5 days ago
Kuala Lumpur, MalaysiaSenior
Responsibilities
- Conduct manual code security audits of business code and write audit reports.
- Track security developments and analyze and reproduce emerging vulnerabilities.
- Identify security risks in business architecture, processes, business logic, requirements, and technical implementation plans.
- Provide security solutions and drive their implementation and related risk governance.
- Support Security Development Lifecycle implementation and security auditing.
- Perform penetration testing and apply vulnerability discovery and exploitation techniques.
Requirements
- Associate degree or above; requirements may be relaxed for candidates with strong capabilities.
- At least 3 years of business development or audit experience based on Java or Go, including experience leading or participating in Security Development Lifecycle implementation.
- Expert-level proficiency in Java and/or Go, including language characteristics, mainstream frameworks, and relevant code-audit experience.
- Proficiency in common security vulnerabilities, including OWASP Top 10, their discovery methods, vulnerable code scenarios, and exploitation techniques.
- Familiarity with white-box audit methodologies and the ability to track and reproduce emerging vulnerabilities.
- Familiarity with frameworks such as SpringMVC, SSM, Gin, and GoZero.
- Solid understanding of penetration testing and common vulnerability exploitation techniques.
- Ability to use AI tools to improve security-work efficiency.
- Strong logical thinking, communication, coordination, organization, and documentation skills.
- Preferred experience with Trusted Execution Environment, encryption, data-protection architectures, and solution implementation.
- Preferred high-quality vulnerability submissions to domestic or international SRC or bug-bounty platforms.
- Preferred experience discovering CVE or CNVD vulnerabilities and demonstrated Java or Go code-audit results.
Benefits
- Study Growth Fund supporting professional development and continuous learning.
- Regular internal team-building activities, workshops, and events.
- Opportunity to work in a diverse, international, globally collaborative environment.
- Career advancement opportunities within a rapidly expanding global company.
- Internal mobility opportunities to support long-term career development.
