51 Security Testing jobs in Hong Kong
Cyber Security Specialist (Penetration Testing)
Posted 8 days ago
Job Viewed
Job Description
Join to apply for the Cyber Security Specialist (Penetration Testing) role at Mox Bank
Cyber Security Specialist (Penetration Testing)1 day ago Be among the first 25 applicants
Join to apply for the Cyber Security Specialist (Penetration Testing) role at Mox Bank
Get AI-powered advice on this job and more exclusive features.
About Mox
Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile eXperience; Money eXperience; Money X (multiplier), eXponential growth, eXploration… it’s all up for us to define together.
Application Deadline: 6 October 2025
Department: Technology-CDSIO
Location: Hong Kong (SAR)
About Mox
Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile eXperience; Money eXperience; Money X (multiplier), eXponential growth, eXploration… it’s all up for us to define together.
Why Mox
Everything at Mox – from our products, features, to rewards – is designed based on customer research, tailor made for your needs. We care about what customers care about, especially in data security and privacy. Data ethics is core to everyone here at Mox. Mox rewards you with an array of banking and lifestyle benefits. Who says banking can’t be fun?
What we are looking for?
We are looking for a cyber security specialist (Penetration testing to join our team!
Responsibilities
- Provide security expertise to ensure the ongoing confidentiality, integrity, and availability of systems and information effectively and efficiently.
- Scope and perform hands-on penetration testing and security assessments of web applications, APIs, infrastructure, cloud environments and mobile (iOS/Android) apps to assess and validate their security posture
- Write high quality reports on identified vulnerabilities, including recommendations to remediate, and deliver report to stakeholders
- Manage security assessments conducted by vendors and consultants
- Manage the penetration testing pipeline to ensure on-time completion and delivery
- Work closely with key development and operations stakeholders to ensure timely remediation
- Conduct security code reviews and make recommendations to developers
- ·Drive security awareness of secure coding practices and techniques
- Work collaboratively with key development and operations stakeholders to support the secure CI/CD pipeline
- Conduct offensive research to evaluate emerging cyber security threats and trends
- Work closely with the security operations team to proactively identify potential weaknesses, threats or vulnerabilities and address them
- Maintain up-to-date knowledge of the latest attacks, vulnerabilities, mitigation strategies, industry best practices and regulations
- Provide subject matter expertise, security consulting, and advisory services to business entities and project teams
- Build strong working relationships across the business and technology teams
- 5+ Years’ experience in IT security related positions with a key focus on penetration testing and application security
- You should be able to demonstrate:
- Passion for offensive security and assurance
- Risk mindset and knowledge of risk management guidelines and frameworks
- Good understanding of penetration testing methodologies / techniques and software security principles
- Ability to communicate and articulate technical findings with stakeholders at all levels of the business
- Hands-on threat, vulnerability, and remediation management experience
- Experience working in a cloud and container-based environment is highly desired
- Critical thinker with strong problem-solving and analytical skills
- Strong time management and ability to manage multiple projects under strict timelines.
- Development and automation experience in one or more programming languages are highly desired
- Strong collaborative nature and ability to contribute to a team environment
- Previous experience working within the finance/banking or advisory services industry beneficial
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Banking
Referrals increase your chances of interviewing at Mox Bank by 2x
Sign in to set job alerts for “Cyber Security Specialist” roles.Sha Tin District, Hong Kong SAR 6 days ago
Incident Response Consultant, Cyber Security (English, Mandarin, Cantonese) Cybersecurity Analyst (Red Team), 42K UpSha Tin District, Hong Kong SAR 1 week ago
Information Technology Cybersecurity Analyst / Specialist Cybersecurity Detection and Response AnalystSha Tin District, Hong Kong SAR 1 week ago
CYBER SECURITY AND RISK ANALYST / CYBER SECURITY ENGINEER Information Security Engineer - Officer/ Associate - Security Services - IT - 12months contract Application Security Specialist & Penetration Tester Cyber Security Consultant - Red Team SpecialistCentral & Western District, Hong Kong SAR 3 days ago
Cyber Security Analyst / Engineer (Identity and Access Management) Assistant Manager, Information Security AssuranceSha Tin District, Hong Kong SAR 2 weeks ago
Kwun Tong District, Hong Kong SAR 4 days ago
Network Security Engineer (1 year contract) Information Technology Security Specialist (Senior) Cyber Security Consultant & Penetration TesterWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrCyber Security Specialist (Penetration Testing)
Posted 3 days ago
Job Viewed
Job Description
Join to apply for the Cyber Security Specialist (Penetration Testing) role at Mox Bank
Cyber Security Specialist (Penetration Testing)1 day ago Be among the first 25 applicants
Join to apply for the Cyber Security Specialist (Penetration Testing) role at Mox Bank
Get AI-powered advice on this job and more exclusive features.
About Mox
Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile eXperience; Money eXperience; Money X (multiplier), eXponential growth, eXploration… it’s all up for us to define together.
