Start Your Search Here

Job Search

OSL

Singapore / Global

Senior Application Security Engineer

Job Description

岗位职责:

代码审计与渗透测试

:负责公司 Web、API 及 Web3 业务(如 Smart Contract、DApp、钱包)的代码安全审计、漏洞挖掘与渗透测试。

SDL / DevSecOps 建设

:推进安全开发生命周期(SDL),将静态/动态安全扫描工具(SAST/DAST)集成至 CI/CD 流程。

安全事件应急响应

:负责应用层安全事件的快速响应、溯源分析与漏洞修复跟进。

安全设计与架构评审

:参与新业务/产品的安全架构设计与逻辑漏洞评审,提供针对性的安全加固方案。

任职要求:

基础安全能力

:2 年以上应用安全或渗透测试经验,精通 OWASP Top 10,能独立完成 Web/API 的漏洞挖掘与利用。

Web3 / 区块链经验

:熟悉 Web3 常见安全风险(如智能合约重入攻击、闪电贷攻击、签名伪造、DApp 跨站攻击等),有 Solidity 代码审计或 DApp/钱包渗透经验者优先。

安全工具与自动化

:熟悉常见安全工具(如 Burp Suite、Slither、Mythril、Checkmarx),具备编写 Python/Go 自动化安全脚本的能力。

沟通与协作

:具备良好的跨部门沟通能力,能推动开发团队高效完成漏洞修复。

Key Responsibilities:

Code Audit & Penetration Testing

: Conduct security code reviews and penetration testing for Web applications, APIs, and Web3 infrastructure (Smart Contracts, DApps, Wallets).

SDL & DevSecOps

: Drive the Security Development Lifecycle (SDL) by integrating SAST/DAST automation tools into CI/CD pipelines.

Incident Response

: Handle application-level security incidents, conduct root-cause analysis, and track vulnerability remediation.

Security Architecture Review

: Participate in product design reviews to identify architectural/logical flaws and provide security hardening solutions.

Requirements:

Core AppSec Skills

: 2+ years of experience in AppSec or PenTesting; solid knowledge of OWASP Top 10 and web/API vulnerability exploitation.

Web3 / Blockchain Experience

: Familiar with Web3 threat vectors (e.g., Reentrancy, Flash Loans, Signature Forgery, DApp attacks). Hands-on experience in Solidity auditing or DApp/Wallet testing is a strong plus.

Tooling & Automation

: Proficient with security tools (e.g., Burp Suite, Slither, Mythril, Checkmarx) and capable of scripting in Python or Go for automation.

Communication

: Excellent cross-functional communication skills to effectively drive remediation with development teams.

Apply Now

Similar Opportunities

View all jobs