Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
public:hire [2021-02-02 07:11] xsvendapublic:hire [2024-04-23 09:16] (current) – [Publications] xukrop
Line 1: Line 1:
 +~~NOTOC~~
 +
 ====== Job offerings - CRoCS ====== ====== Job offerings - CRoCS ======
  
-<callout type="info" icon="true"> +This page lists currently open employment and PhD positions to our lab. 
-**Position (tenure-track) in CybersecurityFaculty of InformaticsMasaryk UniversityCzech Republic **+ 
 +===== Employment positions ===== 
 + 
 +We currently have no employment positions open, but feel free to see the list of [[public:research:main|current research projects]] to see the areas we work in. 
 + 
 +===== PhD positions ===== 
 + 
 +<grid> 
 +<col xs="12" sm="8" lg="8"> 
 +<TEXT size="large"> 
 +{{fa>font-awesome}}\_//Topic:// Examining the ecosystems of computer security certification schemes 
 + 
 +{{fa>user-circle-o}}\_//Supervisor:// Vashek Matyas %%<%%<matyas@fi.muni.cz>%%>%% 
 + 
 +{{fa>industry}}\_//Industry cooperation:// [[https://research.redhat.com/|Red Hat Czech s.r.o.]] 
 + 
 +{{fa>calendar}}\_//Start date:// September 2024 or February 2025 
 +</TEXT> 
 +</col> 
 + 
 +<col xs="12" sm="4" lg="4"> 
 +<TEXT align="right"> 
 +<button type="primary" icon="fa fa-fw fa-paper-plane">[[mailto://matyas@fi.muni.cz| Contact the supervisor]]</button> 
 +</TEXT> 
 +</col> 
 +</grid> 
 + 
 +<TEXT size="large"> 
 +We are looking for **two doctoral students to work in the areas of computer security and machine learning** improving the security certification scene. The students will **join an existing research team around the [[https://seccerts.org|sec-certs]] project**. Positions are fully funded by the faculty with extra remuneration provided by the industrial partner. 
 +</TEXT> 
 + 
 +<grid> 
 +<col xs="12" sm="6" lg="6"> 
 + 
 +==== Topic specification ==== 
 + 
 +The aim of these PhD positions is to analyse and improve the ecosystems of products certified under security certification frameworks such as FIPS 140-2/3 and Common Criteria. Even such security-certified products suffer from critical vulnerabilities, and assessing which certified products are impacted by such vulnerabilities is complicated due to the large amount of unstructured certification-related data and unclear relationships between the certificates. The tooling we develop automates the analysis of tens of thousands of certification-related documents, extracting machine-readable features where manual analysis is unattainable. 
 + 
 +==== Expected expertise ==== 
 + 
 +We expect candidate(s) who have (or soon will havea MSc degree or equivalent and a solid background in computer science or engineeringwith some background either in computer security or machine learning or natural language processing (though not necessarily both). Fluent communication in spoken and written English is expected. 
 + 
 +==== The team ==== 
 + 
 +The academic research team you'll join consists of your supervisortwo part-time engaged assistant professors and multiple supervised bachelor and master students. Furthermoremultiple Red Hat engineers are engaged to help the application of the project results at Red Hat as well as the wider certification community. 
 + 
 +</col> 
 +<col xs="12" sm="6" lg="6">
  
-**Deadline for application:** February 28, 2021.</callout>+==== The sec-certs project ====
  
-Join the vibrant security and applied crypto research group in Brno, Czechia! Join the research team that won the 2016 USENIX Security Symposium Best Paper Award2017 ACM CCS Real-World Impact Awardor 2020 CHES Best Paper Award. The team that helped hundreds of graduates in the security Master programs, has been involved in +Sec-certs is a tool for data scraping and analysis of security certificates from Common Criteria and FIPS 140-2/3 frameworks. It periodically updates the database of certificatesprocesses the available certification PDFs and metadata and enriches them by adding new metadata (e.g. detected certificate dependencies) or cross-referencing other datasets (CPEsCVEs, CWEs, …). The whole dataset is open an available through the web interface at [[https://seccerts.org|seccerts.org]].
-both fundamental and applied crypto/security/privacy research projects and industry partnerships+
  