Application Deadline: 6 October 2025
Department: Technology-CDSIO
Location: Hong Kong (SAR)
About Mox
Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile eXperience; Money eXperience; Money X (multiplier), eXponential growth, eXploration… it’s all up for us to define together.
Why Mox
Everything at Mox – from our products, features, to rewards – is designed based on customer research, tailor made for your needs. We care about what customers care about, especially in data security and privacy. Data ethics is core to everyone here at Mox. Mox rewards you with an array of banking and lifestyle benefits. Who says banking can’t be fun?
What we are looking for?
We are looking for a cyber security specialist (Penetration testing to join our team!
Responsibilities
- Provide security expertise to ensure the ongoing confidentiality, integrity, and availability of systems and information effectively and efficiently.
- Scope and perform hands-on penetration testing and security assessments of web applications, APIs, infrastructure, cloud environments and mobile (iOS/Android) apps to assess and validate their security posture
- Write high quality reports on identified vulnerabilities, including recommendations to remediate, and deliver report to stakeholders
- Manage security assessments conducted by vendors and consultants
- Manage the penetration testing pipeline to ensure on-time completion and delivery
- Work closely with key development and operations stakeholders to ensure timely remediation
- Conduct security code reviews and make recommendations to developers
- ·Drive security awareness of secure coding practices and techniques
- Work collaboratively with key development and operations stakeholders to support the secure CI/CD pipeline
- Conduct offensive research to evaluate emerging cyber security threats and trends
- Work closely with the security operations team to proactively identify potential weaknesses, threats or vulnerabilities and address them
- Maintain up-to-date knowledge of the latest attacks, vulnerabilities, mitigation strategies, industry best practices and regulations
- Provide subject matter expertise, security consulting, and advisory services to business entities and project teams
- Build strong working relationships across the business and technology teams
- 5+ Years’ experience in IT security related positions with a key focus on penetration testing and application security
- You should be able to demonstrate:
- Passion for offensive security and assurance
- Risk mindset and knowledge of risk management guidelines and frameworks
- Good understanding of penetration testing methodologies / techniques and software security principles
- Ability to communicate and articulate technical findings with stakeholders at all levels of the business
- Hands-on threat, vulnerability, and remediation management experience
- Experience working in a cloud and container-based environment is highly desired
- Critical thinker with strong problem-solving and analytical skills
- Strong time management and ability to manage multiple projects under strict timelines.
- Development and automation experience in one or more programming languages are highly desired
- Strong collaborative nature and ability to contribute to a team environment
- Previous experience working within the finance/banking or advisory services industry beneficial
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Banking
Referrals increase your chances of interviewing at Mox Bank by 2x
Sign in to set job alerts for “Cyber Security Specialist” roles.Sha Tin District, Hong Kong SAR 6 days ago
Incident Response Consultant, Cyber Security (English, Mandarin, Cantonese) Cybersecurity Analyst (Red Team), 42K UpSha Tin District, Hong Kong SAR 1 week ago
Information Technology Cybersecurity Analyst / Specialist Cybersecurity Detection and Response AnalystSha Tin District, Hong Kong SAR 1 week ago
CYBER SECURITY AND RISK ANALYST / CYBER SECURITY ENGINEER Information Security Engineer - Officer/ Associate - Security Services - IT - 12months contract Application Security Specialist & Penetration Tester Cyber Security Consultant - Red Team SpecialistCentral & Western District, Hong Kong SAR 3 days ago
Cyber Security Analyst / Engineer (Identity and Access Management) Assistant Manager, Information Security AssuranceSha Tin District, Hong Kong SAR 2 weeks ago
Kwun Tong District, Hong Kong SAR 4 days ago
Network Security Engineer (1 year contract) Information Technology Security Specialist (Senior) Cyber Security Consultant & Penetration TesterWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrConsultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Con[...]
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ005350) role at KPMG China
Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ005350)Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ005350) role at KPMG China
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.
KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.
Our wide range of projects includes Cyber Strategy, Cyber Digital Transformation, Governance & Risk, as well as a strong presence in Penetration Testing or Ethical Hacking. We are keen to speaking with cyber security specialists with various expertise and experiences to join our growth story.
We are now seeking Consultant/ Senior Consultant candidates for Cyber Defense Team.
Key Responsibilities
- Perform vulnerability assessment and penetration tests on different platforms and technologies
- Simulate real-time cyber-attacks using red team / blue team / purple team exercises
- Conduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware / ransomware
- Conduct source code review to identify software program vulnerabilities and detect malware or malicious embedded code
- Conduct cloud / server / network / middleware security configuration assessments
- Conduct architecture review for cloud / on-premise IT environments
- Prepare reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities
- Assist in continuously enhancing the existing security assessment methodologies
- Support in developing marketing and training materials to help develop staff awareness within the company and communicate KPMG's capabilities to clients
- Remain up-to-date on the latest cybersecurity threats, vulnerabilities and regulatory requirements
- Develop constructive client relationships, both inside and outside of KPMG
- Bachelor’s degree in computer science, InformationTechnology, or related field.
