Application Security Engineering Manager
You will lead the company's application security team, formulate and implement application security strategy and technical roadmap, build a full-lifecycle application security system, manage security risks and vulnerabilities, ensure regulatory compliance, and collaborate with R&D, product, testing, operations, and compliance teams.
Responsibilities
- Formulate application security strategy, technical roadmaps, and implementation plans.
- Lead SDLC security, vulnerability management, security code review, penetration testing, and security monitoring.
- Establish application security standards, processes, and operating procedures.
- Track emerging security technologies, vulnerabilities, and attack methods.
- Build, manage, and develop the application security engineering team.
- Set team OKRs, performance standards, assignments, training, and reviews.
- Lead application security risk assessments and mitigation planning.
- Integrate security throughout the software development lifecycle.
- Establish and manage the vulnerability management system.
- Respond to application security incidents and lead root-cause investigations.
- Ensure compliance with global regulations and industry standards.
- Support audits, risk assessments, regulatory reporting, and compliance programs.
- Collaborate with R&D, product, testing, operations, compliance, network security, and data security teams.
- Provide security guidance, remediation support, and awareness training.
Requirements
- 8+ years of application security or related experience, including 3+ years managing senior application security teams.
- Preferred fintech, digital currency, payment, or blockchain industry experience.
- Deep understanding of application security risks in digital currency trading and payment systems.
- Proficiency in security code review, penetration testing, vulnerability research, SDLC security management, and application security monitoring.
- Experience with OWASP Top 10, vulnerability discovery, and remediation.
- Proficiency in at least one programming language such as Java, Python, or Go.
- Familiarity with SAST, DAST, IAST, and vulnerability scanners.
- Understanding of FATF, MiCA, ISO 27001, and PCI DSS requirements.
- Excellent leadership, team management, coordination, and analytical skills.
- Experience handling major application security incidents.
- Fluent oral and written Chinese and English communication skills.
- Bachelor's degree or above in computer science, information security, network security, or a related field.
- CISSP, CISM, or CEH certifications preferred.
- Preferred experience building security systems for compliant exchanges or payment institutions.
- Preferred cloud security experience with AWS, GCP, or Azure.
Benefits
- Meaningful cross-functional collaboration.
- Opportunities for career advancement in a fast-growing organization.
- Culture that welcomes data-backed ideas and innovation.