-This position is aimed to strengthen the work of the [[https://crocs.fi.muni.cz/|Centre for Research on Cryptography and Security (CRoCS]]) at the Faculty of Informatics. CRoCS works to improve security and privacy of real-world solutions through applied research (often in cooperation with industry) and advanced education of future security professionals. System security or network security focus are most desired, yet the abilities to work with a team of graduate students and faculty on research targeting top security/crypto conferences and to engage both undergraduate and graduate students in both educational and research exercises are most critical. The successful candidates would work the CRoCS centre, headed by prof. Vaclav (Vashek) Matyas. More info is at +[[https://seccerts.org/|{{:public:research:sec-certs-logo.png?nolink&200|sec-certs project}}]] 
-https://crocs.fi.muni.cz/public/research/main .+{{:public:research:logo.png?400|}}
  
-Expert knowledge suitable for teaching is expected in at least one of the areas covered by courses: +\_
-  * [[https://is.muni.cz/course/fi/podzim2020/PV181?lang=en | PV181 Laboratory of security and applied cryptography]] +
-  * [[https://is.muni.cz/predmet/fi/podzim2019/PV182?lang=en|PA193 Secure coding principles and practices]] +
-  * [[https://is.muni.cz/course/fi/jaro2020/PA197 | PA197 Secure Network Design]]+
  
-The starting salary for this Assistant Professor position is **80,000 CZK**, and with the progress in this tenure-track position can in no more than 3 years be modified based on the level of involvement in research and educational projects.+==== Industry involvement ====
  
-Candidates with borderline record and/or missing skills may be offered a Lecturer position for the start of their engagement. The monthly salary for the Lecturer position 49,000 CZK.+The successful candidate(s) will work with CRoCS during the whole duration of the project, while cooperation with Red Hat is expected in a form of regular meetings with Red Hat experts where progress will be evaluated and next targets agreed. The work to be undertaken during all years of research will be at the intersection of computer security and machine learning.
  
-More details re. the call and applications are available at +In case of inquires related to the industrial cooperation, please contact Martin Ukrop %%<%%<mukrop@redhat.com>%%>%%.
-https://www.muni.cz/en/about-us/careers/vacancies/59434+
  
-Any queries re. the submission shall be sent topers@fi.muni.cz. Queries re. the position as such can be addressed to Prof. Vashek Matyas.+[[https://research.redhat.com/|{{:wiki:redhat.png?nolink&200|Red Hat}}]]
  
-**Deadline for application:**  February 28, 2021.+</col> 
 +</grid>
  
-See the list of [[public:research:main|current research projects]] to see the areas we work in.+==== Publications ====
  
 +{{section>publications:keywords:sec-certs&noheader&fullpage}}
 +==== Interested? ====
  
-----+  * Are you interested in the position? The next step is to contact the supervisor to discuss each other's expectations and meet the rest of the team. 
 +  * Do you know someone who may be interested? Please refer them to this web page. 
 +  * Do you know a relevant place to hang a poster? Download it below.
  
 +<button type="primary" icon="fa fa-fw fa-paper-plane">[[mailto://matyas@fi.muni.cz| Contact the supervisor]]</button>
 +\_<button icon="fa fa-fw fa-file">[[https://crocs.fi.muni.cz/_media/public/research/2024-04_sec-certs_phd-poster.pdf| Poster (A4)]]</button>
 +\_<button icon="fa fa-fw fa-file-image-o">[[https://crocs.fi.muni.cz/_media/public/research/2024-04_sec-certs_phd-slide.pdf| Presentation slide (16:10)]]</button>