Application Security Engineer (Pentester)
Status
Hong Kong
Full time
Hybrid
Compensation is not specified
Role
Security Engineer
Description
Responsibilities
- Discover security vulnerabilities by conducting design reviews, source code reviews, and penetration testing, either manually or using automated tools, and oversee the remediation process.
- Participate in agile scrum meetings, offering expert suggestions on security control design, libraries, and protocols.
- Deliver security training sessions.
- Develop and implement security control verification and risk detection using automated scripts.
- Offer assistance in application-level security monitoring, intrusion detection, and incident response.
Requirements
- Possession of OSCP (or equivalent like CREST) is mandatory.
- In-depth knowledge of OWASP Top 10 and ability to identify and rectify logic flaws are highly preferred.
- Minimum of four years of experience in Web API testing and proficient use of BurpSuite is desired.
- Experience in Mobile App testing, understanding of device jailbreaking/rooting, API hooking, reverse engineering, and de-obfuscation is highly beneficial.
- Strong fluency in spoken and written English is required, while proficiency in Mandarin would be advantageous.
Skills Required

Сrypto.com
Website
Сrypto.comCompany size
Not specified
Location
United States
Description
Not specified
Status