- At least one professionally qualification required: CREST, GXPN, GPEN, GCTI, GWAPT, OSCE3, OSEP, OSWE, OSEP, OSCP, CRTE, eCPTX, CISSP, or other relevant qualifications.
- 2 years of relevant working experience preferred: Red/Blue/Purple Teaming, Web/Mobile/Network/OT/IoT/other Penetration Tests, Vulnerability Assessment, Source Code Review, Appliance/System/Cloud Configuration Review, Malware development, Social Engineering.
- Candidate with less experience will be considered as Consultant.
- Knowledge in threat intelligence, reverse engineering, security products, incident response, SOC operation or other related areas will be an advantage.
- Experience with at least one scripting language (e.g. Bash, PowerShell) or programming language (e.g. Python, C, Java) preferred.
- Able to understand basic networking concepts (e.g. routing, ALC, load balancers, SSL/TLS, TCP) is preferred.
- Understand the industry recognised testing standards and have knowledge of common red teaming tools·
- Knowledge base in enterprise technologies and operations, enterprise networking, internet application security, database security evaluation and architecture, with self-motivated learning ability.
- Be able to conduct research and development and solve technical problems independently.
- Be able to work as part of a team, and at the same time being an independent self-starter·
- Have strong analytical, problem solving and inter-personal skills·
- Commands excellent written and oral communication skills with the ability to present ideas and results to technical and non-technical audiences·
- Possess a recognised Degree in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline (STEM) is preferred·
- Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)
KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges. In return, we are helping you to develop your skills and career within the KPMG network.
- Well-structured career development and learning path, 1-to-1 coaching by our cybersecurity professionals
- Access to various cyber security learning resources
- Wide exposure to working with leading financial institutions and corporations
- Continuous sponsorship and support on professional certificate development (i.e. Offensive Security, GIAC, CREST, etc.)
- Opportunities for secondment / exchange within KPMG Global network based on staff performance and preference
- Opportunities to attend KPMG overseas Global Cyber Events – such as HackNet / BlackHat
- One annual professional membership sponsorship on the approved list
- Work in a passionate team with blended cybersecurity talents
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity – and how we make a positive impact on our people, environment and society.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China’s Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement "). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China’s HR personnel in the location where your application is submitted (see here). Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Professional Services
Referrals increase your chances of interviewing at KPMG China by 2x
Sign in to set job alerts for “Senior Java Consultant” roles. Senior Java Backend Developer - Web3 / Fintech / Financial Services (Senior) Staff Engineer - Java (Compliance Platform) Principal/Senior Engineer - Core - Platform Tool (Java) Senior/Staff Java Trading Developer, Liquidity Platform Principal/Senior Java Engineer - Multi-Language & Localization Lead Software Engineer, Java, Order Management System for Equities Trading Senior Engineer - Compliance Platform(Java) Principal/Senior Java Engineer - Defi - Earn Senior Engineer - Java (Exchange Platform - Financial Product) Lead Software Engineer, Electronic Trading Technology, Java Principal/Senior Engineer - Defi - Explorer(Java)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrConsultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Con[...]
Posted 3 days ago
Job Viewed
Job Description
Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ005350) role at KPMG China
Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ005350)Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ005350) role at KPMG China
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.
KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.
Our wide range of projects includes Cyber Strategy, Cyber Digital Transformation, Governance & Risk, as well as a strong presence in Penetration Testing or Ethical Hacking. We are keen to speaking with cyber security specialists with various expertise and experiences to join our growth story.
We are now seeking Consultant/ Senior Consultant candidates for Cyber Defense Team.
Key Responsibilities
- Perform vulnerability assessment and penetration tests on different platforms and technologies
- Simulate real-time cyber-attacks using red team / blue team / purple team exercises
- Conduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware / ransomware
- Conduct source code review to identify software program vulnerabilities and detect malware or malicious embedded code
- Conduct cloud / server / network / middleware security configuration assessments
- Conduct architecture review for cloud / on-premise IT environments
- Prepare reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities
- Assist in continuously enhancing the existing security assessment methodologies
- Support in developing marketing and training materials to help develop staff awareness within the company and communicate KPMG's capabilities to clients
- Remain up-to-date on the latest cybersecurity threats, vulnerabilities and regulatory requirements
- Develop constructive client relationships, both inside and outside of KPMG
- Bachelor’s degree in computer science, InformationTechnology, or related field.
- At least one professionally qualification required: CREST, GXPN, GPEN, GCTI, GWAPT, OSCE3, OSEP, OSWE, OSEP, OSCP, CRTE, eCPTX, CISSP, or other relevant qualifications.
