Senior Offensive Security Specialist
7 days ago
About Bullish Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include: Bullish Exchange – a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high‑performance central‑limit order book matching engine with automated market making to provide deep and predictable liquidity. Bullish Exchange is regulated in Germany, Hong Kong, and Gibraltar. CoinDesk Indices – a collection of tradable proprietary and single‑asset benchmarks and indices that track the performance of digital assets for global institutions in the digital assets and traditional finance industries. CoinDesk Data – a broad suite of digital assets market data and analytics, providing real‑time insights into prices, trends, and market dynamics. CoinDesk Insights – a digital asset media and events provider and operator of Coindesk.com, a digital media platform that covers news and insights about digital assets, the underlying markets, policy, and blockchain technology. Reports to Director, Offensive Security and Vulnerability Management The Bullish Offensive Security and Vulnerability Management (OSVM) team provides Bullish Global with the capabilities to ensure that our products and services are secure and meet the security obligations expected by our customers and regulators. The OSVM team helps to secure all of Bullish Global, which includes the Bullish Exchange, CoinDesk, and CCData. The OSVM team regularly performs manual security assessments and penetration testing across a variety of technologies, source code reviews, vulnerability remediation support, automated security testing, security tool development, and red‑teaming. We are seeking a Senior Offensive Security Specialist to join our Offensive Security team to help secure Bullish Global. In this exciting role, you will be a key player within an elite security team delivering industry‑leading crypto services. This role will work closely with product and engineering teams to deliver secure software. This work will include delivering a wide range of security capabilities across a modern technology stack. This role will also work closely with developers to diagnose, document, and remediate application security vulnerabilities. The ideal candidate will be a mix of hacker, programmer and security enthusiast who has a special passion for the unique promise and challenge of a dynamic environment working with a variety of products and teams. Responsibilities Perform web application penetration testing, source code reviews, and/or network penetration testing. Perform mobile and API penetration testing. Support project tasks and deadlines for engineering teams spanning multiple time zones. Create unique tools to assist in scaling the security program. Exploit vulnerabilities found in product systems and clearly communicate complex vulnerabilities to both technical and non‑technical staff. Create detailed technical reports explaining technicaland business risk of the vulnerabilities found to include actionable recommendations/considerations. Provide technical leadership/mentorship to the security and engineering teams. Write new tools and automation. Reverse engineering. Other duties as assigned. Required skills and experience 5+ years of relevant experience in cyber security. Experience in performing senior‑level penetration testing and application security assessments, conducting design code reviews, applying offensive security methodologies, and demonstrating high ethical standards. Familiarity with attack tools such as Burp Suite, Nessus, Kali Linux, and similar tools. Knowledge of common attacks and vulnerabilities including OWASP Top 10 and SANS CWE 25. Exposure to and understanding of various security assessment activities including mobile application assessments (iOS and Android), web services API assessments (REST, GraphQL, and Message Queues), and hardware/embedded systems. Basic proficiency in multiple mainstream programming languages such as C/C++, Java, JavaScript, Python, or Go. Ability to effectively assess risks and severity and communicate vulnerability impact to management and engineering teams. Solid understanding of network and protocol basics including IP, DNS, HTTP, and SSL/TLS. Familiarity with basic cryptographic concepts including PKI, cryptographic algorithms, and application of cryptography for encryption at rest and in motion. Solid understanding and experience with software development practices across larger organizations, Agile fundamentals, CI/CD tools, and familiarity with scanning and intelligence tools, including vulnerability management, SAST, DAST, OSA, and API traceability. Experience with public cloud concepts, architectures, and tools (AWS, Azure, and/or GCP). Proficiency with basic Linux systems privilege and permission models, admin and operational concepts, and basic scripting. Holder of application security and penetration testing certifications such as OSCP, OSCE, or OSWE; other information and cyber security certifications. In‑house and third‑party penetration testing experience. Bonus Strong self‑starter who has the ability to operate independently. Possess restlessness and desire to break into things. Developed communication skills with ability to deliver concepts effectively to non‑technical audiences, including senior leadership; proficiency in preparing presentations, analytical reports, and documents regarding program operational status, achievements and performance. Experience of external communications including papers and conference presentations. Bullish is proud to be an equal opportunity employer. We are fast evolving and striving towards being a globally diverse community. With integrity at our core, our success is driven by a talented team of individuals and the different perspectives they are encouraged to bring to work every day. #J-18808-Ljbffr
-
Senior Offensive Security Specialist
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeJoin to apply for the Senior Offensive Security Specialist role at Bullish About the Company Bullish is a global digital asset platform focused on providing market infrastructure and information services. Services include the regulated Bullish Exchange for spot and derivatives trading, CoinDesk Indices for benchmark tracking, CoinDesk Data for...
