OSL
Singapore / Global
Singapore / Global
岗位职责:
代码审计与渗透测试
:负责公司 Web、API 及 Web3 业务(如 Smart Contract、DApp、钱包)的代码安全审计、漏洞挖掘与渗透测试。
SDL / DevSecOps 建设
:推进安全开发生命周期(SDL),将静态/动态安全扫描工具(SAST/DAST)集成至 CI/CD 流程。
安全事件应急响应
:负责应用层安全事件的快速响应、溯源分析与漏洞修复跟进。
安全设计与架构评审
:参与新业务/产品的安全架构设计与逻辑漏洞评审,提供针对性的安全加固方案。
任职要求:
基础安全能力
:2 年以上应用安全或渗透测试经验,精通 OWASP Top 10,能独立完成 Web/API 的漏洞挖掘与利用。
Web3 / 区块链经验
:熟悉 Web3 常见安全风险(如智能合约重入攻击、闪电贷攻击、签名伪造、DApp 跨站攻击等),有 Solidity 代码审计或 DApp/钱包渗透经验者优先。
安全工具与自动化
:熟悉常见安全工具(如 Burp Suite、Slither、Mythril、Checkmarx),具备编写 Python/Go 自动化安全脚本的能力。
沟通与协作
:具备良好的跨部门沟通能力,能推动开发团队高效完成漏洞修复。
Key Responsibilities:
Code Audit & Penetration Testing
: Conduct security code reviews and penetration testing for Web applications, APIs, and Web3 infrastructure (Smart Contracts, DApps, Wallets).
SDL & DevSecOps
: Drive the Security Development Lifecycle (SDL) by integrating SAST/DAST automation tools into CI/CD pipelines.
Incident Response
: Handle application-level security incidents, conduct root-cause analysis, and track vulnerability remediation.
Security Architecture Review
: Participate in product design reviews to identify architectural/logical flaws and provide security hardening solutions.
Requirements:
Core AppSec Skills
: 2+ years of experience in AppSec or PenTesting; solid knowledge of OWASP Top 10 and web/API vulnerability exploitation.
Web3 / Blockchain Experience
: Familiar with Web3 threat vectors (e.g., Reentrancy, Flash Loans, Signature Forgery, DApp attacks). Hands-on experience in Solidity auditing or DApp/Wallet testing is a strong plus.
Tooling & Automation
: Proficient with security tools (e.g., Burp Suite, Slither, Mythril, Checkmarx) and capable of scripting in Python or Go for automation.
Communication
: Excellent cross-functional communication skills to effectively drive remediation with development teams.
Singapore / Global
Singapore / Global
Singapore / Global
Singapore / Global
Singapore / Global
Singapore / Global