- 2 years of relevant working experience preferred: Red/Blue/Purple Teaming, Web/Mobile/Network/OT/IoT/other Penetration Tests, Vulnerability Assessment, Source Code Review, Appliance/System/Cloud Configuration Review, Malware development, Social Engineering.
- Candidate with less experience will be considered as Consultant.
- Knowledge in threat intelligence, reverse engineering, security products, incident response, SOC operation or other related areas will be an advantage.
- Experience with at least one scripting language (e.g. Bash, PowerShell) or programming language (e.g. Python, C, Java) preferred.
- Able to understand basic networking concepts (e.g. routing, ALC, load balancers, SSL/TLS, TCP) is preferred.
- Understand the industry recognised testing standards and have knowledge of common red teaming tools·
- Knowledge base in enterprise technologies and operations, enterprise networking, internet application security, database security evaluation and architecture, with self-motivated learning ability.
- Be able to conduct research and development and solve technical problems independently.
- Be able to work as part of a team, and at the same time being an independent self-starter·
- Have strong analytical, problem solving and inter-personal skills·
- Commands excellent written and oral communication skills with the ability to present ideas and results to technical and non-technical audiences·
- Possess a recognised Degree in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline (STEM) is preferred·
- Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)
KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges. In return, we are helping you to develop your skills and career within the KPMG network.
- Well-structured career development and learning path, 1-to-1 coaching by our cybersecurity professionals
- Access to various cyber security learning resources
- Wide exposure to working with leading financial institutions and corporations
- Continuous sponsorship and support on professional certificate development (i.e. Offensive Security, GIAC, CREST, etc.)
- Opportunities for secondment / exchange within KPMG Global network based on staff performance and preference
- Opportunities to attend KPMG overseas Global Cyber Events – such as HackNet / BlackHat
- One annual professional membership sponsorship on the approved list
- Work in a passionate team with blended cybersecurity talents
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity – and how we make a positive impact on our people, environment and society.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China’s Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement "). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China’s HR personnel in the location where your application is submitted (see here). Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Professional Services
Referrals increase your chances of interviewing at KPMG China by 2x
Sign in to set job alerts for “Senior Java Consultant” roles. Senior Java Backend Developer - Web3 / Fintech / Financial Services (Senior) Staff Engineer - Java (Compliance Platform) Principal/Senior Engineer - Core - Platform Tool (Java) Senior/Staff Java Trading Developer, Liquidity Platform Principal/Senior Java Engineer - Multi-Language & Localization Lead Software Engineer, Java, Order Management System for Equities Trading Senior Engineer - Compliance Platform(Java) Principal/Senior Java Engineer - Defi - Earn Senior Engineer - Java (Exchange Platform - Financial Product) Lead Software Engineer, Electronic Trading Technology, Java Principal/Senior Engineer - Defi - Explorer(Java)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity Engineer, Product Security
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Security Engineer, Product Security role at Chainlink Labs
Join to apply for the Security Engineer, Product Security role at Chainlink Labs
Get AI-powered advice on this job and more exclusive features.
About Us
Chainlink Labs is the primary contributing developer of Chainlink, the decentralized computing platform powering the verifiable web. Chainlink is the industry-standard platform for providing access to real-world data, offchain computation, and secure cross-chain interoperability across any blockchain. Chainlink Labs helps power verifiable applications for banking, DeFi, global trade, and gaming by collaborating with some of the world’s largest financial institutions, notably Swift, DTCC, and ANZ. Chainlink Labs also works with top Web3 teams, including Aave, Compound, GMX, Maker, and Synthetix. Chainlink Labs was ranked as one of the
About Us
Chainlink Labs is the primary contributing developer of Chainlink, the decentralized computing platform powering the verifiable web. Chainlink is the industry-standard platform for providing access to real-world data, offchain computation, and secure cross-chain interoperability across any blockchain. Chainlink Labs helps power verifiable applications for banking, DeFi, global trade, and gaming by collaborating with some of the world’s largest financial institutions, notably Swift, DTCC, and ANZ. Chainlink Labs also works with top Web3 teams, including Aave, Compound, GMX, Maker, and Synthetix. Chainlink Labs was ranked as one of the Global Top 100 Most Loved Workplaces by Newsweek 2025.
The Security Team
The security department is the guardian of Chainlink Labs’ people and infrastructure. Its principal objective is to safeguard Chainlink Labs and its assets against potential threats from any external or internal source. This mission is accomplished through a combination of specialized security engineering, the deployment of cutting-edge technologies, forward-thinking policy development, and the training of highly skilled, security-aware personnel throughout the entire organization.
As an indispensable component of the larger organization, the team seeks to promote a widely understood culture of security, safeguarding our most valuable assets while remaining agile and accessible to all employees and the community.
About The Role
The Chainlink Labs Product Security team is looking for a driven and passionate Security Engineer to join our rapidly expanding team. You will help design and advise other teams on secure and scalable architectures, assist with their implementation, and develop entirely new and novel systems that protect Chainlink and the Web3 ecosystem. You’ll have the opportunity to help shape and secure the next generation of Web3 products and infrastructure.
