Talent.com
Web Application Security Engineer

Web Application Security Engineer

CXM Direct LLCHong Kong, Hong Kong, HK
13 小时前
职位类型
  • Quick Apply
职位描述

Position Overview

We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.

This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.

Core Responsibilities

Offensive Security (Penetration Testing)

The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.

You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL / TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.

Defensive Security (Blue Team Operations)

On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.

You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.

Purple Team Collaboration

As a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.

You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.

Security Integration and Automation

You will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.

Requirements

Required Qualifications

  • Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
  • ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
  • Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
  • Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
  • Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
  • Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
  • Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF / IPS
  • Hands-on experience configuring and tuning web application firewalls and deep packet inspections

Preferred Qualifications

Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.

Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.

Benefits

Competitive Compensation

Medical

Gym Allowance

Company Events

Personal Growth

为此搜索创建职位提醒

Engineer • Hong Kong, Hong Kong, HK

相关职位
Product Manager, Web 3 (App Features)

Product Manager, Web 3 (App Features)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Design and plan features for digital assets and their derivatives, including market data and trading decision support tools, to help global investors make informed investment decisions.Liaise with ...展示更多最后更新时间: 6天前
Web Developer (Web 3)

Web Developer (Web 3)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Responsible for the development and maintenance of front-end sites for Web 3 business, mainly including user-side sites and management backend sites required for the business expansion of exchange ...展示更多最后更新时间: 28天前
Senior Backend Developer, Trading System (Web 3)

Senior Backend Developer, Trading System (Web 3)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Responsible for the design and implementation of the Digital Asset Management trading system.Maintenance, upgrade, transformation, and performance optimization of the existing system;.Responsible f...展示更多最后更新时间: 28天前
Engineering Architect, Risk (Web 3)

Engineering Architect, Risk (Web 3)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Design and optimize the architecture of real-time risk control engines, lead the technology selection and development of core modules, ensuring the system supports millisecond-level response and hi...展示更多最后更新时间: 28天前
SRE Engineer (Web 3)

SRE Engineer (Web 3)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Ensure the stability of the company's exchange business, respond quickly to incidents with the R&D team, and establish mechanisms to improve handling efficiency. Participate in the construction ...展示更多最后更新时间: 28天前
Senior Backend Developer, Risk (Web 3)

Senior Backend Developer, Risk (Web 3)

moomooHong Kong, Hong Kong, HK
Quick Apply
Responsible for the design and implementation of the risk control system for the Digital Asset Management platform;.Maintenance, upgrade, transformation, and performance optimization of the existin...展示更多最后更新时间: 28天前
Blockchain Engineer - Custodial Wallet

Blockchain Engineer - Custodial Wallet

moomooHong Kong, Hong Kong, HK
Quick Apply
Develop and maintain core custodial wallet modules including account management, deposit, withdrawal, sweeping, signing, and transaction broadcasting. Integrate multiple blockchain protocols (BTC, E...展示更多最后更新时间: 28天前
Testing Engineer (Wallet & Digital Assets)

Testing Engineer (Wallet & Digital Assets)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Responsible for quality assurance of financial business systems, primarily covering Web3 wallets, coin deposits / withdrawals, custody, and other on-chain / off-chain digital asset businesses.This incl...展示更多最后更新时间: 28天前
Senior Testing Engineer (Trading System)

Senior Testing Engineer (Trading System)

moomooShenzhen, Guangdong Province, CN
Quick Apply
Responsible for testing financial business systems, primarily covering trading, matching, risk control, assets, accounts, and other related areas. This includes testing for Web, Client, Server, and ...展示更多最后更新时间: 28天前
Senior Web Developer (Web 3)

Senior Web Developer (Web 3)

moomooHong Kong, Hong Kong, HK
Quick Apply
Responsible for the development and maintenance of front-end sites for Web3 business, mainly including user-side sites and management backend sites required for the business expansion of exchange a...展示更多最后更新时间: 28天前
Equity Derivative Application Support Engineer | VP | Perm role

Equity Derivative Application Support Engineer | VP | Perm role

Unity PartnersHong Kong, Hong Kong
Our client is a globally recognized financial services institution with an extensive presence across key international markets. They are committed to innovation, operational excellence, and empoweri...展示更多上次更新时间:30 天前
Engineering Architect, Trading System (Web 3)

Engineering Architect, Trading System (Web 3)

moomooHong Kong, Hong Kong, HK
Quick Apply
Design and optimize core systems such as matching engines and order management; lead key code development to ensure the system supports high-concurrency trading requests and millisecond-level low-l...展示更多最后更新时间: 28天前
Backend Developer, Server (Web 3)

Backend Developer, Server (Web 3)

moomooHong Kong, Hong Kong, HK
Quick Apply
Responsible for the solution design and requirement implementation of systems such as trading, risk control, asset management, clearing and settlement in the Digital Asset Management platform;.Main...展示更多最后更新时间: 28天前
Mobile Application Developer

Mobile Application Developer

South China Morning PostHK
Quick Apply
About the Team The Product & Technology department is composed of Product Managers, Engineers, Designers and User Researchers. Ownership, meritocracy and collaboration are at our core.We are not...展示更多上次更新时间:30 天前
Engineering Lead, Clearing & Settlement (Web 3)

Engineering Lead, Clearing & Settlement (Web 3)

moomooHong Kong, Hong Kong, HK
Quick Apply
As the technical decision-maker for the exchange's fund clearing and settlement system, you will be responsible for building an efficient, secure, and scalable clearing and settlement system to ens...展示更多最后更新时间: 28天前
Senior APP Developer (CFD Trading APP)

Senior APP Developer (CFD Trading APP)

Zeal GroupHong Kong, Hong Kong, HK
Quick Apply
An award-winning Fintech organization with a dedicated team of 600+ professionals across the globe.With more than 15 offices across the world, we are a people centric company which prides itself on...展示更多最后更新时间: 4天前
Application Systems Engineer

Application Systems Engineer

IO TECH SOLUTIONS LIMITEDHong Kong Island, Hong Kong
Analyse business requirements and enhance existing application systems to meet business needs.Provide technical and application support, and perform application administration and performance tunin...展示更多最后更新时间: 20天前
Testing Engineer (Trading System)

Testing Engineer (Trading System)

moomooHong Kong, Hong Kong, HK
Quick Apply
Responsible for testing financial business systems, primarily covering trading, matching, risk control, assets, accounts, and other related areas. This includes testing for Web, Client, Server, and ...展示更多最后更新时间: 28天前