Job Description
As a Security Engineer for our digital asset exchange platform, you will be responsible for comprehensive security construction across core scenarios including trading systems, account systems, wallet/fund flows, APIs, Web/App interfaces, and cloud infrastructure. Your role involves designing security architectures, conducting security reviews, performing code audits, vulnerability mining, penetration testing, and driving high-risk issue resolution.
You will build and operate security capabilities such as WAF, EDR, SIEM, IDS/IPS, Zero Trust frameworks, Secrets/KMS, and IAM solutions. A key focus will be developing exchange attack/defense systems to detect and mitigate risks including account takeovers, API abuse, fund theft, supply chain attacks, cloud environment intrusions, and APT threats.
The position requires active participation in security incident response, attack tracing, intrusion analysis, and handling major security events. You'll contribute to building automated security platforms and DevSecOps capabilities by integrating security testing into CI/CD pipelines and development workflows.
Continuous research into Web3, blockchain, and emerging exchange attack methodologies will be essential to enhance our overall security defense capabilities in this rapidly evolving space.
Key Responsibilities
- Lead security architecture design and implementation for digital asset exchange platforms
- Conduct thorough security assessments including code reviews and penetration testing
- Develop and maintain security systems (WAF, EDR, SIEM, IDS/IPS, Zero Trust)
- Establish comprehensive threat detection for financial security risks
- Manage security incident response and forensic investigations
- Implement DevSecOps practices and security automation tools
- Research emerging Web3/blockchain security threats and countermeasures
Job Requirements
- 3+ years in internet/fintech/exchange security, with preference for large-scale digital asset platform experience
- Expertise in Web/API security, endpoint protection, network/cloud security (AWS/GCP/Azure), Kubernetes/container security
- Deep understanding of exchange security domains: account protection, authentication, API keys, risk control, wallet systems, deposit/withdrawal flows
- Strong offensive security skills including penetration testing and red team operations
- Proficiency in Go/Python/Java/Rust for security tool development
- Hands-on experience with SIEM, EDR, WAF, IDS, and vulnerability management systems
- Knowledge of blockchain fundamentals and Web3 security risks preferred
Preferred Qualifications
- Security experience at top-tier exchanges (Binance, OKX, Bybit, Coinbase, Kraken) or leading fintech firms
- Background in large-scale red team exercises, APT detection, cloud-native security, or financial security systems
- Notable achievements in vulnerability research, CTF competitions, or bug bounty programs
- Business English proficiency for global security collaboration and high-intensity incident response
Compensation & Benefits
Monthly Salary: $3,500 - $7,000 (13 months per year) + holiday benefits + comprehensive security training budget + opportunities for international security conference participation