Expert Application Security Engineer (iOS)
TLDR
Identify and mitigate security vulnerabilities while collaborating with development teams to enhance secure coding practices on one of the leading crypto platforms.
-
Identify and address security vulnerabilities in code, systems, and networks using manual review, automated tools, and threat modeling.
-
Manage and optimize application security tools, processes, and alerts.
-
Validate and respond to Bug Bounty submissions.
-
Stay informed on the latest offensive security techniques, application security threats, and best practices, and suggest improvements to enhance our security posture.
-
Produce detailed reports of your findings, present them to both management and technical teams, and contribute to preventing real-world attacks.
-
Collaborate with development teams to implement secure coding practices.
-
Work alongside other teams, including operations and compliance, to ensure that security is a consistent priority across the organization.
-
Participate in incident response and management activities.
-
3+ years of experience in offensive security techniques.
-
In-depth understanding of security risks, vulnerabilities, and concepts in web and mobile applications.
-
Proficient in code review, particularly with Kotlin/Swift/Typescript/JavaScript, with a strong grasp of application security threats.
-
Ability to create proof-of-concepts (PoCs) to demonstrate vulnerabilities, review patch code for adherence to standards, and collaborate with repository owners and maintainers.
-
Strong analytical and problem-solving abilities.
-
Excellent verbal and written communication skills.
-
Prior experience in developing mobile security SDKs with a daily active user base of over ten million is preferred.
-
Participated in large-scale business risk control projects, or have practical experience in threat intelligence/business risk prevention, and analysis/countermeasures against black and gray industries.
-
In-depth reverse engineering of major apps from first-tier vendors, or other experiences/projects that demonstrate reverse engineering capabilities.
-
Priority given to candidates who can simultaneously master relevant technologies on multiple platforms.
-
Proficient in ARM assembly, capable of deep-level countermeasures at the native and application layers.
-
Have certain capabilities in device fingerprint recognition, able to simulate new devices through methods such as flashing, modification, and application cloning.
-
Competitive total compensation package
-
L&D programs and Education subsidy for employees' growth and development
-
Various team building programs and company events
-
More that we love to tell you along the process!
Benefits
Learning Budget
L&D programs and Education subsidy for employees' growth and development
Team building programs and events
Various team building programs and company events
OKX operates as a prominent cryptocurrency exchange, enabling users to buy, sell, and trade a wide range of digital assets, including Bitcoin and Ethereum. In addition to facilitating crypto trading, they've developed OKX Wallet, a widely-used platform for accessing decentralized applications and exploring the Web3 landscape.
- Founded
- Founded 2017
- Employees
- 500+ employees
- Industry
- Diversified Financial Services