What You Will Do
- Build security tools and controls that are deployed across the company
- Design, develop, and deploy new core security features to public Chainlink products like the Chainlink core node
- Define new processes and systems that make attacks on our networks hard to execute and easy to detect
- Immerse yourself in Chainlink’s upcoming engineering and non-engineering projects and ensure security is fundamental to their design and functionality
- Help define, shape, and achieve the company’s broader security goals
- Experience in Go or Rust
- Experience in a security related function
- Experience building security software or securing enterprise systems
- Comfortable with *nix operating systems (including macOS)
- Ability to adapt to fast changing environment and set of technologies
- Experience writing or auditing Solidity
- Experience auditing or securing frontends (React, NPM)
- Strong understanding of cryptography, including concepts such as TLS, FIDO, encryption, and public key cryptography
- Familiarity with security analysis tooling and frameworks
- Enthusiasm for the Ethereum (and other EVM compatible networks) with experience in tooling development, hardware wallets, and deployments
- Experience working on open source software with a GitHub history to prove it
We carefully review all applications and aim to provide a response to every candidate within two weeks after the job posting closes. The closing date is listed on the job advert, so we encourage you to take the time to thoughtfully prepare your application. We want to fully consider your experience and skills, and you will hear from us regarding the status of your application shortly after the closing date.
Commitment to Equal Opportunity
Chainlink Labs is an equal opportunity employer. All qualified applicants will receive equal consideration for employment in compliance with applicable laws, regulations, or ordinances. If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us via this form.
Global Data Privacy Notice for Job Candidates and Applicants
Information collected and processed as part of your Chainlink Labs Careers profile, and any job applications you choose to submit is subject to our Privacy Policy. By submitting your application, you are agreeing to our use and processing of your data as required. Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Information Technology
- Industries Technology, Information and Internet
Referrals increase your chances of interviewing at Chainlink Labs by 2x
Sign in to set job alerts for “Product Security Engineer” roles.We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity Engineer, Product Security
Posted 3 days ago
Job Viewed
Job Description
Join to apply for the Security Engineer, Product Security role at Chainlink Labs
Join to apply for the Security Engineer, Product Security role at Chainlink Labs
Get AI-powered advice on this job and more exclusive features.
About Us
Chainlink Labs is the primary contributing developer of Chainlink, the decentralized computing platform powering the verifiable web. Chainlink is the industry-standard platform for providing access to real-world data, offchain computation, and secure cross-chain interoperability across any blockchain. Chainlink Labs helps power verifiable applications for banking, DeFi, global trade, and gaming by collaborating with some of the world’s largest financial institutions, notably Swift, DTCC, and ANZ. Chainlink Labs also works with top Web3 teams, including Aave, Compound, GMX, Maker, and Synthetix. Chainlink Labs was ranked as one of the
About Us
Chainlink Labs is the primary contributing developer of Chainlink, the decentralized computing platform powering the verifiable web. Chainlink is the industry-standard platform for providing access to real-world data, offchain computation, and secure cross-chain interoperability across any blockchain. Chainlink Labs helps power verifiable applications for banking, DeFi, global trade, and gaming by collaborating with some of the world’s largest financial institutions, notably Swift, DTCC, and ANZ. Chainlink Labs also works with top Web3 teams, including Aave, Compound, GMX, Maker, and Synthetix. Chainlink Labs was ranked as one of the Global Top 100 Most Loved Workplaces by Newsweek 2025.
The Security Team
The security department is the guardian of Chainlink Labs’ people and infrastructure. Its principal objective is to safeguard Chainlink Labs and its assets against potential threats from any external or internal source. This mission is accomplished through a combination of specialized security engineering, the deployment of cutting-edge technologies, forward-thinking policy development, and the training of highly skilled, security-aware personnel throughout the entire organization.
As an indispensable component of the larger organization, the team seeks to promote a widely understood culture of security, safeguarding our most valuable assets while remaining agile and accessible to all employees and the community.
About The Role
The Chainlink Labs Product Security team is looking for a driven and passionate Security Engineer to join our rapidly expanding team. You will help design and advise other teams on secure and scalable architectures, assist with their implementation, and develop entirely new and novel systems that protect Chainlink and the Web3 ecosystem. You’ll have the opportunity to help shape and secure the next generation of Web3 products and infrastructure.
