• PIN Transaction Security Engineer (Hardware / Software)

    地點/地点 CN-44-Guangzhou
    工作 ID/工作 ID
    8021
    有職位空缺的 #/有职位空缺的 #
    1
    類別/类别
    IT
  • 概覽/概览

     

    LinkedIn

     公司简介

    地点 广州

    UL是一家全球性独立公司,致力于创造更安全的生活和工作环境。UL在全球有100余家办公处和实验室,超过14000名员工。

    UL支付交易安全部门致力于创新支付交易安全技术,例如非接触信用卡支付、移动支付(NFC)。UL支付交易安全协助客户制定制胜策略并将其转化为有用的产品(用于移动支付、交通票务、电子识别等);同时提供咨询服务,安全评估培训,测试服务和测试工具。

    UL支付交易安全实验室是PCI SSC (https://www.pcisecuritystandards.org/) 指定的认证实验室,具备评估PCI PTS, PCI DSS和PA DSS的资质。同时,UL支付交易安全实验室也提供PCI PIN audits, 以及支付系统和安全嵌入式系统的咨询和培训。我们的客户来自于世界各地,主要集中在亚洲。

    优力检测服务(广州)有限公司 (UL Verification Service (Guangzhou) Co., Ltd.)支付交易安全实验室(Identity Management & Security Laboratory)目前正在进行扩张,我们计划招聘PTS硬件工程师,PTS软件工程师以及FIPS工程师,期待您的加入!

     

     

    UL Verification Services is part of the UL, a global independent company dedicated to promoting safe living and working environments. The company has more than 100 offices and labs across the world and more than 14,000 employees.

     

    UL Identity Management & Security (IMS) is the independent go-to party for new innovative transaction security technology, for instance for contactless credit card payments or for mobile payments (NFC) technology. We help our clients to define winning strategies and convert these into useful products (for mobile payments, transit ticketing and electronic identification). We offer advisory services, training security evaluation services, test services and test tools.

     

    The only PCI PTS accredited laboratory outside of Europe and North America is based in Melbourne, UL Identity Management & Security has clients around the world with a specific focus on Asia. Locally, UL  Identity Management & Security is accredited to perform PCI DSS assessments, as well as PA DSS evaluations of payment software.

     

    UL Identity Management & Security (IMS) performs; PCI PIN audits, general consulting and education services around payment systems and embedded system security.

     

    UL Identity Management & Security (IMS) is looking for a new colleague in our China team! Due to the expansion we are hiring security PIN Transaction Security Engineers (PTS)  (Software / Hardware) who will be based in Guangzhou. Prior information security experience is not essential, although a general security mindset is required. Employees will receive the same training and education which UL Identity Management & Security (IMS) provides to financial institutions and security product vendors around the world.

     

    職責/职责

    招聘内容

    PCI PTS

    PCI是由支付卡行业五大卡组织 (American Express, Discover, JCB international, MasterCard, Visa Inc.)联手创立的支付卡产业安全标准委员会(PCI SSC)规定并发布的整个产业的安全标准,包含PCI PTS, PCI PIN, PCI DSS, PCI PA DSS, PCI SPoCPCI P2PE标准。PCI PTS全称是PCI 个人支付卡密码交易安全规范 (PCI PIN Transaction Security) ,适用于支付终端产品 (包含POS机,密码键盘,读卡器等等) 对个人支付卡以及密码的保护。

    PTS 工程师 硬件方向

    工作内容:

    • 负责对支付终端产品 (POS机,密码键盘,读卡器等等)的硬件安全检测和评估
    • 分析产品的硬件结构,编写攻击案例,基本标准完成评估报告
    • 与软件工程师一起合作完成项目
    • 帮助客户完成产品的合规

     

    PTS Engineer - Hardware

     

    • Good knowledge of analog/digital circuit

    • Experience reviewing schematic, PCB and Gerber files. Skills of PCB reverse engineering is a plus

    • Familiar with skills of circuitry testing and debugging and hardware hacking/modification/penetration is a plus

    • Knowledge of common processors (especially ARM-M and ARM-A architecture based processors)

