[Security] Senior Application Security Engineer
Job Summary:
Primarily responsible for security auditing and security governance of the company's platform systems. Identify potential risks in business requirements and technical implementation plans, provide solutions, and drive their implementation.
Job Responsibilities:
Conduct manual code security audits on business code (Java, Golang, JS, C++, etc.) and write audit reports.
Track domestic and international security developments; analyze and reproduce the latest security vulnerabilities.
Deeply understand and master the company's product business; identify security risks in business architecture, business processes, and business logic; provide corresponding security solutions and drive their implementation.
Drive security solution implementation, risk governance, etc.
Job Requirements:
Associate degree or above; requirements may be relaxed for candidates with strong capabilities.
At least 3+ years of business development or audit experience based on Java or Go; has led or participated in SDL (Security Development Lifecycle) implementation.
Proficient in the underlying principles, discovery methods, vulnerable code scenarios, and exploitation techniques of common security vulnerabilities (not limited to OWASP Top 10).
Expert-level proficiency in Java and/or Go tech stacks; understands language-specific characteristics and common mainstream development frameworks, with relevant code audit experience.
Familiar with common white-box audit methodologies, with the ability to track and reproduce the latest vulnerabilities.
Familiar with mainstream development frameworks such as SpringMVC, SSM, or Gin, GoZero, etc.
Has a solid understanding of penetration testing; proficient in common penetration testing methods and familiar with the principles and exploitation techniques of common vulnerabilities.
Able to proficiently use AI tools to enhance security work efficiency.
Highly proactive with strong logical thinking; possesses good communication, coordination, organizational skills, and documentation writing ability.
Experience with TEE (Trusted Execution Environment) and other security encryption, data protection technical architectures and solution implementation is preferred.
Nice to Have:
Has submitted high-quality vulnerabilities to domestic or international SRC/bug bounty platforms.
Has discovered CVE or CNVD general vulnerabilities.
Has Java or Go code audit experience with demonstrated results.