Senior Offensive Security Specialist

2 days ago


hong kong, Hong Kong SAR China Bullish Full time

Be among the first 25 applicants The Bullish Offensive Security and Vulnerability Management (OSVM) team provides Bullish Global with the capabilities to ensure that our products and services are secure and meet the security obligations expected by our customers and regulators. The OSVM team helps to secure all of Bullish Global, which includes the Bullish Exchange, CoinDesk, and CCData. The OSVM team regularly performs manual security assessments and penetration testing across a variety of technologies, source code reviews, vulnerability remediation support, automated security testing, security tool development, and red‑teaming. We are seeking a Senior Offensive Security Specialist to join our Offensive Security team to help secure Bullish Global. In this exciting role, you will be a key player within an elite security team delivering industry‑leading Crypto services. This role will work closely with product and engineering teams to deliver secure software. This work will include delivering a wide range of security capabilities across a modern technology stack. This role will also work closely with developers to diagnose, document, and remediate application security vulnerabilities. The ideal candidate will be a mix of hacker, programmer, and security enthusiast who has a special passion for the unique promise and challenge of a dynamic environment working with a variety of products and teams. Responsibilities Perform mobile and API penetration testing. Support project tasks and deadlines for engineering teams spanning multiple time zones. Create unique tools to assist in scaling the security program. Exploit vulnerabilities found in product systems and clearly communicate complex vulnerabilities to both technical and non‑technical staff. Create detailed technical reports explaining technical and business risk of the vulnerabilities found to include actionable recommendations/considerations. Provide technical leadership/mentorship to the security and engineering teams. Writing new tools and automation. Other duties as assigned. Required skills and experience 5+ years of relevant experience in cyber security. Bachelor’s Degree in Computer Science or related field. Experience in performing senior‑level penetration testing and application security assessments, conducting design code reviews, applying offensive security methodologies, and demonstrating high ethical standards. Familiarity with attack tools such as Burp Suite, Nessus, Kali Linux and similar tools. Knowledge of common attacks and vulnerabilities including OWASP Top 10 and SANS CWE 25. Exposure to and understanding of various security assessment activities including Mobile application assessments (iOS and Android), web Services API assessments (examples: REST, GraphQL and Message Queues), and hardware/embedded systems. Ability to effectively assess risks and severity and communicate vulnerability impact to management and engineering teams. Solid understanding of network and protocol basics including IP, DNS, HTTP and SSL/TLS. Familiarity with basic cryptographic concepts including PKI, cryptographic algorithms, application of cryptography for encryption at rest and in motion. Solid understanding and experience with software development practices across larger organizations, Agile fundamentals, Continuous Integration/Testing/Delivery tools and techniques, and familiarity with scanning and intelligence tools, including Vulnerability Management, SAST, DAST, OSA, and API traceability. Experience with public cloud concepts, architectures and tools (AWS, Azure and/or GCP). Proficiency with basic Linux systems privilege and permission models, admin and operational concepts, and basic scripting. Holder of Application Security and Penetration Testing certifications such as OSCP, OSCE or OSWE; other Information and Cyber Security certifications Inhouse and third party penetration testing experience. Bonus Strong self‑starter who has the ability to operate independently. Possess restlessness and desire to break into things. Developed communications skills with ability to deliver concepts effectively to non‑technical audience including senior leadership; proficiency in preparation of presentations, analytical reports, and documents regarding program operational status, achievement and performance. Experience of external communications including papers and conference presentations. Seniority level Mid‑Senior level Employment type Full‑time Job function Information Technology #J-18808-Ljbffr



  • Hong Kong Island, Hong Kong SAR China Cyber Security Operations Specialist Full time

    Mox is built by and for the ones who aspire to live life to the fullest – we call them Generation Mox! The name Mox reflects the endless opportunities we can create. Why Mox Everything at Mox – from our products, features, to rewards – is designed based on customer research, tailor made for your needs. We care about what customers care about,...


  • Hong Kong Island, Hong Kong SAR China Rise Associates Asia Limited Full time

    IT Security Specialist (Application Security/ Offensive Security) To cope with the strengthening of IT security capability against Insurance Authority’s requirements, this insurance company is looking for candidates with Application Security OR Vulnerability Scan for Application OR DevSecOps experiences to join on a 12-month renewable contract basis....


  • hong kong, Hong Kong SAR China Bullish Full time

    Offensive Security Specialist - Supply Chain - Senior 1 week ago Be among the first 25 applicants The Cybersecurity Team requires a new team member specializing in supply chain security to support strategic objectives focusing on 3rd party risk and compliance requirements. The position will focus on identifying risks in 3rd party products (software, SaaS...


  • hong kong, Hong Kong SAR China Bullish Full time

    A leading technology company seeks an Offensive Security Specialist to enhance supply chain security. Responsibilities include developing security programs, conducting risk assessments, and performing automated tasks. Ideal candidates will have over 5 years of experience in cybersecurity and a background at a mid-senior level. This full-time role is based in...

  • Cyber Defense

    6 days ago


    Hong Kong Island, Hong Kong SAR China Cyber Security Operations Specialist Full time

    A financial technology firm is seeking a Cyber Security Operations Specialist to design and implement cyber security solutions, manage incident responses, and enhance Threat Intelligence platforms. The suitable candidate will have experience in cyber security technologies, an understanding of the threat landscape, and the ability to work collaboratively with...


  • Hong Kong Island, Hong Kong SAR China Rise Associates Asia Limited Full time

    A Hong Kong-based insurance company is seeking an IT Security Specialist to enhance its security capabilities. The role involves leading application security initiatives, defining secure coding standards, and managing vulnerability assessments. Candidates should have a tertiary degree, experience in application security and vulnerability management, and be...

  • SOC Security

    2 days ago


    Hong Kong Island, Hong Kong SAR China Securitas Security Services (Hong Kong) Limited Full time

    A leading global media company in Hong Kong seeks a Security Specialist to ensure the security of its operations. Responsibilities include analyzing global events, managing the electronic security system, and maintaining accurate event logs. The ideal candidate has tertiary education with experience in mass media or security services and should have a good...

  • Security Engineer

    7 days ago


    Hong Kong, Hong Kong SAR China Meliora Full time

    Our client is a Tier-1 leader in the High-Frequency Trading (HFT) industry , and they are seeking an exceptional Offensive Security Engineer to join their elite team. What We’re Looking For Proven offensive security expertise with the ability to deep dive into technical solutions. Strong experience in threat modeling and proactive security assessments....


  • Hong Kong Island, Hong Kong SAR China PFCC Group Full time

    Cyber Security Operation Specialist (Leading Digital Bank) Join a fast-growing digital bank that's transforming the future of banking in Hong Kong. Our client blends innovation, technology, and customer insight to deliver secure, user-centric financial solutions. As a Cyber Security Operations Specialist, you'll be part of a mission‑driven team where...


  • hong kong, Hong Kong SAR China InfoTech Services (Hong Kong) Limited Full time

    A financial institution in Hong Kong is seeking a Senior Specialist / Specialist I in Cyber Security. This permanent role requires enhancing system and network infrastructure to implement cyber security initiatives. Candidates should have a university degree and a minimum of 7 years’ experience in network security. Responsibilities include coordinating...