-
Senior Offensive Security Specialist
2 weeks ago
hong kong, Hong Kong SAR China Bullish Full timeBe among the first 25 applicants The Bullish Offensive Security and Vulnerability Management (OSVM) team provides Bullish Global with the capabilities to ensure that our products and services are secure and meet the security obligations expected by our customers and regulators. The OSVM team helps to secure all of Bullish Global, which includes the Bullish...
-
Senior Offensive Security Engineer
7 days ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeA global digital asset platform in Hong Kong is seeking a Senior Offensive Security Specialist to join its security team. You will be responsible for performing penetration testing, conducting vulnerability assessments, and ensuring the security of their products. Ideal candidates will have over 5 years of cybersecurity experience, familiarity with security...
-
Senior Offensive Security Engineer
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeA digital asset platform in Hong Kong is seeking a Senior Offensive Security Specialist to ensure security across its products. The role involves conducting penetration testing, building custom tools, and collaborating with engineering teams. Candidates should have over 5 years of experience in cybersecurity with strong skills in application security...
-
Hong Kong Island, Hong Kong SAR China Bullish Full timeA global digital asset platform is seeking a Senior Offensive Security Specialist to enhance its supply chain security program. The role demands over five years of cybersecurity experience, including work in application security and penetration testing. Candidates should possess coding skills and operational awareness of DevOps, alongside the ability to...
-
Senior Offensive Security Specialist
1 week ago
Hong Kong Island, Hong Kong SAR China Bullish Full timeSenior Offensive Security Specialist - Supply Chain About Bullish Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include: Bullish Exchange - a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high-performance central limit...
-
Cyber Security Specialist
4 days ago
Hong Kong Island, Hong Kong SAR China Mox Bank Full timeCyber Security Specialist (Penetration Testing) 2 days ago Be among the first 25 applicants About Mox Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create, - Mobile eXperience; Money eXperience; Money X (multiplier), eXponential growth,...
-
Senior Penetration Tester: Web, Mobile
4 days ago
Hong Kong Island, Hong Kong SAR China Mox Bank Full timeA leading digital bank in Hong Kong is seeking a Cyber Security Specialist focused on penetration testing to join its dynamic team. This role involves providing security expertise, conducting testing and assessments, and managing vulnerabilities while collaborating closely with development and operations teams. The ideal candidate will have 5+ years of IT...
-
Cyber Security Operation Specialist
2 weeks ago
Hong Kong Island, Hong Kong SAR China PFCC Group Full timeCyber Security Operation Specialist (Leading Digital Bank) Join a fast-growing digital bank that's transforming the future of banking in Hong Kong. Our client blends innovation, technology, and customer insight to deliver secure, user-centric financial solutions. As a Cyber Security Operations Specialist, you'll be part of a mission‑driven team where...
-
SOC Security
2 weeks ago
Hong Kong Island, Hong Kong SAR China Securitas Security Services (Hong Kong) Limited Full timeA leading global media company in Hong Kong seeks a Security Specialist to ensure the security of its operations. Responsibilities include analyzing global events, managing the electronic security system, and maintaining accurate event logs. The ideal candidate has tertiary education with experience in mass media or security services and should have a good...