Senior Security Engineer, Application Security
Trail of Bits- Full Time
- Senior (5 to 8 years)
Candidates must possess an OSCP (or equivalent, such as CREST) certification, demonstrating a deep understanding of security vulnerabilities and penetration testing methodologies. A strong knowledge of the OWASP Top 10 and the ability to detect and address logic flaws is highly desirable, along with minimum four years of experience in Web API testing and proficiency in using BurpSuite. Experience with Mobile App testing, comprehension of jailbreaking/rooting a device, API hooking, reverse engineering, and de-obfuscation is also beneficial.
The Application Security Engineer (Pentester) will discover security vulnerabilities through design review, source code review, and penetration testing, either manually or by using automated tools, and follow up on the remediation process. They will participate in relevant agile scrum meetings and provide professional recommendations on the design of security controls, libraries, and/or protocols. The role also involves conducting security-related training sessions, implementing various security control verification and risk detection through automated scripts, and providing support on application-level security monitoring, intrusion detection, and incident response.
Cryptocurrency trading and financial services platform
Crypto.com provides a platform for trading and managing cryptocurrencies, catering to over 100 million customers worldwide. Users can buy, sell, and store various cryptocurrencies while benefiting from services like transaction processing and card issuance. The platform generates revenue primarily through transaction fees and premium services, ensuring a secure and user-friendly experience. What sets Crypto.com apart from its competitors is its strong focus on regulatory compliance, security, and privacy certifications, which builds trust among users. The company's goal is to accelerate cryptocurrency adoption, aiming to have 'Cryptocurrency in Every Wallet™' and to support builders and entrepreneurs in creating a more equitable digital ecosystem.