11 months ago
Shenzhen, China or Hong Kong, Hong KongSenior
Responsibilities
- Conduct comprehensive penetration testing on company applications and systems.
- Organize attack-defense drills and red-team exercises.
- Test and bypass blue-team defense technologies to improve security protections.
- Research offensive and defensive technologies, industry developments, and security tools.
- Build security capabilities including detection rules, monitoring strategies, and intrusion traceability.
- Develop countermeasures and TTPs based on threat intelligence and APT behavior models.
- Write scripts and tools for automated exploitation and basic security tool development.
Requirements
- More than five years of practical attack-and-defense experience and the ability to independently complete penetration testing.
- Experience with internal network penetration and domain penetration, including successful cases.
- Practical experience conducting penetration testing in AWS cloud environments and performing container and Kubernetes security attack and defense.
- Familiarity with Linux and Windows system principles, databases, command execution, and privilege escalation techniques.
- Familiarity with mainstream web frameworks and the ability to conduct code auditing and vulnerability mining in Java, Go, or Python.
- Practical experience with red-team and blue-team exercises.
- Ability to write scripts or tools for automated exploitation and basic tool development.
Benefits
- Cross-functional collaboration with relevant teams on implementations that improve customer experience.
- Opportunities for career advancement in a fast-growing organization expanding beyond APAC.
- A culture that supports data-backed ideas and meaningful organizational impact.
- Opportunity to work at a regulated crypto company serving more than 18 million users.
