Senior Application Security Engineer
United States
Crypto.com
Over 100 million users buy, sell, and trade Bitcoin, Ethereum, NFTs and more on Crypto.com. Join the World's leading crypto trading platform.The team includes holders of international patents for technologies integrated in our security architecture. Under the stewardship of a distinguished CISO recognized by the Forbes Technology Council and among the Global Top 100 CISOs, our team has consistently championed industry standards, acquiring certifications like ISO27001, ISO27701, ISO22301, PCI:DSS 3.2.1 (Level 1), NIST Tier 4, and SOC 2 Type II, in addition to the MPI License from Singapore MAS. Our Chief Information Security Officer reports directly to the CEO, underscoring the prioritization of security in our organization's hierarchy.
Our Security Team not only places great emphasis on credentials and expertise but also deeply values hands-on experience, rapid cognition, and dynamic learning. The challenges in the world of crypto are ever-evolving, and as such, our team prides itself on quick adaptability and robust teamwork, ensuring that we stay ahead of potential threats and always safeguard our user base.
Job Responsibilities:
- Discover security vulnerabilities through design review, source code review and penetration testing, either manually or by using automated tools, and follow up on the remediation process;
- Participant in relevant agile scrum meetings and provide professional recommendations on the design of security controls, libraries, and/or protocols;
- Conduct security-related training sessions;
- Implement various security control verification and risk detection through automated scripts;
- Provide support on application-level security monitoring, intrusion detection, and incident response.
Job Requirements:
- OSCP (or equivalent, such as CREST) is a MUST;
- A deep understanding of OWASP Top 10 and the ability to detect and address logic flaws are highly desirable;
- Minimum five years of experience in Web API testing and proficiency in using BurpSuite is preferred;
- Experience with Mobile App testing, comprehension of jailbreaking/rooting a device, API hooking, reverse engineering, and de-obfuscation is highly beneficial;
- Previous working experiences in a crypto trading platform would be highly advantageous.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile APIs Application security Burp Suite CISO Compliance CREST Crypto Incident response Intrusion detection ISO 22301 ISO 27001 Monitoring NIST OSCP OWASP Pentesting Privacy Reverse engineering Scrum SOC SOC 2 Vulnerabilities
Perks/benefits: Career development Competitive pay Health care Medical leave
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.