Senior Security Engineer - Application/Product Security, APAC

59 Minutes ago • 4 Years + • Cyber Security • Undisclosed

About the job

Job Description

ByteDance seeks a Senior Security Engineer specializing in Application/Product Security for its APAC region. Responsibilities include ensuring applications meet the highest security and privacy standards, performing security tests (black box, code reviews, threat modeling), translating requirements into test plans, certifying infrastructure components, supporting incident response, and providing guidance to other teams. The ideal candidate possesses 4+ years of experience in security engineering, advanced knowledge in web/mobile app security, network security, and coding proficiency (JavaScript, Go, Python, Java, C++, Rust). Experience with CTFs, CVEs, and bug bounty programs is preferred. The role involves working on cutting-edge security challenges at scale.
Must have:
  • 4+ years security engineering experience
  • Advanced knowledge of web/mobile app security
  • Proficiency in at least one programming language (JS, Go, Python, Java, C++, Rust)
  • Strong problem-solving and debugging skills
  • Design review, threat modeling, security mitigation
Good to have:
  • CTF experience
  • CVEs (excluding XSS, CSRF)
  • Bug bounty experience (HackerOne, BugCrowd)
Responsibilities
About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content. Why Join Us Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible. Together, we inspire creativity and enrich life - a mission we aim towards achieving every day. To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always. At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve. Join us. About the Team The team is missioned to build infrastructures, platforms and technologies, as well as to support cross-functional teams to protect our users, products and infrastructures. In this team you'll have a unique opportunity to have first-hand exposure to the strategy of the company in key security initiatives, especially in building scalable and secure-by-design systems and solutions. Our challenges are not your regular day-to-day technical problems; you'll be part of a team that's developing new solutions to new challenges of a kind not previously addressed by big tech. It's working fast, at scale, and we're making a difference. - Ensure that our applications are designed and implemented to the highest security and privacy standards thus maintaining and enhancing user trust. - Design and perform tests and check cases to analyze design, architectures, existing systems services, operating systems, networks and applications from a security perspective, via black box testing, code reviews, automation, threat modeling and research. This is to meet confidentiality, integrity, authentication, availability, authorisation, and nonrepudiation standards. - Translate requirements into test plan, write and execute test scripts or codes in line with standards and procedures to determine vulnerability to attacks. - Certify infrastructure components, systems and applications that meet security standards. - Discover security issues that appear under new threat scenarios, support incident response, forensics, remediation in a cross-functional environment driving towards incident resolution. - Provide guidance to other teams and security engineers, drive security initiatives, and lead cross-functional projects focused on improving the security posture of company's products and systems.
Qualifications
Minimum Qualifications - Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or other relevant majors. - 4+ years of security engineering experience such as design review, threat modeling, security mitigation development, security tooling development or privacy engineering. - Advanced knowledge and understanding in various disciplines: web application security, mobile app security, network security, operating system internals and hardening, applied cryptography, cloud computing. You're expected to be an expert in at least one of these areas. - Solid experience in writing and reviewing code in at least one of the following programming languages: JavaScript (Node JS), Go, Python, Java, C++, Rust. - Strong problem-solving skills and excellent debugging / troubleshooting skills. Preferred Qualifications - CTF players, live competitions and hacking events experience. - CVEs (excluding vulnerabilities such as XSS, CSRF in random CMS) are preferred. - BugBounty experience with reputable statistics in HackerOne, BugCrowd etc. ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
View Full Job Description

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Where imagination meets innovation, delivering limitless gaming experiences.

View All Jobs

Get notified when new jobs are added by ByteDance

Similar Jobs

Salesforce - Senior Backend Software Engineer

Salesforce, Israel (On-Site)

Luxoft - Infrastructure Engineer with AWS

Luxoft, United States (Remote)

Industrial Scientific - Software Engineering Full Stack Developer

Industrial Scientific, India (On-Site)

Wolters Kluwer - FrontEnd/UI - Senior Product Software Engineer

Wolters Kluwer, India (On-Site)

PwC - Data Protection Director

PwC, Canada (On-Site)

Forcepoint - Software Engineer II - C++ Developer

Forcepoint, India (On-Site)

Globalization Partners - Information Security Manager - GRC

Globalization Partners, (Remote)

Allvue Systems - Tech Risk Security Operations Engineer I

Allvue Systems, India (On-Site)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Upstox - SDE II - Backend

Upstox, India (On-Site)

Intelex Technologies ULC - Staff QA Engineer

Intelex Technologies ULC, India (On-Site)

Enphase Energy - Sr. Software Engineer (QA Lead)

Enphase Energy, India (On-Site)

PhonePe - Firmware Engineer (5-7 yrs bracket)

PhonePe, India (On-Site)

Hitachi - Quality Analyst

Hitachi, India (On-Site)

Unity - Senior Data Engineer

Unity, Finland (On-Site)

The Walt Disney Company - Lead Machine Learning Engineer, Ad Platforms

The Walt Disney Company, United States (On-Site)

Activision - Staff Backend Engineer - Activision Blizzard Media

Activision, United States (On-Site)

Get notifed when new similar jobs are uploaded

Jobs in Singapore

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

undefined - Senior Application Security Engineer

Bengaluru, Karnataka, India (On-Site)

PwC - Penetration Tester (m/f)

PwC, Slovakia (On-Site)

Palo Alto Networks - Systems Engineering Manager - SE Academy, India

Palo Alto Networks, India (On-Site)

Klüber Lubrication - Vulnerability Analyst (F/M/D)

Klüber Lubrication, India (Hybrid)

Nintendo - Security Engineer

Nintendo, United States (Hybrid)

DataVisor - Senior Security Engineer

DataVisor, India (Remote)

Get notifed when new similar jobs are uploaded