Job Overview
Job description
- Location:
- China
- Work arrangement:
- On-site
云安全与 DevSecOps 工程师 / DevSecOps & Cloud Security Engineer at DavionLabs in China.
Responsibilities
Promote the implementation of the "security shift left" strategy, seamlessly integrate automated security detection (SAST/DAST/SCA) into the CI/CD pipeline, and collaborate with the R&D team to achieve full life cycle closed-loop management of security vulnerabilities.
- Lead the security architecture design and daily operation and maintenance of cloud infrastructure. Coordinate and manage core cloud security components and protection strategies such as WAF and IAM to ensure the stable operation of cloud assets and businesses.
- Regularly lead penetration testing and risk assessment of cloud environments, web applications and business links to discover potential logical flaws and deep security vulnerabilities.
- Construct and continuously optimize the security monitoring and alarm matrix of the cloud native environment, efficiently respond to unexpected security incidents, and carry out continuous cloud security situation management (CSPM).
Requirements
Bachelor degree or above (computer, information security and other related majors are preferred), with 3-5 years of practical experience in DevSecOps system implementation or large-scale cloud platform security operation and maintenance.
- Have an in-depth understanding of agile development and CI/CD processes, be proficient in at least one programming language such as Python, Go or Shell, and be able to independently develop security automation scripts and tools.
- Proficient in cloud native architecture, with in-depth understanding of the AWS ecosystem and its core security component configurations, and solid cloud compliance audit and situation management capabilities.
- Have excellent offensive and defensive thinking and practical skills, be familiar with OWASP Top 10 and common web vulnerability principles, and be able to skillfully use mainstream tools in the industry to carry out penetration testing and traffic analysis.
【Extra points】
Have in-depth practical experience in security protection of containerization and cloud-native orchestration systems (Docker, Kubernetes).
- Hold professional security certifications that are highly recognized in the industry (such as AWS Certified Security - Specialty, CISSP, CISA, OSCP, etc.).
- Have experience in building the full-link DevSecOps system of a large Internet enterprise from 0 to 1, or have experience in red-blue confrontation/attack and defense drills in large-scale cloud environments.
About the Company
Davion Labs is now looking for a cloud security and DevSecOps engineer with profound technical background and practical experience to join the ApeX Protocol core team.
ApeX Protocol is a leading decentralized exchange (DEX) platform dedicated to providing users with a smooth, efficient, and secure cryptocurrency trading experience. Focused on innovation and user empowerment, ApeX Protocol aims to redefine the decentralized exchange landscape through its cutting-edge technology and comprehensive product portfolio.
The latest product, ApeX Omni (v2), provides multi-chain liquidity, flexible and user-centric design, and top-level security based on zero-knowledge proofs, allowing all users to enjoy a safer and more efficient trading experience.
As a cloud security and DevSecOps engineer, you will be deeply involved in the full life cycle security construction of the underlying infrastructure and R&D pipeline of the ApeX protocol. From the security defense design of cloud native architecture, automated security tool chain integration of CI/CD processes (such as SAST/DAST/SCA), to penetration drills and daily security operations in cloud environments, you will be responsible for continuously optimizing the security baseline of the system. We look forward to your professional defense-in-depth concept and close collaboration with the R&D team to promote "security left shift" and provide solid and reliable infrastructure guarantees for the cloud architecture that supports large-scale on-chain assets.
- Role:
- 云安全与 DevSecOps 工程师 / DevSecOps & Cloud Security Engineer
- Job Type:
- Full Time