What You Will Do
- Build security tools and controls that are deployed across the company
- Design, develop, and deploy new core security features to public Chainlink products like the Chainlink core node
- Define new processes and systems that make attacks on our networks hard to execute and easy to detect
- Immerse yourself in Chainlink’s upcoming engineering and non-engineering projects and ensure security is fundamental to their design and functionality
- Help define, shape, and achieve the company’s broader security goals
- Experience in Go or Rust
- Experience in a security related function
- Experience building security software or securing enterprise systems
- Comfortable with *nix operating systems (including macOS)
- Ability to adapt to fast changing environment and set of technologies
- Experience writing or auditing Solidity
- Experience auditing or securing frontends (React, NPM)
- Strong understanding of cryptography, including concepts such as TLS, FIDO, encryption, and public key cryptography
- Familiarity with security analysis tooling and frameworks
- Enthusiasm for the Ethereum (and other EVM compatible networks) with experience in tooling development, hardware wallets, and deployments
- Experience working on open source software with a GitHub history to prove it
We carefully review all applications and aim to provide a response to every candidate within two weeks after the job posting closes. The closing date is listed on the job advert, so we encourage you to take the time to thoughtfully prepare your application. We want to fully consider your experience and skills, and you will hear from us regarding the status of your application shortly after the closing date.
Commitment to Equal Opportunity
Chainlink Labs is an equal opportunity employer. All qualified applicants will receive equal consideration for employment in compliance with applicable laws, regulations, or ordinances. If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us via this form.
Global Data Privacy Notice for Job Candidates and Applicants
Information collected and processed as part of your Chainlink Labs Careers profile, and any job applications you choose to submit is subject to our Privacy Policy. By submitting your application, you are agreeing to our use and processing of your data as required. Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Information Technology
- Industries Technology, Information and Internet
Referrals increase your chances of interviewing at Chainlink Labs by 2x
Sign in to set job alerts for “Product Security Engineer” roles.We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrUbuntu Security Engineer
Posted 8 days ago
Job Viewed
Job Description
Join to apply for the Ubuntu Security Engineer role at Canonical
3 days ago Be among the first 25 applicants
Join to apply for the Ubuntu Security Engineer role at Canonical
Get AI-powered advice on this job and more exclusive features.
Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading public cloud and silicon providers, and industry leaders in many sectors. The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries and very few office-based roles. Teams meet two to four times yearly in person, in interesting locations around the world, to align on strategy and execution.
The company is founder-led, profitable, and growing.
Canonical is building a team dedicated to providing security coverage across a wide range of ecosystems and environments, working to make the world a better, safer place. We are hiring an Ubuntu Security Engineer to join an industry-leading security engineering team and help protect the open source community and Ubuntu users from emerging threats. We are looking for candidates across all levels of experience, from Graduate to Senior.
As part of the Ubuntu Security Team, you will work with some of the best and brightest people in technology to monitor, triage, respond to, and document new and existing vulnerabilities in open source software. You will collaborate with internal teams and external partners to identify issues, prioritize them, and coordinate remediation.
This is an engineering-focused role that may also involve activities such as producing security assessments, building features, conducting code reviews, developing internal tools, engaging with the open source community, and participating in industry initiatives and events.
This role requires international travel at least twice a year, usually for one week. It also requires the ability to be productive in a globally distributed team through self-discipline and self-motivation.
Location: Worldwide, this is a globally remote role
The role entails
- Analyzing, fixing, and testing vulnerabilities in open source packages
- Keeping track of vulnerabilities in the Ubuntu ecosystem as they are discovered, researched, and fixed, leveraging internal tools
- Collaborating with other teams in the Ubuntu community and upstream developers, as needed, to exchange or develop vulnerability patches and ensure that Ubuntu includes the most robust security features
- Auditing source code for vulnerabilities
- Building features and tools to help teams strengthen the security of their products and contribute to the overall security of Ubuntu
- You have a thorough understanding of the common categories of security vulnerabilities and techniques for fixing them
- You are familiar with coordinated disclosure practices
- You are familiar with open source development tools and methodologies
- You are skilled in one or more of C, Python, Go, Rust, Java, Ruby, PHP or JavaScript/TypeScript
- You have excellent logic, problem-solving, troubleshooting, and decision-making skills
- You can clearly and effectively communicate with the team and Ubuntu community members
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Appreciative of diversity, polite, and effective in a multi-cultural, multi-national organization
- Thoughtfulness and self-motivation
- Result-oriented, with a personal drive to meet commitments
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognize outstanding performance. In addition to base pay, we offer a performance-driven annual bonus or commission. We provide all team members with additional benefits which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Team Member Assistance Program & Wellness Platform
- Opportunity to travel to new locations to meet colleagues
- Priority Pass and travel upgrades for long-haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open-source projects and the platform for AI, IoT, and the cloud, we are changing the world of software. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence; in order to succeed, we need to be the best at what we do. Most colleagues at Canonical have worked from home since our inception in 2004. Working here is a step into the future and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Get notified about new Security Engineer jobs in Hong Kong SAR .
