[Security] Senior Application Security Engineer
About Us
-
Conduct manual code security audits on business code (Java, Golang, JS, C++, etc.) and write audit reports.
-
Track domestic and international security developments; analyze and reproduce the latest security vulnerabilities.
-
Deeply understand and master the company's product business; identify security risks in business architecture, business processes, and business logic; provide corresponding security solutions and drive their implementation.
-
Drive security solution implementation, risk governance, etc.
-
Associate degree or above; requirements may be relaxed for candidates with strong capabilities.
-
At least 3+ years of business development or audit experience based on Java or Go; has led or participated in SDL (Security Development Lifecycle) implementation.
-
Proficient in the underlying principles, discovery methods, vulnerable code scenarios, and exploitation techniques of common security vulnerabilities (not limited to OWASP Top 10).
-
Expert-level proficiency in Java and/or Go tech stacks; understands language-specific characteristics and common mainstream development frameworks, with relevant code audit experience.
-
Familiar with common white-box audit methodologies, with the ability to track and reproduce the latest vulnerabilities.
-
Familiar with mainstream development frameworks such as SpringMVC, SSM, or Gin, GoZero, etc.
-
Has a solid understanding of penetration testing; proficient in common penetration testing methods and familiar with the principles and exploitation techniques of common vulnerabilities.
-
Able to proficiently use AI tools to enhance security work efficiency.
-
Highly proactive with strong logical thinking; possesses good communication, coordination, organizational skills, and documentation writing ability.
-
Experience with TEE (Trusted Execution Environment) and other security encryption, data protection technical architectures and solution implementation is preferred.
-
Has submitted high-quality vulnerabilities to domestic or international SRC/bug bounty platforms.
-
Has discovered CVE or CNVD general vulnerabilities.
-
Has Java or Go code audit experience with demonstrated results.
Why Join Us
At Bybit, we are committed to fostering a supportive and enriching work environment.
Our benefits include:
- Study Growth Fund: We support your professional development and continuous learning.
- Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
- Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
- Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
- Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.
Apply for this job
*
indicates a required field

