Application Security Engineering Manager

You will lead the company's application security team, formulate and implement application security strategy and technical roadmap, build a full-lifecycle application security system, manage security risks and vulnerabilities, ensure regulatory compliance, and collaborate with R&D, product, testing, operations, and compliance teams.

Responsibilities

  • Formulate application security strategy, technical roadmaps, and implementation plans.
  • Lead SDLC security, vulnerability management, security code review, penetration testing, and security monitoring.
  • Establish application security standards, processes, and operating procedures.
  • Track emerging security technologies, vulnerabilities, and attack methods.
  • Build, manage, and develop the application security engineering team.
  • Set team OKRs, performance standards, assignments, training, and reviews.
  • Lead application security risk assessments and mitigation planning.
  • Integrate security throughout the software development lifecycle.
  • Establish and manage the vulnerability management system.
  • Respond to application security incidents and lead root-cause investigations.
  • Ensure compliance with global regulations and industry standards.
  • Support audits, risk assessments, regulatory reporting, and compliance programs.
  • Collaborate with R&D, product, testing, operations, compliance, network security, and data security teams.
  • Provide security guidance, remediation support, and awareness training.

Requirements

  • 8+ years of application security or related experience, including 3+ years managing senior application security teams.
  • Preferred fintech, digital currency, payment, or blockchain industry experience.
  • Deep understanding of application security risks in digital currency trading and payment systems.
  • Proficiency in security code review, penetration testing, vulnerability research, SDLC security management, and application security monitoring.
  • Experience with OWASP Top 10, vulnerability discovery, and remediation.
  • Proficiency in at least one programming language such as Java, Python, or Go.
  • Familiarity with SAST, DAST, IAST, and vulnerability scanners.
  • Understanding of FATF, MiCA, ISO 27001, and PCI DSS requirements.
  • Excellent leadership, team management, coordination, and analytical skills.
  • Experience handling major application security incidents.
  • Fluent oral and written Chinese and English communication skills.
  • Bachelor's degree or above in computer science, information security, network security, or a related field.
  • CISSP, CISM, or CEH certifications preferred.
  • Preferred experience building security systems for compliant exchanges or payment institutions.
  • Preferred cloud security experience with AWS, GCP, or Azure.

Benefits

  • Meaningful cross-functional collaboration.
  • Opportunities for career advancement in a fast-growing organization.
  • Culture that welcomes data-backed ideas and innovation.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available