Software Engineer (Python/Linux/Packaging)Hong Kong SAR $4,800.00-$7,200.00 2 weeks ago
Senior Software Engineer - Crypto Trading Infrastructure Site Reliability Engineer (Crypto Trading) Python and Kubernetes Software Engineer - Data, AI/ML & Analytics Python and Kubernetes Software Engineer - Data, Workflows, AI/ML & Analytics Software Engineer - Solutions EngineeringHong Kong, Hong Kong SAR SGD24,000.00-SGD60,000.00 1 month ago
Embedded Linux Senior Software Engineer - Optimisation Python Software Engineer - Ubuntu Hardware Certification Team Go (Golang) Software Engineer, Developer Tooling and Containers System Software Engineer - Golang compiler, tooling, and ecosystem Software Engineer - Cross-platform C++ - Multipass Golang Software Engineer, Developer Tooling and Containers C++/Rust Graphics and Windowing System Software Engineer - MirWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrBe The First To Know
About the latest Security testing Jobs in Hong Kong !
Ubuntu Security Engineer
Posted 7 days ago
Job Viewed
Job Description
Join to apply for the Ubuntu Security Engineer role at Canonical
3 days ago Be among the first 25 applicants
Join to apply for the Ubuntu Security Engineer role at Canonical
Get AI-powered advice on this job and more exclusive features.
Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading public cloud and silicon providers, and industry leaders in many sectors. The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries and very few office-based roles. Teams meet two to four times yearly in person, in interesting locations around the world, to align on strategy and execution.
The company is founder-led, profitable, and growing.
Canonical is building a team dedicated to providing security coverage across a wide range of ecosystems and environments, working to make the world a better, safer place. We are hiring an Ubuntu Security Engineer to join an industry-leading security engineering team and help protect the open source community and Ubuntu users from emerging threats. We are looking for candidates across all levels of experience, from Graduate to Senior.
As part of the Ubuntu Security Team, you will work with some of the best and brightest people in technology to monitor, triage, respond to, and document new and existing vulnerabilities in open source software. You will collaborate with internal teams and external partners to identify issues, prioritize them, and coordinate remediation.
This is an engineering-focused role that may also involve activities such as producing security assessments, building features, conducting code reviews, developing internal tools, engaging with the open source community, and participating in industry initiatives and events.
This role requires international travel at least twice a year, usually for one week. It also requires the ability to be productive in a globally distributed team through self-discipline and self-motivation.
Location: Worldwide, this is a globally remote role
The role entails
- Analyzing, fixing, and testing vulnerabilities in open source packages
- Keeping track of vulnerabilities in the Ubuntu ecosystem as they are discovered, researched, and fixed, leveraging internal tools
- Collaborating with other teams in the Ubuntu community and upstream developers, as needed, to exchange or develop vulnerability patches and ensure that Ubuntu includes the most robust security features
- Auditing source code for vulnerabilities
- Building features and tools to help teams strengthen the security of their products and contribute to the overall security of Ubuntu
- You have a thorough understanding of the common categories of security vulnerabilities and techniques for fixing them
- You are familiar with coordinated disclosure practices
- You are familiar with open source development tools and methodologies
- You are skilled in one or more of C, Python, Go, Rust, Java, Ruby, PHP or JavaScript/TypeScript
- You have excellent logic, problem-solving, troubleshooting, and decision-making skills
- You can clearly and effectively communicate with the team and Ubuntu community members
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Appreciative of diversity, polite, and effective in a multi-cultural, multi-national organization
- Thoughtfulness and self-motivation
- Result-oriented, with a personal drive to meet commitments
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognize outstanding performance. In addition to base pay, we offer a performance-driven annual bonus or commission. We provide all team members with additional benefits which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Team Member Assistance Program & Wellness Platform
- Opportunity to travel to new locations to meet colleagues
- Priority Pass and travel upgrades for long-haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open-source projects and the platform for AI, IoT, and the cloud, we are changing the world of software. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence; in order to succeed, we need to be the best at what we do. Most colleagues at Canonical have worked from home since our inception in 2004. Working here is a step into the future and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Get notified about new Security Engineer jobs in Hong Kong SAR .
Software Engineer (Python/Linux/Packaging)Hong Kong SAR $4,800.00-$7,200.00 2 weeks ago
Senior Software Engineer - Crypto Trading Infrastructure Site Reliability Engineer (Crypto Trading) Python and Kubernetes Software Engineer - Data, AI/ML & Analytics Python and Kubernetes Software Engineer - Data, Workflows, AI/ML & Analytics Software Engineer - Solutions EngineeringHong Kong, Hong Kong SAR SGD24,000.00-SGD60,000.00 1 month ago
Embedded Linux Senior Software Engineer - Optimisation Python Software Engineer - Ubuntu Hardware Certification Team Go (Golang) Software Engineer, Developer Tooling and Containers System Software Engineer - Golang compiler, tooling, and ecosystem Software Engineer - Cross-platform C++ - Multipass Golang Software Engineer, Developer Tooling and Containers C++/Rust Graphics and Windowing System Software Engineer - MirWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrWeb3 Senior Security Engineer
Posted 10 days ago
Job Viewed
Job Description
We are working with a decentralised exchange which looks to innovate on providing the best of CEXs and DEXs, focusing on building a safe, simple and scalable platform for trading. They differentiate themselves by offering institutional level systems and support whilst remaining on-chain and decentralised.
