检测方式;
    5、熟练掌握网络协议、熟练使用各类抓包分析工具,能够独立开展网络安全事件分析、追踪溯源等工作;
    6、熟悉常见网络安全产品和安全服务,具备某一方向的实际交付经验;
    7、具有优秀的沟通协调和解决问题能力、良好的团队合作意识和抗压能力;
    8、有AI+安全相关经验;
    9、拥有cisp等行业相关资质证书。
    能力优秀者,薪酬面议。
    更新于 2026-08-08
  • 成都 - 信息安全分析师(安全运营), ITS 岗位职责来自 毕马威

    򀀇
    KPMG China provides multidisciplinary services from audit tax to advisory, with a strong focus on serving our clients’ needs their industries. Not only do we have an overriding commitment to provide the highest quality services four clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment community. At KPMG, you’ll translate insights action reveal opportunities fall—our teams, our clients our world.



    Service Line Overview

    Information Technology Services (ITS) is a single, integrated serviceganization with global, national practice-based components that work together to meet service expectations deliver priority projects to KPMG China.



    About The Role

    As a part of the Security Operations Centre, you will work with a team of SOC analysts to deliver professional cyber security services, which spans the full range of security monitoring, incident investigation, response reporting, threat intelligent vulnerability management, other security analytics functions.



    Key Responsibilities 主要职责

    Ensuring timely incident identification, assessment, containment, recovery.
    负责网络安全事件的识别、评估、遏制与恢复全流程处置工作;

    Act as incident response specialist fcyber security incidents when required coordinate resources teams across the firm to adequately respond to security threats.
    紧急事件发生时担任应急响应分析师,统筹协调跨部门资源与团队协助,高效处置各类安全威胁;

    Develop enhance incident response processes playbooks.
    梳理、搭建并持续优化应急响应流程与标准化处置预案(playbook);

    Provide cyber security guidance on operational topics such as security incident response, vulnerability management, data breach prevention, security alert monitoring, etc.
    针对安全事件处置、漏洞管理、数据泄露防护、安全告警监控等日常运营工作,提供专业安全指导;

    Prompt response to latest cyber security news vulnerability updates.
    实时跟进行业*新安全动态、高危漏洞通告,并同步落地对应防护应对措施;

    Perform threat management, threat modelling, identify threat actors develop security monitoring use cases.
    开展威胁管理与威胁建模工作,梳理攻击者画像,输出检测规则与用例;

    Measure SOC performance metrics – ensuring compliance to policies SLA, process adherence process optimization.
    统计SOC安全运营核心指标,保障各项工作符合内部制度、服务SLA,跟进流程落地执行情况并推进持续优化;

    Ensure compliance with internal standards, international standard like ISO27001 regulatory requirements in China.
    落实内部安全规范、ISO27001等国际体系标准及国内相关法律法规、监管合规要求。


    Experience & Background 任职要求

    Bachelor’s degree, with a majin IT other relevant disciplines.
    本科及以上学历,计算机、信息技术、网络安全等相关专业;

    5+ year experience in IT Security / SOC / incident detection response field.
    拥有5年及以上信息安全、SOC安全运营、安全检测与应急响应相关从业经验;

    Holder of CISSP, CISM and/CISA preferred.
    持有CISSP、CISM、CISA等安全资质证书者优先;

    Experience in network security, cloud security container security.
    掌握网络安全、云安全、容器安全相关技术,具备落地实操经验;

    Proven experience in incident detection & response in multi-cloud hybrid-cloud environments.
    具备多云、混合云架构场景下安全检测、应急响应实战经验;

    Experience in data analytics, process automation, application development will be an advantage.
    具备数据分析、安全流程自动化、简易开发能力者优先考虑;

    Proven experience in SIEM, SOAR TIP tools, develop enhance IR playbook, security solutions evaluation recommendations.
    熟练使用SIEM、SOAR、威胁情报平台(TIP)等安全工具,可独立编写优化应急处置预案(IR playbook),完成安全产品测评、选型及方案推荐;

    Technical knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST.
    熟悉MITRE ATT&CK框架、Cyber Kill Chain、NIST等主流安全模型;

    Experience with endpoint security products, firewall technologies, threat intelligence, penetration tests, information security principles practices will be an advantage.
    了解终端安全产品、防火墙技术、威胁情报运营、渗透测试及信息安全基础理论与实操者优先;

    Experience with China brsecurity vendors will be an advantage.
    熟悉国产主流安全厂商产品与方案者优先;

    Strong desire to develop follow standards procedures.
    具备较强的体系规范搭建意识,习惯遵循并落地标准化流程制度。



    About KPMG



    At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance fany form of discrimination against any persons. It is important fus to an inclusive, diverse agile workplace four people to develop thrive at both a personal professional level.



