Officer, Application Security, LME
Hong Kong Exchanges and Clearing Limited4 months ago
Shenzhen, ChinaEntry Level / Mid Level
Responsibilities
- Support secure SDLC initiatives through static code analysis, dependency analysis, and secure design reviews.
- Maintain and enhance SonarQube and integrate security checks into CI/CD pipelines.
- Produce and manage SBOMs for in-house and third-party applications.
- Perform application and API security testing, including testing during deployment.
- Support vulnerability remediation in collaboration with development teams.
- Participate in threat modeling and security architecture discussions.
- Assist with penetration testing and red teaming under senior guidance.
- Support application security on Kubernetes platforms, including OpenShift.
- Work with global stakeholders, including the London Metal Exchange, in English-speaking environments.
Requirements
- 1–3 years of experience in application security, secure software development, or cybersecurity.
- Understanding of web application security and API security, including OWASP Top 10 and OWASP API Top 10.
- Familiarity with DevSecOps practices and tools such as SonarQube and CI/CD pipelines.
- Basic understanding of software supply chain security and SBOM concepts.
- Exposure to Kubernetes or OpenShift environments is advantageous.
- Strong interest in penetration testing, vulnerability research, and attacker techniques.
- Experience in a foreign financial institution environment is a plus.
- Good spoken and written English is required.
- Strong self-learning capability, hands-on attitude, and passion for technology.
Benefits
- Permanent employment in Shenzhen, China.
- Standard 40-hour work week.
- Work with global stakeholders in an English-speaking environment.