Senior Offensive Security Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Offensive Security Specialist (Cybersecurity): Perform web application, mobile, API, and cloud penetration testing, source code reviews, and red-teaming for digital asset platforms with an accent on vulnerability exploitation and custom tool development. Focus on diagnosing vulnerabilities, creating detailed risk reports, and providing technical leadership to engineering teams across multiple time zones.
Location: Hong Kong
Company
Institutionally focused global digital asset platform providing regulated exchange, indices, market data, and insights via Exchange and CoinDesk services.
What you will do
- Perform web application, mobile, API, and cloud penetration testing.
- Conduct source code reviews and red-teaming activities.
- Develop custom tools and automation for vulnerability discovery and attack simulation.
- Exploit vulnerabilities in systems and communicate risks to technical and non-technical staff.
- Create detailed technical reports with actionable remediation recommendations.
- Provide technical leadership and mentorship to security and engineering teams.
Requirements
- 7+ years in cybersecurity with senior-level penetration testing and application security assessments.
- Experience with Burp Suite, Nessus, Kali Linux, OWASP Top 10, and similar tools.
- Knowledge of mobile/iOS/Android, API/REST/GraphQL assessments, and cloud (AWS, Azure, GCP).
- Proficiency in C/C++, Java, JavaScript, Python, or Go; Linux systems; network/protocol basics.
- Understanding of cryptographic concepts, Agile, CI/CD, SAST/DAST tools.
- Hold certifications like OSCP, OSCE, or OSWE.
Nice to have
- Strong self-starter with independent operation skills.
- Experience in external communications, papers, and conference presentations.
Culture & Benefits
- Work in a fast-evolving, globally diverse community with integrity at core.
- Collaborate with elite security team on industry-leading crypto services.
- Support multiple time zones and engineering teams.
- Equal opportunity employer encouraging diverse perspectives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →