We are seeking a Product Security Engineer / Security Architect to partner closely with software engineering and infrastructure teams to embed security throughout the software development lifecycle (SDLC). This position reports directly to the Head of Security in APAC and focuses on secure-by-design principles, threat modeling, security code reviews, and architecture reviews rather than offensive penetration testing.
This role is based in Hong Kong. Comprehensive relocation support and benefits will be provided for qualifying candidates.
Key Responsibilities:
- Product Security & Architecture Review: Partner with software engineering teams to evaluate system designs, review application architecture, and integrate secure-by-design principles into core trading systems and platforms.
- Secure Software Development & Code Review: Conduct security code reviews across core languages (Python, C++, Rust, Go, Java) to identify vulnerabilities, promote secure coding practices, and guide developers on remediation.
- Threat Modeling & Risk Assessment: Perform threat modeling, risk assessments, and vulnerability analysis across business applications, hybrid cloud services, and infrastructure.
- DevSecOps & Security Tooling: Assist with integrating, managing, and automating security testing tools—including SAST, DAST, dependency scanning, and secret detection—within CI/CD pipelines and developer workflows.
- Security Control Implementation: Support the implementation and operation of security controls across cloud environments (AWS/Azure) and operating systems (Linux/Windows).
- Vendor & Third-Party Risk: Conduct security assessments of third-party vendors and external software components to ensure alignment with internal security baselines.
- Advisory & Collaboration: Act as a trusted security partner for engineering and infrastructure teams, providing technical security guidance and fostering a strong security culture.
Qualifications & Requirements:
- 5–10 years of hands-on experience in Product Security, Application Security, Software Engineering, or Security Architecture.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related technical discipline.
- Strong code literacy with hands-on development or code review experience in at least one key language: Python, C++, Rust, Go, or Java/Kotlin.
- Proven experience in threat modeling methodologies, application vulnerability assessment, and architectural reviews (moving away from purely offensive pen testing).
- Hands-on familiarity securing Linux/Windows environments and practical experience with AWS and/or Microsoft Azure (ideally in hybrid cloud setups).
- Practical experience embedding automated security scanning (SAST/DAST/SCA) into modern CI/CD pipelines.
- Previous exposure to low-latency, performance-sensitive systems, financial services, or quantitative trading environments is highly desirable.
- Excellent problem-solving abilities, clear technical communication skills, and a collaborative, pragmatic approach to security engineering.