【About the company】
We are one of the world's earliest and most established digital asset platforms, serving tens of millions of users across global markets. Consistently ranked among the top exchanges worldwide, we support a comprehensive suite of trading and wealth management products across thousands of digital assets. With thousands of employees spanning key financial hubs globally, we operate with a remote-first, high-autonomy culture that attracts talent who thrive in fast-moving, intellectually demanding environments. We are building the financial infrastructure of the next era of the internet.
【Why This Role】
Account takeover risk is changing quickly: social engineering, phishing sites, deepfake identity bypass, client-side malware, malicious browser extensions, and post-takeover fund movement now happen in tighter windows. This role exists to stop asset loss before it becomes irreversible. You will build the strategy layer that connects risk rules, AI detection, dynamic verification, and automated response into a second-level defense system.
【Requirements】
- Design account and fund security strategies across the user lifecycle, from login and API authorization to withdrawals, transfers, and suspicious trading behavior
- Build real-time detection and dynamic step-up verification for social engineering, phishing, malware hijacking, browser extension compromise, and abnormal device behavior
- Partner with algorithm teams on anti-forgery models for AI face spoofing, identity bypass, non-human behavior, and abnormal transaction patterns
- Deploy second-level monitoring and interception strategies for post-takeover fund movement, including malicious matched trading, unusual counterparties, and abnormal price gaps
- Upgrade security infrastructure with product, security engineering, and funding teams, including AI Agent-based case handling and centralized verification capabilities
【What You'll Bring】
Non-negotiables
- You have owned account security, anti-fraud, ATO defense, fund-risk, or abuse strategy in a production environment where asset loss was a hard metric
- You can reverse-engineer attack paths across phishing, social engineering, malware hijacking, deepfake bypass, and post-takeover laundering behavior
- You can use data to investigate messy risk signals across device fingerprints, behavior traces, transaction logs, identity events, and counterparties
- You know how to balance security and user experience through confidence scoring, dynamic challenges, staged intervention, and clear escalation paths
Bonus
- You have worked in crypto exchanges, fintech anti-fraud, KYC risk, account security, or high-scale internet abuse defense
- You have collaborated with algorithm teams on face spoofing, anomaly detection, graph risk, or real-time interception models
- You have built risk infrastructure involving verification centers, automated case handling, or AI-assisted investigation workflows