Job Description
Key Responsibilities
- Conduct thorough code reviews and implement quality control measures to ensure compliance with security standards and specifications
- Participate in optimizing code audit processes to improve efficiency and effectiveness
- Perform in-depth technical analysis and evaluation of critical project modules to identify potential security risks and quality issues
- Collaborate closely with development teams to provide code improvement recommendations and technical support
- Drive automation of code audit and penetration testing processes by developing or customizing specialized tools to enhance efficiency and coverage
- Develop exchange-specific secure coding standards and promote their integration into CI/CD pipelines (e.g., GitLab SAST)
- Provide vulnerability remediation solutions and technical training for development teams
- Document audit methodologies and compile case studies of typical vulnerabilities
Job Requirements
- Bachelor's degree or higher in Computer Science, Cybersecurity, or related field, or equivalent practical experience
- Minimum 2 years of experience in information security, with at least 1 year focused on code security auditing or vulnerability research
- Experience in web3 industry or independently completing code audits for medium-to-large projects and producing high-quality audit reports
- Proficiency in common programming languages (Java, C++, Go, Python, etc.) and multiple programming techniques
- Familiarity with common code scanning tools (CodeSec, Fortify, Checkmarx, CodeQL, etc.) and ability to customize rules and evaluate results
- Thorough understanding of OWASP Top 10, CWE/SANS Top 25 vulnerabilities including their principles, exploitation methods, and remediation
- Strong logical thinking and problem-solving skills
- Knowledge of common cybersecurity threats and protective measures
- Excellent learning ability to quickly adapt to new technologies and environments
- Preferred: Holding security certifications (CISP, CISSP, CSSLP) or having CNVD/CNNVD/CVE vulnerability submission records


