Lead the design of enterprise level security architecture, covering security protection for core systems such as hybrid cloud infrastructure, Web3 application scenarios, and traditional financial services
Independently build and debug open-source security components (such as Wazuh/Suricata/osquiry), and construct a defense in depth system that adapts to budget constraints
Establish a cross regional security collaboration mechanism, coordinate product, research and development, compliance and other departments to build a security technology ecosystem
Monitoring and Response
Build an active defense system, design abnormal behavior detection rules and response processes
Build a real-time monitoring system based on business operations, and establish a risk identification model for scenarios such as fund theft and abnormal transactions
Lead the emergency response to financial level security incidents and develop contingency plans for sensitive data breaches, financial fraud, and other scenarios
Engineering Security Practice
Build a log analysis platform to achieve cross time zone log correlation analysis and traceability evidence collection
Design terminal control solutions and automated compliance inspection tools that are adaptable to multiple jurisdictions
Promote the evolution of the DevSecOps system and integrate detection tools into the CI/CD process
Build a blockchain node monitoring system and design a smart contract security audit framework
Operation and Maintenance
Formulate SDL security development specifications for Internet financial business, and lead penetration tests and red blue confrontation drills
Lead the implementation of DevSecOps system and embed automated security detection module in CI/CD process
Build an endpoint protection system that is compatible with emerging businesses such as mobile payments and digital currencies
Compliance Security
Design and implement the company's information security baseline to ensure that the company's data transmission, data protection, security system, etc. comply with local compliance and regulatory requirements
Job Requirements
Bachelor's degree or above in computer/information security related majors
More than 8 years of experience in information security, over 3 years of team management experience, experience in the fintech field is preferred
Good communication skills, English can be used as a working language
Familiar with the open source security ecosystem, with practical experience in designing security systems from scratch preferred
Proficient in WAF, IDS, and implementation of defense systems such as situational awareness in financial scenarios
Proficient in designing progressive security evolution paths under resource constraints, balancing short-term defense and long-term architecture requirements
Accept quarterly international travel (approximately 30 days per year)