Job Description
Summary
Your Role
- Responsible for demand risk identification and security review, code audit, pre-launch testing, and post-launch risk monitoring during the R&D process;
- Responsible for following up on security vulnerability handling and vulnerability warning operations, and assisting in business repairs until the vulnerability is closed;
- Provide security training for developers and provide effective solutions to security issues in the code;
- Conduct emergency response to security incidents and resolve security issues in a timely manner;
- Continuously track and operate intelligence collection, analysis, and mining in related fields to provide risk warnings;
- Regularly coordinate with business departments to synchronize the latest security status, requirements and specifications, and work with business departments to implement them.
Your Craft
- Bachelor degree or above, more than 5 years of experience in penetration and code auditing;
- Master at least one development language (Nodejs, Golang, etc.);
- Master security emergency response technologies and processes;
- Familiar with penetration testing and APT attack and defense techniques, and familiar with intranet penetration (not limited to various types of lateral privilege escaping, anti-killing techniques, tunnel penetration techniques, etc.);
- Familiar with common Internet business scenario security design and data security best practices;
- Familiar with common encryption signature algorithms, TLS, OAuth, JWT and related technologies;
- Familiar with common public chains (BTC/ETH, etc.) and the basic working principles of digital currency wallets;
- Active thinking and strong learning ability.
Extra Credit
- Experience in threat modeling, SDL/devsecops;
- Have experience in APT tracing;
- Experience in developing security tools and platforms;
- Have experience in emergency plan customization and response, and experience in continuous tracking and operation of intelligence in related fields.
Skills
- Development
- Software Engineering