[Security] Senior Application Security Engineer
Abu Dhabi, UAE; Kuala Lumpur, Malaysia·Posted 5d ago
cryptoweb3gogolang
<div class="content-intro"><p><strong>About Us</strong></p> <div data-page-id="HladdPLXIoNz4nxkqkCuk4rAs8v" data-lark-html-role="root" data-docx-has-block-data="false"> <div class="ace-line ace-line old-record-id-XCikdRR2xoZIjdxtCKcuOflrs8d">Established in 2018, Bybit is one of the world’s leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries and regions. Powered by world-class technology and a user-first mindset, Bybit delivers a seamless ecosystem across trading, payments, wealth management, custody, institutional services, and Web3 — connecting users to the future of digital finance.</div> <div class="ace-line ace-line old-record-id-IF06dI0MPoBwYfxbZ4zui13HsoC"> </div> <div class="ace-line ace-line old-record-id-X5EbdOwvMoYuOmxQBbuueUEDsDd">Our core values define how we build. We listen, care and improve to create products and experiences that put users first. Backed by a global team of ambitious builders, problem-solvers, and innovators, we foster a high-performance and fast-moving environment where talent is empowered to drive real impact at the global scale. Supported by 24/7 multilingual customer service and a strong commitment to innovation, we are shaping the future of finance through technology, collaboration, and bold execution.</div> <div class="ace-line ace-line old-record-id-LtVud2dO7oglqJxxZoOucqjJsPc"> </div> <div class="ace-line ace-line old-record-id-RMHkdm4bPo66l3xMVO8ui1o8sle">Today, Bybit is recognized as one of the most trusted and transparent platforms in the digital asset industry, continuing to expand its global presence while building the infrastructure for the next generation of financial services.</div> </div></div><div data-zone-id="0" data-line-index="0" data-line="true"> <div data-zone-id="0" data-line-index="0" data-line="true"> <div data-zone-id="0" data-line-index="0" data-line="true"> <div data-zone-id="0" data-line-index="0" data-line="true"> <div data-page-id="PRvcdzjJMo4fiExkkbsuSuBDsOf" data-lark-html-role="root" data-docx-has-block-data="false"> <div class="ace-line ace-line old-record-id-Th2wd1ecxoaCZFxPgUvutl7os2b"><strong>Job Summary:</strong></div> <div class="ace-line ace-line old-record-id-Ofindl0U0oxEHhxyAmnuwmams9f"> </div> <div class="ace-line ace-line old-record-id-Zs3ZdUFIvoUKgFxLXnIud7xqshd">Primarily responsible for security auditing and security governance of the company's platform systems. Identify potential risks in business requirements and technical implementation plans, provide solutions, and drive their implementation.</div> <div class="ace-line ace-line old-record-id-XkAxdkDl9oqiSqxBUp5uWcDisg4"> </div> <div class="ace-line ace-line old-record-id-Nj9edSzTdo0wtXxzrIuu6jXksTe"><strong>Job Responsibilities:</strong></div> <ol class="list-number1"> <li class="ace-line ace-line old-record-id-LGJtd9dEcoAJSAxUbMTuHJSUsUb" data-list="number"> <div>Conduct manual code security audits on business code (Java, Golang, JS, C++, etc.) and write audit reports.</div> </li> <li class="ace-line ace-line old-record-id-R2IydHtt1o3ifuxVbGLu8BFDsOd" data-list="number"> <div>Track domestic and international security developments; analyze and reproduce the latest security vulnerabilities.</div> </li> <li class="ace-line ace-line old-record-id-V1hLd5DUToX1LAxs4crunxLGssc" data-list="number"> <div>Deeply understand and master the company's product business; identify security risks in business architecture, business processes, and business logic; provide corresponding security solutions and drive their implementation.</div> </li> <li class="ace-line ace-line old-record-id-SUOedFxGPoMfYxxgrLiuwwcJsxd" data-list="number"> <div>Drive security solution implementation, risk governance, etc.