Web Application Security Engineer

2 weeks ago


Singapore NodeFlair Full time

Job Summary:

Job Type
Permanent

Seniority
Mid Junior

Years of Experience
At least 2 years

Tech Stacks
HTTP TCP Websockets AWS Go Checkmarx CI gRPC Shell Azure Java Linux JavaScript SQL Python

  • If you're looking for a fastpaced, missiondriven organization where opportunities to learn and excel are endless, then Binance is the place for you

Responsibilities:

  • Configure, deploy and manage Web Application Firewall (WAF) and Bot mitigation solutions, as well as integration of those platforms with other solutions as the need arises.
  • Perform indepth security review of new Binance features and functionalities. This includes identifying security vulnerabilities (OWASP top ten, common issues in NVD, RCE, etc.), reviewing code in Java and/or node JS, verifying security posture through pentest (using manual/automated techniques with tools like Kali Linux, Burp suite, Checkmarx, WebInspect).
  • Hands on security experience working with AWS and common service components within AWS. Ability to identify security gaps in the overall design as well as configuration issues in individual components.
  • Partner with Product Security, SaaS Operations, and Engineering teams to evaluate, select, and implement WAF services at scale Work with Engineering teams to coordinate WAF onboarding, explaining and coordinating any architectural or configuration changes required to support WAF deployment.
  • Participate in technical design activities to ensure a sound design and any infrastructure impact is understood.
  • Review vulnerability scan output and assess where WAF configuration can be used to mitigate attacks.
  • Participate in technical design activities to ensure a sound design and any infrastructure impact is understood.
  • Select and deploy appropriate CI/CD tools for WAF pipeline. Strive for continuous improvement and build continuous integration, continuous development, and constant Security pipeline (CI/CD Pipeline).

Requirements:

  • Relevant Experience or Degree in Information Security or Computer Science preferred; other majors will be considered.
  • Strong scripting skills (Shell, Python, Batch, Power Shell, etc).
  • Prefer experience in cloud Web Application Firewalls, both SaaS and native cloud provider relevant (Imperva, CloudArmor, AWS WAFv2, Azure WAFv2).
  • Prefer experience with WAF solutions.
  • Nice to Haves:
  • Involved in Bug Bounty program (Need provide evidence). Participated and win in a Capture the Flag (CTF) event, or cyber challenge events a plus.(Need provide evidence)
  • If you have an indeep knowledge of a specific technology, teach us about it. Our engineers have a wide breadth of security knowledge, but we love it when engineers have an extensive understanding of one technology.
-
Working at Binance

  • Be a part of the world's leading blockchain ecosystem that continues to grow and offers excellent career development opportunities
  • Work alongside diverse, worldclass talent in an environment where learning and growth opportunities are endless
  • Tackle fastpaced, challenging and unique projects
  • Work in a truly global organization, with international teams and a flat organizational structure
  • Competitive salary and benefits Flexible working hours, remotefirst, and casual work attire
  • Learn more about how Binancians embody the organization's
    core values, creating a unified culture that enables collaboration, excellence, and growth.
  • Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.


  • Singapore WEB MASTER CONSULTANCY PTE LTD Full time

    Roles & ResponsibilitiesJob Description & RequirementsKnowledge of PHP/MySQL.Experience developing in PHP, which requires integration with databases such as MySQL.Experience programming in HTML, CSS, XML, JavaScript, jQuery, etc.Experience in WordPress development is a plus.Must be able to understand and use development frameworks.Must be able to follow...


  • Singapore WEB MASTER CONSULTANCY PTE LTD Full time

    Roles & ResponsibilitiesJob Description & RequirementsKnowledge of PHP/MySQL.Experience developing in PHP, which requires integration with databases such as MySQL.Experience programming in HTML, CSS, XML, JavaScript, jQuery, etc.Experience in WordPress development is a plus.Must be able to understand and use development frameworks.Must be able to follow...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media’s application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers  (2) Software...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media's application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers (2) Software Composition...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media’s application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers  (2) Software...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media's application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers (2) Software Composition...


