Job description
Job Responsibilities:
1. Responsible for the overall information security architecture planning and implementation of the company, including: account security, fund security, wallet security, API security, data security, cloud security, internal permission security, etc.;
2. Establish and continuously improve security management systems, standards, and processes;
3. Responsible for transaction system security protection: login security, risk control strategies, anti-cheating, anti-scraping, abnormal transaction identification, etc.;
4. Establish security monitoring and alert mechanisms;
5. Organize vulnerability remediation and security reviews, manage vulnerability bounty programs, security scanning, and penetration testing;
6. Collaborate with the compliance team to meet regulatory and audit requirements, promoting: ISO27001, SOC2, data privacy compliance, KYC/AML security requirements, etc.;
7. Responsible for security audits and risk assessment work;
8. Manage and cultivate the security technical team, collaborating with R&D, operations, product, compliance, and other teams to advance security projects.
Job Requirements:
1. Bachelor's degree or above, preferably in computer science, network security, information security, or related fields;
2. Over 5 years of security-related experience, with more than 3 years of team management experience;
3. Experience in internet finance, exchanges, Web3, payment, or financial industry security is preferred;
4. Familiar with at least several of the following areas:
① Basic security: network security/Web security/API security/cloud security/Linux security/data security;
② Blockchain/CEX-related: wallet security/hot and cold wallet systems/on-chain attack case analysis/private key management mechanisms;
③ Security operations: SIEM/SOC construction/vulnerability management/security monitoring/security emergency response/risk assessment;
④ Engineering capabilities: Familiar with at least one scripting or development language: Python/Go/Shell/Java.
Bonus Points:
1. Experience in large CEX or Web3 project security;
2. Real security offensive and defensive experience;
3. Familiarity with overseas security compliance systems;
4. Experience in building security systems for 0-1 projects.