Senior Offensive Security Specialist
1 week ago
Senior Offensive Security Specialist - Supply Chain About Bullish Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include: Bullish Exchange - a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high-performance central limit order book matching engine with automated market making to provide deep and predictable liquidity. Bullish Exchange is regulated in Germany, Hong Kong, and Gibraltar. CoinDesk Indices - a collection of tradable proprietary and single-asset benchmarks and indices that track the performance of digital assets for global institutions in the digital assets and traditional finance industries. CoinDesk Data - a broad suite of digital assets market data and analytics, providing real-time insights into prices, trends, and market dynamics. CoinDesk Insights - a digital asset media and events provider and operator of Coindesk.com, a digital media platform that covers news and insights about digital assets, the underlying markets, policy, and blockchain technology. Reports to: Director, Offensive Security and Vulnerability Management The Cybersecurity Team requires a new team member specializing in supply chain security to support strategic objectives focusing on 3rd party risk and compliance requirements. The position will focus on identifying risks in 3rd party products (software, SaaS services, etc.), maintaining Bullish and supplier software bill of materials (SBOMs), performing configuration reviews of services, and working with 3rd party vendors to document and manage emerging risks. This position will also focus on securing the Bullish product supply chain, helping to secure Bullish source code and our build and deployment toolchains. Role & Responsibilities Develop an industry leading supply chain security program focused on the detection, prevention and remediation of threats in the Bullish supply chain Design and execute comprehensive, continuous security assessments (including code reviews, design reviews, and secure configuration reviews ) across all third-party software products and Bullish's internal build/deploy toolchain to manage transitive risk Implement guidelines and processes to facilitate the secure selection, procurement, and implementation of third-party services Perform risk assessments and work with operations teams to strengthen the Bullish build and deploy technology stack Develop automation around SBOM generation, maintenance, and the risk-prioritized triage/remediation of identified vulnerabilities Manage key offensive security tooling, including static analysis, software composition analysis, SBOM management, and Javascript analysis solutions. This includes the triage and management of any detected security weaknesses Assist with the orchestration of external penetration tests, when needed Stay updated with emerging supply chain security threats and industry trends to further grow the program Experience & Qualifications 5+ years experience in cybersecurity. Preferably in Application Security, Penetration Testing, or Cloud Security Engineering Operational DevOps experience (JIRA backlog management, ticket assignment, sprint management, etc.) Ability to read and understand code. Prefer basic level of knowledge in JavaScript, C++, Rust, Go, Python, and Java Must be comfortable writing code. Many tasks will require automation or custom coding Experience using AI/LLM to assist with performing tasks and development Hands-on experience in common DevOps/SecOps/DevSecOps and CI/CD technologies Self-starts. Autonomous and self-directed. Need someone that can operate with minimal oversight Basic understanding of Security frameworks such as ISO27001 and NIST CSF Bachelors of Computer Science degree, or equivalent, depending on experience Bullish is proud to be an equal opportunity employer. We are fast evolving and striving towards being a globally-diverse community. With integrity at our core, our success is driven by a talented team of individuals and the different perspectives they are encouraged to bring to work every day. #J-18808-Ljbffr
-
Senior Offensive Security Specialist
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeJoin to apply for the Senior Offensive Security Specialist role at Bullish About the Company Bullish is a global digital asset platform focused on providing market infrastructure and information services. Services include the regulated Bullish Exchange for spot and derivatives trading, CoinDesk Indices for benchmark tracking, CoinDesk Data for...
-
Senior Offensive Security Specialist
2 weeks ago
hong kong, Hong Kong SAR China Bullish Full timeBe among the first 25 applicants The Bullish Offensive Security and Vulnerability Management (OSVM) team provides Bullish Global with the capabilities to ensure that our products and services are secure and meet the security obligations expected by our customers and regulators. The OSVM team helps to secure all of Bullish Global, which includes the Bullish...
-
Senior Offensive Security Specialist
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeAbout Bullish Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include: Bullish Exchange – a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high‑performance central‑limit order book matching engine with automated...
-
Senior Offensive Security Engineer
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeA global digital asset platform in Hong Kong is seeking a Senior Offensive Security Specialist to join its security team. You will be responsible for performing penetration testing, conducting vulnerability assessments, and ensuring the security of their products. Ideal candidates will have over 5 years of cybersecurity experience, familiarity with security...
-
Senior Offensive Security Engineer
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeA digital asset platform in Hong Kong is seeking a Senior Offensive Security Specialist to ensure security across its products. The role involves conducting penetration testing, building custom tools, and collaborating with engineering teams. Candidates should have over 5 years of experience in cybersecurity with strong skills in application security...
-
Hong Kong Island, Hong Kong SAR China Bullish Full timeA global digital asset platform is seeking a Senior Offensive Security Specialist to enhance its supply chain security program. The role demands over five years of cybersecurity experience, including work in application security and penetration testing. Candidates should possess coding skills and operational awareness of DevOps, alongside the ability to...
-
Cyber Security Specialist
4 days ago
Hong Kong Island, Hong Kong SAR China Mox Bank Full timeCyber Security Specialist (Penetration Testing) 2 days ago Be among the first 25 applicants About Mox Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile eXperience; Money eXperience; Money X (multiplier), eXponential growth,...
-
Senior Penetration Tester: Web, Mobile
4 days ago
Hong Kong Island, Hong Kong SAR China Mox Bank Full timeA leading digital bank in Hong Kong is seeking a Cyber Security Specialist focused on penetration testing to join its dynamic team. This role involves providing security expertise, conducting testing and assessments, and managing vulnerabilities while collaborating closely with development and operations teams. The ideal candidate will have 5+ years of IT...
-
Cyber Security Operation Specialist
2 weeks ago
Hong Kong Island, Hong Kong SAR China PFCC Group Full timeCyber Security Operation Specialist (Leading Digital Bank) Join a fast-growing digital bank that's transforming the future of banking in Hong Kong. Our client blends innovation, technology, and customer insight to deliver secure, user-centric financial solutions. As a Cyber Security Operations Specialist, you'll be part of a mission‑driven team where...
-
SOC Security
2 weeks ago
Hong Kong Island, Hong Kong SAR China Securitas Security Services (Hong Kong) Limited Full timeA leading global media company in Hong Kong seeks a Security Specialist to ensure the security of its operations. Responsibilities include analyzing global events, managing the electronic security system, and maintaining accurate event logs. The ideal candidate has tertiary education with experience in mass media or security services and should have a good...