  • Singapore TAUREN PTE. LTD. Full time

    **Responsibilities: - Work closely with product, engineering, and DevSecOps teams to deliver secure software across web, API, mobile, and other platforms. Enable secure software development and delivery by producing and delivering actionable security requirements, guidelines, and design patterns to engineering. Guide team and thirdparty vendors in performing...


  • Singapore INNOEDGE LABS PTE. LTD. Full time

    Roles & ResponsibilitiesAt InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver...


  • Singapore INNOEDGE LABS PTE. LTD. Full time

    Roles & ResponsibilitiesAt InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver...


  • Singapore Infosight consulting Full time

    Provide technical support and advisory on Web Application Servers / Middleware to the IT team on all related projects. Optimize the environment for scalability and performance, including sizing, tuning and monitoring of these environments. Enforce security policies for access to web services. Contribute to the ongoing improvement of the efficiency and...


  • Singapore IKIGAI ENABLERS PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description: At least 2 years of experience in a relevant DevSecOps role and technical degree in computer / information science; or At least 4 years of experience in a relevant DevSecOps role; or At least 6 years of related field work experience, at least 1 year of which in a software development role, and at least 1 of which...


  • Singapore Government Technology Agency Full time

    [What the role is] Singapore Land Authority is the geospatial agency in Singapore, managing and operating a web-based public map platform to provide localised and accurate map data and location-based services (LBS) to serve many government agencies, private sectors and general public. We are looking for a talented web application developer to join our...


  • Singapore Government Technology Agency Full time

    [What the role is] Singapore Land Authority is the geospatial agency in Singapore, managing and operating a web-based public map platform to provide localised and accurate map data and location-based services (LBS) to serve many government agencies, private sectors and general public. We are looking for a talented web application developer to join our...


  • Singapore Government Technology Agency Full time

    [What the role is] Singapore Land Authority is the geospatial agency in Singapore, managing and operating a web-based public map platform to provide localised and accurate map data and location-based services (LBS) to serve many government agencies, private sectors and general public. We are looking for a talented web application developer to join our...


  • Singapore Government Technology Agency Full time

    [What the role is] Singapore Land Authority is the geospatial agency in Singapore, managing and operating a web-based public map platform to provide localised and accurate map data and location-based services (LBS) to serve many government agencies, private sectors and general public. We are looking for a talented web application developer to join our...


  • Singapore Government Technology Agency Full time

    [What the role is] Singapore Land Authority is the geospatial agency in Singapore, managing and operating a web-based public map platform to provide localised and accurate map data and location-based services (LBS) to serve many government agencies, private sectors and general public. We are looking for a talented web application developer to join our...


  • Singapore JAC Recruitment Singapore Full time

    Location:SingaporeSpecialisation:Information TechnologySalary:SGD 80, ,000 (Annual)Reference:PR/093311Contact details:Sarah ChinJob published:March 02, :45Our client is a premier tech firm in the finance industry, renowned for delivering revolutionary financial products to a global user base. This company excels in utilizing state-of-the-art technology to...


  • Singapore Singapore Land Authority Full time

    Role Overview: Singapore Land Authority is the leading geospatial agency in Singapore, responsible for managing and operating a user-friendly public map platform that delivers precise map data and location-based services (LBS) to various government agencies, businesses, and the general public. We are seeking a skilled web application developer to join our...


  • Singapore Singapore Land Authority Full time

    Role Overview: Singapore Land Authority is the leading geospatial agency in Singapore, responsible for managing and operating a user-friendly public map platform that delivers precise map data and location-based services (LBS) to various government agencies, businesses, and the general public. We are seeking a skilled web application developer to join our...


  • Singapore THE SUPREME HR ADVISORY Full time

    5 days 9am " 6pm Location: Queenstown Job Scope: To develop and build a JAVA Spring Boot + Angular + MySQL web application on Microsoft Azure stack To deploy, test, debug, tune and main 5 days 9am ' 6pm Location:Queenstown Job Scope: To develop and build a JAVA Spring Boot + Angular + MySQL web application on Microsoft Azure stack To deploy, test, debug,...