Job Description
Summary
Responsibilities
- Discover security vulnerabilities through design review, manual source code review, and follow up on the remediation process
- Use automated tools to find security vulnerabilities in source code and/or system
- Participant in relevant agile scrum meetings and provide professional recommendations on the design of security controls, libraries, and/or protocols
- Conduct secure coding training sessions
- Implement various security control verification and risk detection by developing our own automation system
- Implement security related libraries for internal use
- Provide support on application level security monitoring, intrusion detection, and incident response
Requirements
- At least 5 years of software development experience with a focus on either Server Side Java or Rails language.
- Experience in mobile application development will be an added advantage
- We would love to hire a code reviewer with a solid background in security code review, but we are also open to candidates who have solid background in software development but no security code review experience.
- Candidates with more experience will be considered for a more senior role and title
- Good understanding of the whole software development lifecycle, CI/CD tools, cloud, Kubernetes, and various and technology stacks
- CISSP, CSSLP, OSWE is definitely an advantage
- Familiar with OWASP Top 10 is an advantage
- Proficiency in both spoken and written English. Being able to speak Mandarin will be an advantage
Skills
- App Development
- Communications Skills
- Development
- Java