About Us
- Conduct manual code security audits on business code (Java, Golang, JS, C++, etc.) and write audit reports.
- Track domestic and international security developments; analyze and reproduce the latest security vulnerabilities.
- Deeply understand and master the company's product business; identify security risks in business architecture, business processes, and business logic; provide corresponding security solutions and drive their implementation.
- Drive security solution implementation, risk governance, etc.
- Associate degree or above; requirements may be relaxed for candidates with strong capabilities.
- At least 3+ years of business development or audit experience based on Java or Go; has led or participated in SDL (Security Development Lifecycle) implementation.
- Proficient in the underlying principles, discovery methods, vulnerable code scenarios, and exploitation techniques of common security vulnerabilities (not limited to OWASP Top 10).
- Expert-level proficiency in Java and/or Go tech stacks; understands language-specific characteristics and common mainstream development frameworks, with relevant code audit experience.
- Familiar with common white-box audit methodologies, with the ability to track and reproduce the latest vulnerabilities.
- Familiar with mainstream development frameworks such as SpringMVC, SSM, or Gin, GoZero, etc.
- Has a solid understanding of penetration testing; proficient in common penetration testing methods and familiar with the principles and exploitation techniques of common vulnerabilities.
- Able to proficiently use AI tools to enhance security work efficiency.
- Highly proactive with strong logical thinking; possesses good communication, coordination, organizational skills, and documentation writing ability.
- Experience with TEE (Trusted Execution Environment) and other security encryption, data protection technical architectures and solution implementation is preferred.
- Has submitted high-quality vulnerabilities to domestic or international SRC/bug bounty platforms.
- Has discovered CVE or CNVD general vulnerabilities.
- Has Java or Go code audit experience with demonstrated results.
Why Join Us
At Bybit, we are committed to fostering a supportive and enriching work environment.
Our benefits include:
- Study Growth Fund: We support your professional development and continuous learning.
- Internal Events: Participate in regular team-building activities, workshops, and events designed to promote collaboration and innovation.
- Global Collaboration: Be part of a diverse, international team, working alongside colleagues from around the world.
- Career Advancement: Access opportunities for growth and advancement within a rapidly expanding global company.
- Internal Mobility: Grow with us- Your long-term development is important to us. We offer internal job opportunities to help build your career path.
Skills Required
- Associate degree or higher, although requirements may be relaxed for exceptionally capable candidates.
- At least 3 years of business development or security audit experience based on Java or Go.
- Experience leading or participating in Security Development Lifecycle implementation.
- Proficiency in common security vulnerabilities, including OWASP Top 10, vulnerability discovery, vulnerable code scenarios, and exploitation techniques.
- Expert-level proficiency in Java and/or Go, including language-specific characteristics, mainstream frameworks, and code auditing.
- Familiarity with white-box security audit methodologies and the ability to track and reproduce current vulnerabilities.
- Familiarity with development frameworks such as SpringMVC, SSM, Gin, and GoZero.
- Solid penetration testing knowledge and proficiency with common penetration testing methods and vulnerability exploitation techniques.
- Ability to use AI tools to improve security work efficiency.
- Strong initiative, logical thinking, communication, coordination, organization, and technical documentation skills.
- Experience with Trusted Execution Environments, security encryption, data protection architectures, and solution implementation.
- High-quality vulnerability submissions to domestic or international security response or bug bounty platforms.
- Discovery of CVE or CNVD general vulnerabilities.
- Demonstrated Java or Go code audit experience and results.
What We Do
Since its inception in March 2018, Bybit has emerged as a leading cryptocurrency exchange, offering a comprehensive suite of tailored crypto services and product solutions meticulously crafted for retail and institutional traders alike. Trusted by millions worldwide, Bybit continues to push the boundaries of innovation, consistently refining and expanding its multi-spectral product offerings. At the heart of Bybit's mission lies the unwavering commitment to providing a secure, reliable, and transparent trading platform that empowers investors to seamlessly navigate the dynamic world of crypto. Whether you seek to explore Spot or Derivatives trading, harness the potential of Mining and Staking products, or leverage API support for algorithmic trading, Bybit empowers you to take control of your crypto journey. As pioneers in the ever-evolving Web3 landscape, Bybit meticulously curates and incubates innovative crypto projects, decentralized solutions, and data-driven research, fostering a vibrant ecosystem of crypto education and growth opportunities. Our core values of empathy, responsiveness, and continuous improvement permeate every aspect of our operations, shaping an inclusive environment where every individual feels valued and empowered. Bybit actively collaborates with regulatory bodies and institutions worldwide, playing a pivotal role in establishing robust safety and security frameworks, paving the way for a secure and dynamic future of crypto. Embrace the Digital Revolution with Bybit: Your Trusted Partner in the Crypto Frontier. #CryptoArk #Bybit