    • Familiar with capturing and analyzing signals using common equipment (including but not limited to oscilloscope, multi – meter, signal generator, logic analyzer)

    • Familiar with at least one of following languages : ASM, C, C++, C#, python

    • Experience on embedded electric device development is a plus

     

    PTS 工程师 软件方向

    工作内容:

    • 负责对支付终端产品(POS机,密码键盘,读卡器等等)的软件和网络安全检测和评估
    • 分析产品的软件架构,审核代码和文档,基本完成评估报告
    • 与硬件工程师一起合作完成项目
    • 帮助客户完成产品的合规

     

     

    PTS Engineer - Software  

     

    • Good knowledge of OS such as Linux/Android including architecture, components and security features
    • Good knowledge of Cryptographic theory including symmetric and asymmetric algorithms and implementations
    • Good knowledge of common processors (especially ARM-M and ARM-A architecture based processors)
    • Familiar with cyber security such as TCP/IP, HTTP, HTTPS, TLS Perform tools with at least one of following languages : C, C++, Java, C# Experience on software development on embedded electric device is a plus
    • Experience on payment industry and skill of software reverse engineering is a plus.
    • Knows network penetration testing

     

    What You’ll Achieve

    • Participate in UL Identity Management & Security (IMS) Technical Product and Services training, methodology, and enablement
    • Begin participation in field activities with clients by shadowing seasoned security engineers/senior security engineers and practicing enablement gained from training
    • Execute implementations for customers and start on your journey to internalize business outcomes and business context relevance to UL Identity Management & Security (IMS) implementation methodologies and approaches
    • Complete UL Identity Management & security technical certifications and fully ramp on technology and implementation methodologies; start to develop and contribute subject-matter expertise and project deliverables to review for incorporation into internal knowledge exchanges
    • Begin UL Identity Management & Security (IMS) ambassador and guidance of junior services team members in our services organization

     

     

     

    資歷/资历

    要求:

    • 熟练掌握模拟/数字电路设计
    • 具备分析原理图,PCB和Gerber的经验;具备对PCB进行逆向工程的技能优先
    • 熟悉电路测试、调试,以及硬件攻击、修改、入侵
    • 掌握通用处理器,尤其是ARM-M和ARM-A结构的处理器
    • 熟练使用通用工具抓取和分析信号,例如示波器,万用表,信号发电机,逻辑分析仪等
    • 熟悉至少一种语言:ASM,C语言,C++, C#, python
    • 具备嵌入式电子设备开发经验优先
    • 有良好的团队合作精神,沟通能力佳

     

     

    要求:

    • 熟练掌握Linux/Android操作系统,包含结构,组件以及安全特性
    • 熟练掌握密码学原理,包含对称算法和非对称算法及其实现
    • 熟悉通用处理器,尤其是ARM-M和ARM-A架构的处理器
    • 熟悉网络安全协议,例如TCP/IP, HTTP, HTTPS, TLS
    • 熟悉至少一种语言:ASM,C语言,C++, C#, python
    • 具备嵌入式电子设备软件开发经验优先
    • 具备支付行业工作经验优先
    • 具备软件逆向工程技能优先
    • 具备网络入侵测试经验优先
    • 有良好的团队合作精神,沟通能力佳

     

    • University Degree (Equivalent to Bachelor’s Degree) in Electronic/Computer Science/Computer Engineering/Electrical Engineering. Fresh graduates are welcome to apply.

     

    • Good skills in embedded software preferred.

     

    • Experience in hardware development or in a laboratory environment and skills in developing codes in different languages (C, C++, assembly) preferred.

     

    • Familiar with test equipment and working in a multi-skills environment mixing electronic, optical, security, mechanical, and IT.

     

    • Excellent communications and interpersonal skills.

     

    • A self-motivated team player who is able to work independently and likes to bring new ideas for technical development.

    選項/选项

    Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
    在您的新聞推送上共用/在您的新闻推送上共享

    與我們聯系 !/注册接收职位提醒!

    還未準備申請?/ 未准备好应聘? 與我們聯系/花一分钟时间注册信息 ,作進一步考慮/以获得UL最新发布职位信息提醒。