</div> </li> </ol> <div class="ace-line ace-line old-record-id-XkhudEQf1oJVrnxewHuuINHms9c"><strong>Job Requirements:</strong></div> <ol class="list-number1"> <li class="ace-line ace-line old-record-id-Setud4deqovgqLxWdlauOjaHsnc" data-list="number"> <div>Associate degree or above; requirements may be relaxed for candidates with strong capabilities.</div> </li> <li class="ace-line ace-line old-record-id-QiWmdih1JoqAhlxEcuYuOBqGsaf" data-list="number"> <div>At least 3+ years of business development or audit experience based on Java or Go; has led or participated in SDL (Security Development Lifecycle) implementation.</div> </li> <li class="ace-line ace-line old-record-id-XH0hdnb1vo6uO9xtOrhuH2mpsPh" data-list="number"> <div>Proficient in the underlying principles, discovery methods, vulnerable code scenarios, and exploitation techniques of common security vulnerabilities (not limited to OWASP Top 10).</div> </li> <li class="ace-line ace-line old-record-id-Jr8BdjKIeoHJ1IxYekIulWvysgd" data-list="number"> <div>Expert-level proficiency in Java and/or Go tech stacks; understands language-specific characteristics and common mainstream development frameworks, with relevant code audit experience.</div> </li> <li class="ace-line ace-line old-record-id-EVQJdYxF2oLJyhxKt2vu1Fx6sAg" data-list="number"> <div>Familiar with common white-box audit methodologies, with the ability to track and reproduce the latest vulnerabilities.</div> </li> <li class="ace-line ace-line old-record-id-Apz1dQ0kpo38OJxcMznuXXDMswd" data-list="number"> <div>Familiar with mainstream development frameworks such as SpringMVC, SSM, or Gin, GoZero, etc.</div> </li> <li class="ace-line ace-line old-record-id-VO9Td3bgXo5WukxJZGOuWO34sGf" data-list="number"> <div>Has a solid understanding of penetration testing; proficient in common penetration testing methods and familiar with the principles and exploitation techniques of common vulnerabilities.</div> </li> <li class="ace-line ace-line old-record-id-U3Hrdnz3GoW64kxdESguGm4Us0b" data-list="number"> <div>Able to proficiently use AI tools to enhance security work efficiency.</div> </li> <li class="ace-line ace-line old-record-id-WyjrdVZMfod1XpxW6GcubRSns6T" data-list="number"> <div>Highly proactive with strong logical thinking; possesses good communication, coordination, organizational skills, and documentation writing ability.</div> </li> <li class="ace-line ace-line old-record-id-MyDWdXkKLo6C8nxKiIBuFou4sjc" data-list="number"> <div>Experience with TEE (Trusted Execution Environment) and other security encryption, data protection technical architectures and solution implementation is preferred.</div> </li> </ol> <div class="ace-line ace-line old-record-id-HcIDduPmdopAMgx90OYu36RPskd"><strong>Nice to Have:</strong></div> <ol class="list-number1"> <li class="ace-line ace-line old-record-id-MZ3yd8iRPoFE87xbJBvuYRiXs9e" data-list="number"> <div>Has submitted high-quality vulnerabilities to domestic or international SRC/bug bounty platforms.</div> </li> <li class="ace-line ace-line old-record-id-SrI2dKmxwoXb85xXGIauX4Ulspb" data-list="number"> <div>Has discovered CVE or CNVD general vulnerabilities.</div> </li> <li class="ace-line ace-line old-record-id-MSNOdbjw4oFCJPx3TXMub6EcsKb" data-list="number"> <div>Has Java or Go code audit experience with demonstrated results.</div> </li> </ol> </div> </div> </div> </div> </div><div class="content-conclusion"><p><strong>Why Join Us</strong><br>At Bybit, we are committed to fostering a supportive and enriching work environment. <br>Our benefits include:<br>- Study Growth Fund: We support your professional development and continuous learning.<br>- Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.<br>- Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.<br>- Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.<br>- Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.</p></div>