Security Engineer (Penetration Tester) - Security Assurance

5 Months ago • All levels • Cyber Security

Job Summary

Job Description

ByteDance's Security Assurance team seeks a talented Security Engineer (Penetration Tester) to strengthen their security posture. Responsibilities include designing and conducting penetration testing, identifying vulnerabilities, certifying systems, and collaborating with product teams to improve security practices. The ideal candidate will have a strong background in web application security, mobile app security, cloud security, and relevant programming languages. This role involves identifying and resolving security issues, conducting security reviews, and providing security engineering support.
Must have:
  • Background in Computer Science/Engineering or Information Systems
  • Strong knowledge in web application security, mobile app security, cloud security, and thick client security
  • Solid experience in coding with JavaScript (Node JS), Go, Python, Java, C++, or Rust
  • Good project management skills and teamwork
Good to have:
  • CTF player experience
  • CVEs (excluding vulnerabilities like XSS, CSRF in random CMS)
  • BugBounty experience with reputable statistics in HackerOne, BugCrowd etc.

Job Details

Responsibilities
About ByteDance Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content. Why Join Us Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible. Together, we inspire creativity and enrich life - a mission we aim towards achieving every day. To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always. At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve. Join us. About the Security Assurance Team at ByteDance The team is missioned to build infrastructures, platforms and technologies, as well as to support cross-functional teams to protect our users, products and infrastructures. In this team, you'll have a unique opportunity to have first-hand exposure to the strategy of the company in key security initiatives, especially in building scalable and secure-by-design systems and solutions. Our challenges are not your regular day-to-day technical problems; you'll be part of a team that's developing new solutions to new challenges of a kind not previously addressed by big tech. It's working fast, at scale, and we're making a difference. Responsibilities - Continuously design and conduct penetration testing to determine if infrastructure components, systems and applications meet confidentiality, integrity, authentication, availability, authorisation, and nonrepudiation standards in the staging/production environment. - Translate requirements into test plan, write and execute test scripts or codes in line with standards and procedures to determine vulnerability to attacks. - Certify infrastructure components, systems and applications that meet security standards. - To identify risks and actively take ownership to resolve any potential project issues. - Conduct technical security reviews for any new products and feature requirements. - Provide security engineering support to product teams to help identify potential security flaws in the early stages of SDLC. - Collaborate closely with other parts of the security team and product teams to design defense-in-depth controls that limit attackers' ability and improve our security postures. - Continuously conduct security research and strive to innovate.
Qualifications
- Background in Computer Science, Computer Engineering, Information Systems or other STEM disciplines. - Strong knowledge in some of these various disciplines: web application security, mobile app security, cloud security and thick client security. - Solid experience in writing and reviewing code in at least one of the following programming languages: JavaScript (Node JS), Go, Python, Java, C++, Rust. - Good project management skills and focused teamwork. Preferred Requirements - CTF players, live competitions and hacking events experience. - CVEs (excluding vulnerabilities such as XSS, CSRF in random CMS) are preferred. - BugBounty experience with reputable statistics in HackerOne, BugCrowd etc. ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Similar Jobs

Netflix - Full Stack Software Engineer (L5), Content Middleware Infrastructure

Netflix

New York, New York, United States (Remote)
1 Week ago
ARHS - Développeur Sénior Fullstack Java/Angular

ARHS

Luxembourg, Luxembourg, Luxembourg (On-Site)
6 Months ago
Google - Customer Engineer (English, Japanese)

Google

Tokyo, Japan (On-Site)
1 Week ago
ION - Senior AI Engineer, Italy

ION

Pisa, Tuscany, Italy (On-Site)
6 Months ago
Nagarro - Staff Engineer, Java Fullstack

Nagarro

Mexico (Remote)
6 Months ago
Google - Software Engineer III, AI Agent Security, Core

Google

Zürich, Zurich, Switzerland (On-Site)
1 Week ago
PwC - Consultoría I Consultor Senior Ciberseguridad OT

PwC

Madrid, Community Of Madrid, Spain (On-Site)
7 Months ago
PwC - Risk Services - Change Management Specialist

