Назад
Company hidden
12 часов назад

Senior Application Security Engineer (Web3)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UAE/Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Web3): Auditing business code and governing security for cryptocurrency exchange and digital finance platform systems with an accent on Java and Go code review, vulnerability research, and business logic risk analysis. Focus on reproducing emerging vulnerabilities, designing security solutions, and driving Security Development Lifecycle and risk governance implementation.

Location: Abu Dhabi, UAE or Kuala Lumpur, Malaysia

Company

hirify.global operates a cryptocurrency exchange and digital financial platform serving users across trading, payments, wealth management, custody, institutional services, and Web3.

What you will do

  • Conduct manual security audits of business code written in Java, Go, JavaScript, C++, and other technologies.
  • Prepare security audit reports and identify risks in business architecture, processes, logic, requirements, and technical implementation plans.
  • Track emerging domestic and international security developments and reproduce newly discovered vulnerabilities.
  • Design security solutions, drive their implementation, and support security risk governance.
  • Develop a deep understanding of product business processes to identify and address application security risks.

Requirements

  • Associate degree or above; requirements may be relaxed for candidates with strong capabilities.
  • At least 3 years of business development or security audit experience based on Java or Go, including participation in or leadership of SDL implementation.
  • Expert-level proficiency in Java and/or Go, including language-specific characteristics, mainstream frameworks, and code auditing.
  • Strong knowledge of common security vulnerabilities, OWASP Top 10, white-box audit methodologies, vulnerability discovery, and exploitation techniques.
  • Solid penetration testing knowledge and practical use of common penetration testing methods.
  • Ability to use AI tools to improve security work efficiency, supported by strong analytical, communication, coordination, organizational, and documentation skills.

Nice to have

  • Experience with TEE, encryption, data protection architectures, and security solution implementation.
  • High-quality vulnerability submissions to domestic or international SRC or bug bounty platforms.
  • Discovered CVE or CNVD vulnerabilities.
  • Demonstrated Java or Go code audit results.

Culture & Benefits

  • Study Growth Fund for professional development and continuous learning.
  • Internal team-building activities, workshops, and collaboration events.
  • International collaboration with colleagues from around the world.
  • Career advancement opportunities and internal mobility within a rapidly expanding global company.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →