12 часов назад
Senior Application Security Engineer (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (Web3): Auditing business code and governing security for cryptocurrency exchange and digital finance platform systems with an accent on Java and Go code review, vulnerability research, and business logic risk analysis. Focus on reproducing emerging vulnerabilities, designing security solutions, and driving Security Development Lifecycle and risk governance implementation.
Location: Abu Dhabi, UAE or Kuala Lumpur, Malaysia
Company
operates a cryptocurrency exchange and digital financial platform serving users across trading, payments, wealth management, custody, institutional services, and Web3.
What you will do
- Conduct manual security audits of business code written in Java, Go, JavaScript, C++, and other technologies.
- Prepare security audit reports and identify risks in business architecture, processes, logic, requirements, and technical implementation plans.
- Track emerging domestic and international security developments and reproduce newly discovered vulnerabilities.
- Design security solutions, drive their implementation, and support security risk governance.
- Develop a deep understanding of product business processes to identify and address application security risks.
Requirements
- Associate degree or above; requirements may be relaxed for candidates with strong capabilities.
- At least 3 years of business development or security audit experience based on Java or Go, including participation in or leadership of SDL implementation.
- Expert-level proficiency in Java and/or Go, including language-specific characteristics, mainstream frameworks, and code auditing.
- Strong knowledge of common security vulnerabilities, OWASP Top 10, white-box audit methodologies, vulnerability discovery, and exploitation techniques.
- Solid penetration testing knowledge and practical use of common penetration testing methods.
- Ability to use AI tools to improve security work efficiency, supported by strong analytical, communication, coordination, organizational, and documentation skills.
Nice to have
- Experience with TEE, encryption, data protection architectures, and security solution implementation.
- High-quality vulnerability submissions to domestic or international SRC or bug bounty platforms.
- Discovered CVE or CNVD vulnerabilities.
- Demonstrated Java or Go code audit results.
Culture & Benefits
- Study Growth Fund for professional development and continuous learning.
- Internal team-building activities, workshops, and collaboration events.
- International collaboration with colleagues from around the world.
- Career advancement opportunities and internal mobility within a rapidly expanding global company.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
20 часов назад
Application Security Engineer\Lead (Fintech)
20 часов назад
Cyber Security Vulnerability Researcher (Web Applications)
1 день назад
Application Security Engineer
2 дня назад
Application Security Engineer (AI)
1 день назад
Application Security Engineer (AI)
1 день назад