Job Description
Summary
Your Role
- Responsible for demand risk identification and security review, code audit, pre-launch testing, and post-launch risk monitoring during the R&D process;
- Responsible for following up security vulnerability handling and vulnerability warning operations, and assisting business repairs until the vulnerability is closed;
- Provide security training for developers and provide effective solutions to security issues in the code;
- Conduct emergency response to security incidents and solve security problems in a timely manner;
- Continue to track and operate intelligence collection, analysis, and mining in related fields to conduct risk warnings;
- Regularly coordinate with business departments to synchronize the latest security status, requirements and specifications, and work with business departments to implement them.
Your Craft
- Bachelor degree or above, more than 5 years of penetration and code auditing experience;
- Master at least one development language (Nodejs, Golang, etc.);
- Master security emergency response technologies and processes;
- Familiar with penetration testing and APT attack and defense techniques, and familiar with intranet penetration (not limited to various types of horizontal escaping of privileges, anti-killing techniques, tunnel penetration techniques, etc.);
- Familiar with common Internet business scenario security design and data security best practices;
- Familiar with common encryption signature algorithms, TLS, OAuth, JWT and related technologies;
- Familiar with common public chains (BTC/ETH, etc.) and the basic working principles of digital currency wallets;
- Active thinking and strong learning ability.
Extra Credit
- Have experience in threat modeling, SDL/devsecops practice;
- Have experience in APT tracing;
- Experience in developing security tools and platforms;
- Have experience in emergency plan customization and response, and experience in continuous tracking and operation of intelligence in related fields.
Skills
- Development
- Software Engineering