About The Team
Our security engineering team builds internal platforms that help developers deliver secure software efficiently. We develop Secure SDLC capabilities including SAST, SCA, software supply-chain security, and DevSecOps automation. We also apply AI and Agent technologies to code review, vulnerability analysis, false-positive reduction, and security automation, embedding security directly into CI/CD pipelines and developer workflows.
Job Description
- Participate in the design, development, and continuous improvement of internal security tools and platforms, including but not limited to:
- AI-assisted code review and vulnerability analysis;
- Static Application Security Testing (SAST);
- Software Composition Analysis (SCA) and software supply-chain security;
- Security automation and other Secure SDLC tools.
- Develop and improve security detection rules, analysis logic, and automated workflows based on security requirements.
- Participate in secure code review, vulnerability analysis, and false-positive investigation to improve detection accuracy and vulnerability coverage.
- Use AI-assisted development, code-analysis, and security-research tools to improve engineering and security-analysis efficiency.
- Contribute to LLM- or Agent-based security tools involving repository search, tool use, task orchestration, and result validation.
- Integrate security tools with Git, source-code management platforms, CI/CD pipelines, and other developer workflows.
- Participate in feature development, testing, troubleshooting, performance improvement, and ongoing system maintenance.
- Collaborate with security and engineering teams to support the analysis, remediation, and continuous improvement of security issues.
- Keep up with developments in application security, DevSecOps, software supply-chain security, and AI-assisted security engineering.
- Mentoring Junior Security Engineers and Intern.
Requirements
- Bachelor's degree in Computer Science, Information System, Software Engineering, Automation Engineering, or related field in Engineering.
- At least 2 years of full time experience in security engineering or application security.
- Practical experience using AI-assisted development, code-analysis, or security tools, with the ability to perform basic validation of AI-generated code and analysis results is preferred.
- Good application security fundamentals and an understanding of common Web, API, and code-security risks, such as injection, access-control vulnerabilities, authentication and authorization weaknesses, SSRF, unsafe file handling, and sensitive-data exposure.
- Basic code-reading and analysis skills, with the ability to understand the root causes and remediation approaches of common vulnerabilities.
- Familiarity with at least one programming language, such as Go, Python, Java, or JavaScript, and the ability to implement common features, modify existing code, debug issues, and troubleshoot problems.
- Good computer science fundamentals, including networking, operating systems, databases, processes, threads, and common software runtime mechanisms.