We are in search of a Security Engineer to join their vibrant team, where you will play a crucial role in pinpointing risks across the organisation. Collaborating with each team, you will focus on identifying, alerting, mitigating, and preventing risks. This role offers you the chance to contribute to shaping, constructing, and pioneering security solutions in a swiftly evolving industry.
What you’ll be doing:
- Architecting, implementing, and managing comprehensive security solutions.
- Establish and enforce security policies, standards, and guidelines that comply with industry regulations and best practices.
- Participate in penetration testing and purple teaming with ongoing or new projects to ensure their security posture is at a high level.
- Monitor and respond to security incidents, ensuring quick resolution.
- Build automation and leverage security frameworks with engineers that are able to improve security and reduce friction.
- Take part in critical discussion topics, with the ability to challenge decisions and the status quo; we take collaboration and feedback seriously, believing it is one of the foundational principles of a great team.
What we’re looking for:
- Strong Information Security (InfoSec) skills, with proven experience in application security or a relevant field.
- Hands-on experience of developing, engineering, or architecting within a public cloud environment.
- Experience with engineering, using infrastructure-as-code (such as Terraform and Ansible).
- Experience with performing threat modelling exercises or a very good understanding of the methodology and ability to assess a project's risk.
- Understanding of container and DevSecOps concepts (we use DefectDojo) with CI/CD experience.
- Familiarity with blockchain technology and cryptocurrency trading platforms.
Bonus Points:
- Professional certifications such as OSCP, CISSP, CDP & CMTP.
- Experience with IT security frameworks such as SOC 2 and ISO 27001.
#LI-REMOTE
Apply for this job*
indicates a required field
First Name *
Last Name *
Email *
Phone *
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
LinkedIn Profile
Website
Working Location *
EMEA - Europe
APAC - Asia Pacific
LATIN - Latin America
UAE
Others
Do you have any Web3 experience? * Select.
Web3 Vertical Experience *
Defi
NFT
Gamefi
Infrastructure
ZK
Exchanges
VC
Chain
DePin
Accelerator
Incubator
Trading
Asset Management
Others
Any personal experience in Web3 (e.g. side project, personal investment) if no professional experience. *
#J-18808-LjbffrWeb3 Senior Security Engineer
Posted 3 days ago
Job Viewed
Job Description
We are working with a decentralised exchange which looks to innovate on providing the best of CEXs and DEXs, focusing on building a safe, simple and scalable platform for trading. They differentiate themselves by offering institutional level systems and support whilst remaining on-chain and decentralised.
We are in search of a Security Engineer to join their vibrant team, where you will play a crucial role in pinpointing risks across the organisation. Collaborating with each team, you will focus on identifying, alerting, mitigating, and preventing risks. This role offers you the chance to contribute to shaping, constructing, and pioneering security solutions in a swiftly evolving industry.
What you’ll be doing:
- Architecting, implementing, and managing comprehensive security solutions.
- Establish and enforce security policies, standards, and guidelines that comply with industry regulations and best practices.
- Participate in penetration testing and purple teaming with ongoing or new projects to ensure their security posture is at a high level.
- Monitor and respond to security incidents, ensuring quick resolution.
- Build automation and leverage security frameworks with engineers that are able to improve security and reduce friction.
- Take part in critical discussion topics, with the ability to challenge decisions and the status quo; we take collaboration and feedback seriously, believing it is one of the foundational principles of a great team.
What we’re looking for:
- Strong Information Security (InfoSec) skills, with proven experience in application security or a relevant field.
- Hands-on experience of developing, engineering, or architecting within a public cloud environment.
- Experience with engineering, using infrastructure-as-code (such as Terraform and Ansible).
- Experience with performing threat modelling exercises or a very good understanding of the methodology and ability to assess a project's risk.
- Understanding of container and DevSecOps concepts (we use DefectDojo) with CI/CD experience.
- Familiarity with blockchain technology and cryptocurrency trading platforms.
Bonus Points:
- Professional certifications such as OSCP, CISSP, CDP & CMTP.
- Experience with IT security frameworks such as SOC 2 and ISO 27001.
#LI-REMOTE
Apply for this job*
indicates a required field
First Name *
Last Name *
Email *
Phone *
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
LinkedIn Profile
Website
Working Location *
EMEA - Europe
APAC - Asia Pacific
LATIN - Latin America
UAE
Others
Do you have any Web3 experience? * Select.
Web3 Vertical Experience *
Defi
NFT
Gamefi
Infrastructure
ZK
Exchanges
VC
Chain
DePin
Accelerator
Incubator
Trading
Asset Management
Others
Any personal experience in Web3 (e.g. side project, personal investment) if no professional experience. *
#J-18808-Ljbffr