    We strive to make ESG (environmental, social governance) a watermark running through ourganisation; from empowering our people to become agents of positive change, to providing better solutions services to our clients. To lead by example, we launched Our Impact Plan (OIP) which includes our ESG commitments progress across four key pillars – Planet, People, Prosperity Governance.

    We encourage you to come as you are, we welcome all qualified candidates to apply, hope you unlock opportunities with us. Visit KPMG China website fmore company information.

    Please note that all information in this form has been voluntarily supplied will be used by KPMG fselection purposed only.
    更新于 2026-08-07
  • 网络安全分析师 岗位职责来自 航天信息北京

    򀀇
    1.参与信息化系统安全体系建设,负责落实安全模块设计与实现,范围包括身份认证、访问控制、数据加密、终端防护等层面,确保系统符合网络安全等保2.0三级及以上标准。
    2.负责牵头设计多因子认证(MFA)方案落地,调研评估身份认证前沿技术,组织设计开发新型认证方式的安全集成。
    3.负责认证类产品部署落地,包括认证检测服务部署、性能调优、安全策略制定、网络路径管理等。
    4.负责对接认证技术的外联工作,协调资源组织联调联试,推动安全方案落地。
    5.负责保障系统认证体系符合《个人信息保护法》《网络安全法》等法规要求,设计安全审计机制,定期开展系统风险评估与漏洞排查。
    任职要求:
    1.本科及以上学历,计算机科学与技术、网络空间安全、信息安全等相关专业。
    2.5年以上网络安全领域工作经验,其中至少3年以上大型政企(政务/金融优先)身份认证体系或安全架构设计经验,并熟悉密钥管理体系。
    3.主导过1个大型政务或金融系统身份认证体系建设项目,了解OAuth2.0、SAML2.0等主流身份协议,熟悉生物识别、数字证书等认证技术,能独立设计多因子认证架构者优先。
    4.具备移动应用安全领域项目经验,熟悉逆向工程、漏洞挖掘与防护方案设计。
    5.参与过第三方系统对接的安全认证项目,熟悉接口联调、安全测试全流程,具备风险处置和应急响应经验者优先。
    6.具备较强的方案撰写能力,能独立输出安全体系设计文档、技术方案、风险评估报告。
    7.优秀的跨部门协作与沟通能力,能协调内外部资源推动项目落地,应对复杂业务需求。
    8.具备技术领导力,能带领团队攻克技术难点,指导中级工程师成长。
    9.持有CISP(注册信息安全专业人员) 认证、CISSP(注册信息系统安全专业人员)、CSSLP(注册安全软件生命周期专业人员)者优先。
    更新于 2026-08-17
  • XDR安全分析师(J11728) 岗位职责来自 山石网科

    򀀩
  • XDR安全分析师(J11728) 岗位职责来自 山石网科

    򀀩
  • 车辆网络安全分析师 岗位职责来自 长春市博图工业技术有限公司

    򀀩
  • 内审数据安全分析师-AI方向 岗位职责来自 上海药明康德新药开发有限公司

    򀀩
  • 大数据安全分析师 岗位职责来自 博彦科技承德有限公司

    򀀩
  • 被动安全(碰撞安全分析师) 岗位职责来自 合肥创智汽车技术开发有限公司

    򀀩
  • 网络安全分析师 岗位职责来自 河北中兴冀能电力发展有限公司数字科技分公司

    򀀩
加载更多

招聘学历要求:本科最多

安全分析师需要什么学历?大专占13.2%,本科占77.6%……想知道其他学历占比多少,请点击查看

按学历统计

说明:薪资一般与学历正相关,一般学历越高,工资越高。安全分析师工资按学历统计,大专工资¥11.6K,想知道其他学历工资,请点击查看

招聘经验要求:3-5年最多

安全分析师经验要求高吗?1-3年占15.8%,3-5年占44.7%……想知道其他经验占比多少,请点击查看

按经验统计

说明:工作经验是影响工资水平的重要因素,一般经验越丰富工资越高。安全分析师工资按经验统计,1-3年工资¥19.9K,想知道其他经验工资,请点击查看

安全分析师工资待遇怎么样

薪酬区间: 4.5-50K,其中44.9%的岗位拿¥20-50K/月,年薪¥24-60W

数据统计来自近一年 69 份样本,截至 2026-09-14

¥20-50K
44.9%的岗位拿
?
月平均工资
年薪统计

说明:安全分析师一个月多少钱?数据统计依赖于各平台发布的公开薪酬,仅供参考。

全国排名: 人工智能 / 软件 / 公共安全 /
学历教育
客服
由百度提供