Application Security Engineer- Global E-Commerce
5 days ago Be among the first 25 applicants
About the Team
As part of ByteDance's Security Department, Security BP team is not only responsible for the security and risk management of the Monetization business, but also plays an important role in connecting and building trust between the business and security team.
Leveraging on various capabilities provided by the Security Department, we ensure the business and customer data are secured by providing high-quality services to the Monetization business, such as platform security, product security, business security and compliance governance.
Responsibilities
Provide security engineering support to product teams to help identify potential security flaws in the early stages of SDLC.
Continuously design and conduct penetration testing to determine if infrastructure components, systems and applications meet security standards in the staging/production environment.
Discover security issues that appear under new threat scenarios, support incident response, forensics, remediation in a cross-functional environment driving towards incident resolution.
Collaborate closely with other parts of the security team and product teams to design defense-in-depth controls that limit attackers' ability and improve our security postures.
To identify risks and actively take ownership to resolve any potential security project issues.
Continuously conduct security research and strive to innovate.
Qualifications
Minimum Qualifications
Background in Computer Science, Computer Engineering, Information Systems or other STEM disciplines.
Strong knowledge in some of these various disciplines: web application security, mobile app security, cloud security and thick client security.
Solid experience in writing and reviewing code in at least one of the following programming languages: JavaScript (Node JS), Go, Python, Java, C++, Rust.
Good project management skills and focused teamwork.
Preferred Qualifications
Experience in independent supporting the application security of a business line.
CTF players, BugBounty experience with reputable statistics in HackerOne, BugCrowd etc.
#J-18808-Ljbffr