Job Description
The role is positioned to ensure the security of business systems and core assets, covering security testing, risk governance, emergency response, and security tool development. The candidate should be proficient in utilizing AI Agents to enhance the quality, efficiency, and auditability of security operations.
Key Responsibilities
- Participate in the full lifecycle security construction of business systems and products, including security reviews, penetration testing, security hardening, security inspections, launch checks, and continuous risk tracking.
- Conduct security testing for Web, API, mobile applications, hosts, networks, and cloud environments to verify vulnerability impacts, produce reproducible test reports, risk assessments, and remediation suggestions, and drive issue resolution.
- Perform specialized risk assessments and security hardening for critical scenarios such as exchange wallets, deposit/withdrawal processes, signature and key management, and blockchain nodes.
- Contribute to the development of security baselines, detection rules, response plans, and emergency response mechanisms; handle security incident analysis, containment, traceability, review, and improvement tracking.
- Engage in the design and development of security platforms, detection tools, and automated scripts to enhance risk discovery, alert analysis, vulnerability verification, and operational efficiency.
- Apply AI Agents to security testing, code and configuration reviews, intelligence analysis, vulnerability assessment, emergency response, and documentation generation, with manual validation, risk control, and audit trails for results.
Job Requirements
The following are mandatory requirements; candidates must demonstrate them through case studies or on-site practical tests.
- Minimum 3 years of experience in the security field, with at least 2 years focused on exchange wallet security, blockchain security, or financial risk control.
- Bachelor's degree or higher in Computer Science, Cybersecurity, Software Engineering, or related fields; undergraduate degree is mandatory.
- Proficient in penetration testing methodologies and common attack chains, capable of independently completing information gathering, vulnerability discovery, exploitation verification, risk assessment, report generation, and retesting closure.
- Skilled in common attack techniques and defense hardening methods for systems, networks, and Web/API applications; understands authentication, access control, data protection, key management, and security boundaries.
- Familiar with Unix/Linux security configurations, baseline checks, log analysis, and mainstream security detection tools; proficient in at least one scripting language (Python, Go, or Shell).
- Experienced in security incident response, capable of independently conducting alert analysis, impact assessment, evidence preservation, remediation, and post-incident review.
- Strong risk awareness, logical analysis, written communication, cross-team collaboration, and continuous learning abilities; maintains judgment quality and drives problem-solving under high-pressure scenarios.
AI Agent Proficiency (Mandatory)
Hard requirement: Must go beyond simple chat or code completion; capable of independently designing, executing, validating, and documenting reusable Agent workflows.
- Proficient in mainstream general-purpose Agents, programming Agents, IDE/CLI Agents, and their tool integration capabilities; able to select appropriate models, modes, and execution strategies based on task requirements.
- Fully understands task decomposition, instruction design, context engineering, constraint setting, tool orchestration, long-task management, memory management, human-machine collaboration, and multi-Agent coordination.
- Capable of integrating Agents with terminals, code repositories, browsers, knowledge bases, APIs, scripts, and MCP or similar tool protocols to build end-to-end security workflows.
- Able to create reusable templates or automated processes for security testing, code audits, configuration reviews, vulnerability verification, intelligence analysis, alert assessment, emergency response, and report generation.
- Systematically validates Agent outputs, including fact-checking, code review, command risk assessment, result reproduction, cross-validation, test cases, and acceptance criteria; never accepts unverified outputs.
- Understands security governance requirements for Agent usage, including least privilege, sensitive data protection, credential isolation, data anonymization, prompt injection prevention, third-party tool and dependency risk control, execution auditing, and manual approval.
- Quantifies efficiency and quality improvements from Agent usage and documents them as reusable prompt templates, workflows, rules, knowledge bases, or operational guidelines for the team.
AI Agent Skill Assessment
- On-site completion of a security-related task using AI Agents, clearly explaining objectives, task breakdown, tool selection, permission boundaries, validation methods, and final conclusions.
- Identifies and corrects Agent errors, unsafe commands, false references, or irreproducible results, demonstrating a thorough manual review process.
- Submits at least one real-world Agent workflow case, detailing inputs, outputs, manual control points, risk measures, and quantifiable benefits.
Preferred Qualifications
- Hands-on experience with exchange wallets, private keys/mnemonics, signature services, hot/cold wallets, deposit/withdrawal processes, or blockchain node security.
- Experience in building security platforms or emergency response platforms, or verifiable achievements in security automation or Agent workflow implementation.
- Publicly submitted high-quality vulnerability PoCs, CVE/CNVD/CNNVD vulnerabilities, or outstanding contributions to open-source security projects, attack/defense competitions, or vulnerability response platforms.
- Experience in cloud-native, container, Kubernetes, supply chain security, or smart contract auditing.
Benefits
7 days of paid annual leave per year, increasing with tenure, and monthly paid sick leave.