Deskripsi Pekerjaan
Join the Global Monetization Platform Trust (GMPT) Security BP Team, a critical group dedicated to safeguarding ByteDance's most valuable revenue streams. As an Application Security Engineer, you will play a pivotal role in securing the complex ecosystem of billing, payments, and advertising platforms that drive our business globally. Our mission is to integrate security into every layer of the software development lifecycle, ensuring that our users' data and financial transactions remain uncompromised.
In this role, you will cover a broad spectrum of security domains, including application security, cloud security, data protection, account management, and the emerging frontier of Large Language Model (LLM) security. You will collaborate closely with engineering, product, and business teams to identify risks, design resilient architectures, and implement robust defense mechanisms. If you are a proactive security professional looking to make a high-impact contribution to a tech giant, we encourage you to apply.
Tanggung Jawab
- Threat Modeling & Risk Assessment: Lead threat modeling sessions and conduct comprehensive risk assessments for GMPT services, cloud infrastructure, and AI/ML models.
- Vulnerability Management: Perform regular penetration testing, code reviews, and automated vulnerability scanning to identify and remediate security flaws before deployment.
- Cloud Security: Design and enforce security controls for cloud environments (AWS/Azure), ensuring compliance with best practices and regulatory standards.
- Secure Development Lifecycle (SDLC): Promote secure coding practices, review pull requests, and provide guidance to developers on mitigating common vulnerabilities (e.g., OWASP Top 10).
- Security Operations: Monitor security alerts, respond to incidents, and analyze logs to detect and mitigate potential threats in real-time.
- LLM Security: Collaborate with AI researchers to secure Large Language Models against prompt injection, data poisoning, and adversarial attacks.
- Compliance & Audits: Support external and internal security audits, ensuring adherence to global privacy and data protection regulations.
Kualifikasi
- Experience: 3+ years of experience in Application Security, Penetration Testing, or a Software Engineering role with a strong security focus.
- Education: Bachelor’s degree in Computer Science, Information Security, or a related technical field.
- Technical Skills: Proficiency in scripting languages such as Python, Go, Java, or C++. Experience with security tools (Burp Suite, OWASP ZAP, SonarQube).
- Cloud Expertise: Deep understanding of cloud security principles and experience working with AWS or Azure.
- Certifications: Relevant security certifications (e.g., CISSP, OSCP, CEH) are a plus.
- Communication: Strong ability to communicate complex security concepts to non-technical stakeholders and engineering teams.
- AI/ML Awareness: Interest or experience in AI/ML security and data privacy is highly desirable.