PwC

Singapore (On-Site)
7 Months ago
Google - Red Teaming and Threat Emulation Consultant

Google

New South Wales, Australia (On-Site)
1 Week ago
Microsoft - Technical Support Engineer - Intune

Microsoft

(Remote)
1 Week ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Google - Technical Solutions Consultant

Google

Dublin, County Dublin, Ireland (On-Site)
1 Week ago
Next Level Business Services - PHP DEVELOPER

Next Level Business Services

Boston, Massachusetts, United States (On-Site)
6 Months ago
ION - Lead Java Developer, New York

ION

New York, New York, United States (Hybrid)
6 Months ago
Microsoft - Senior Software Engineer

Microsoft

Redmond, Washington, United States (On-Site)
1 Week ago
Netflix - Machine Learning Intern, Fall 2025

Netflix

Los Gatos, California, United States (On-Site)
1 Week ago
ByteDance - Software Engineer Intern (CDN/Edge/Traffic Platform)

ByteDance

San Jose, California, United States (On-Site)
2 Weeks ago
Genies - 2025 Summer Backend Engineer Intern

Genies

San Mateo, California, United States (On-Site)
1 Month ago
Nagarro - Associate Staff Engineer, Java

Nagarro

India (Remote)
6 Months ago
Meta - Software Engineer, Android

Meta

Burlingame, California, United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Singapore

ByteDance - Ethics and Compliance Specialist (Training and Communications)

ByteDance

Singapore (On-Site)
2 Weeks ago
ByteDance - Marketing Operations and Campaign Specialist

ByteDance

Singapore (On-Site)
1 Month ago
ByteDance - Site Reliability Engineer, Traffic Infrastructure

ByteDance

Singapore (On-Site)
5 Months ago
ByteDance - Senior Security Software Architect, Security Engineering

ByteDance

Singapore (On-Site)
5 Months ago
ByteDance - Backend Engineer - BytePlus

ByteDance

Singapore (On-Site)
5 Months ago
ByteDance - Service Framework Software Engineer Intern

ByteDance

Singapore (On-Site)
2 Weeks ago
ByteDance - Data Analyst - Global Payment

ByteDance

Singapore (On-Site)
1 Month ago
Google - Partner Operations Manager, YouTube

Google

Singapore (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ByteDance - Senior Site Reliability Architect - Security Engineering - San Jose

ByteDance

San Jose, California, United States (On-Site)
4 Months ago
Google - Product Manager, Google Distributed Cloud, Compliance and Security

Google

Bengaluru, Karnataka, India (On-Site)
1 Week ago
PwC - Auditeur des Systems d'Information

PwC

Douala, Littoral Region, Cameroon (On-Site)
7 Months ago
PwC - IN_Senior Associate _Cloud Security Expert_Advisory Corporate_Advisory_Kolkata

PwC

Kolkata, West Bengal, India (On-Site)
5 Months ago
Trend Micro - (Sr.) Cloud Developer (Vision One)

Trend Micro

Taipei City, Taiwan (On-Site)
7 Months ago
Google - Incident Response Security Consultant

Google

Kuwait City, Al Asimah Governate, Kuwait (On-Site)
1 Day ago
ION - Network Security Engineer

ION

Italy (Hybrid)
6 Months ago
PwC - Cyber Governance Risk & Compliance| Manager | Cyber Security | Technology Consulting

PwC

Dublin, County Dublin, Ireland (On-Site)
6 Months ago
Saviynt - Sr. Principal Software Engineer - Privileged Access Management (PAM)

Saviynt

El Segundo, California, United States (Hybrid)
6 Months ago
Google - Strategic Security Consultant

Google

Toronto, Ontario, Canada (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

About The Company

Where imagination meets innovation, delivering limitless gaming experiences.

San Diego, California, United States (On-Site)

San Jose, California, United States (On-Site)

Dubai, Dubai, United Arab Emirates (On-Site)

New York, New York, United States (On-Site)

San Jose, California, United States (On-Site)

San Jose, California, United States (On-Site)

Seattle, Washington, United States (On-Site)

View All Jobs

Get notified when new jobs are added by ByteDance

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug