- Experience
- 2+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 20 часов назад
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
As a Senior Application Security Engineer at OSL, you will be responsible for comprehensive security auditing and penetration testing across web, API, and Web3 business segments including Smart Contracts, DApps, and Wallets.
Primary Responsibilities
- Perform detailed code audits and penetration tests on web-based applications, APIs, and blockchain-related technologies such as Smart Contracts and decentralized applications.
- Implement and promote Security Development Lifecycle (SDL) practices by integrating static and dynamic application security testing tools into continuous integration and delivery pipelines.
- Lead rapid incident response efforts for application security breaches, conduct forensic analysis to identify root causes, and oversee remediation activities.
- Engage in the security architecture and design review for new products or business lines, identifying potential logic and architectural vulnerabilities, and recommending secure design improvements.
Required Skills and Experience
- Minimum of two years' practical experience in application security or penetration testing with extensive understanding of OWASP Top 10 vulnerabilities and expertise in discovering and exploiting web and API flaws.
- Strong familiarity with Web3 and blockchain security threats such as reentrancy attacks, flash loan exploits, signature forgery, and cross-site vulnerabilities in DApps; experience auditing Solidity smart contracts or conducting penetration tests on wallets or decentralized apps is highly desirable.
- Proficiency with common security assessment tools such as Burp Suite, Slither, Mythril, and Checkmarx, along with skills in scripting automation using Python or Go.
- Excellent interpersonal and communication abilities, enabling effective collaboration with various departments to ensure timely vulnerability resolution.
Additional Information
The role requires onsite presence in Singapore and involves working closely with development teams to embed security best practices within product lifecycles.
Skills
How they work
Communication
Teamwork & Collaboration