Senior Security Engineer

2 days ago


Hong Kong Island, Hong Kong SAR China Grvt Full time

Overview Be among the first 25 applicants. You will join the GRVT Site Reliability Engineering (SRE) team, which operates across three tightly integrated verticals: DevSecOps (cloud infrastructure, incident response, platform stability) Test Engineering (end-to-end testing, regression pipelines, feature assurance) Security Engineering (penetration testing, security advisory, security governance) The organization has the mandate of ensuring the end-to-end reliability of the GRVT platform, protecting our product’s reliability, correctness, and security. This role is positioned within the Security vertical but works cross-functionally with the entire organization. Key Responsibilities Lead technical assurance activities across projects, including penetration testing, purple teaming, threat modeling, and architecture reviews—ensuring both new and existing systems maintain a high security baseline. Serve as the primary security expert within the SRE team, collaborating closely with Ops and QA Engineers and Wider Teams to design practical, high-impact controls that enhance platform security without compromising delivery velocity. Build automation and internal tooling for security visibility, posture monitoring, and enforcement (e.g., secret scanning, anomaly detection, automated test harnesses). Monitor, triage, and lead response efforts for security incidents, coordinating across SRE and wider engineering teams. Establish and maintain security policies and controls aligned with both engineering best practices and regulatory obligations. Educate and empower developers and engineers with actionable guidance, secure coding practices, and feedback cycles—reducing the likelihood of vulnerabilities during development. Experience & Skills Requirements Strong Information Security (InfoSec) background (5+ years), with proven experience in application security across both traditional web stacks and blockchain-based systems. Expert knowledge of web application security, including deep familiarity with the OWASP Top 10, to assess and defend GRVT’s off-chain services against common web-based threats. Python proficiency—experience building security engineering tools such as automated API security testers, custom static analyzers, or CI/CD-integrated scanners for secrets, misconfigurations, and insecure patterns. Proficiency in security testing tools, such as SAST (e.g., SonarQube, Checkmarx, GoSec) and DAST (e.g., OWASP ZAP, Burp Suite). Demonstrated ability to quickly understand and analyze unfamiliar codebases, enabling effective secure code review across diverse systems—including web services, infrastructure components, and smart contracts. Experience conducting threat modelling exercises, or a strong grasp of threat modeling methodologies to evaluate project risk at the design and implementation levels. Smart contract auditing experience, with familiarity in identifying common vulnerabilities in decentralized applications and blockchain systems. Bug bounty programs experience, either as a seasoned researcher or by managing an organization’s program. Experience with cloud infrastructure (e.g., AWS, GCP). Understanding of container security and DevSecOps principles, with practical experience integrating security into CI/CD pipelines. Bonus Points Familiarity with IT security frameworks such as SOC 2 and ISO 27001, and how to align technical controls to compliance objectives. Holds or actively pursues professional certifications such as OSCP, OSWE, CISSP, CDP, or CTMP. Seniority level Mid-Senior level Employment type Full-time Job function Information Technology Referrals increase your chances of interviewing at Grvt by 2x. Get notified about new Senior Security Engineer jobs in Hong Kong, Hong Kong SAR . Smart Contract Security Engineer (Security Audit) Blockchain Security Engineer (Smart Contract Auditing) Binance Accelerator Program - Security Data Analyst We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI. #J-18808-Ljbffr



  • Hong Kong Island, Hong Kong SAR China BluOcean Security Pte Ltd Full time

    A leading security solutions provider in Hong Kong is seeking a Senior Technical Engineer with at least 2 years of experience in systems engineering. The role involves maintaining and optimizing security systems, executing planned preventative maintenance, and supporting investigations into system failures. Candidates should have extensive knowledge of...


  • Hong Kong Island, Hong Kong SAR China BluOcean Security Pte Ltd Full time

    1. Be proactive in ensuring the security systems are operating optimally. 2. Undertake planned and reactive services to the ’s security systems. The schedule will be agreed at the beginning of each year. 3. Undertake Planned Preventative Maintenance (PPMs) across the Estate covering all assets and systems assigned to them. 4. PPMs are to be completed to an...


  • Hong Kong Island, Hong Kong SAR China EXIO (HK) LIMITED Full time

    The Senior Security Engineer will lead the implementation and optimization of security solutions across EXIO’s crypto exchange platform. This role focuses on advanced security operations, including Data Loss Prevention (DLP) , Identity and Access Management (IAM) , and Security Information and Event Management (SIEM) , while mentoring junior team members...


  • Hong Kong Island, Hong Kong SAR China Senior Platform EngineerSquad Lead, Kafka Full time

    Senior Platform Engineer/Squad Lead, Kafka Senior Platform Engineer/Squad Lead, Kafka View all jobs Add expected salary to your profile for insights Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create. Why Mox Everything at Mox – from our...


  • Hong Kong Island, Hong Kong SAR China Acton Consulting Limited Full time

    ( Senior ) Security Engineer / Security Analyst Our client is a leading solution provider. Due to the rapid growth of the company, they are now looking for talented individuals to join the professional team. About the Role Handle customer security incident email/phone enquiries (2nd Tier) Provide 2nd tier support and guide engineer on UTM, IDS, IPS, WAF...


  • Hong Kong Island, Hong Kong SAR China Crypto.com Full time

    (Senior) Security Engineer, Security Engineering & Threat Intelligence We are looking for an intermediate level security engineer to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI driven security automation workflows and...


  • Hong Kong Island, Hong Kong SAR China Second Talent Full time

    A leading international law firm with a strong Asia‑Pacific presence is looking for an experienced Information Security Engineer to join its regional IT Security team in Hong Kong. Senior Information Security Engineer – Global Law Firm (Hong Kong) A leading international law firm with a strong Asia‑Pacific presence is looking for an experienced...


  • Hong Kong Island, Hong Kong SAR China Grvt Full time

    A technology-focused company located in Hong Kong is seeking a Mid-Senior level Security Engineer. The ideal candidate will lead technical assurance activities and work cross-functionally to enhance security controls. With strong Information Security experience of over 5 years, expertise in web application security, and proficiency in Python, candidates will...


  • Hong Kong Island, Hong Kong SAR China Qube Research & Technologies Full time

    A global quantitative investment firm is seeking a Senior Product Security Engineer to safeguard its trading infrastructure. The role emphasizes implementing security controls and collaborating with engineering and product teams throughout all stages of development. Applicants should possess 5-10 years of experience in product security, exhibit a deep...


  • Hong Kong Island, Hong Kong SAR China Qube Research & Technologies Full time

    Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology and data driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to...