Responsibilities
- Design and implement secure application architectures, considering factors like authentication, authorization, data protection, and vulnerability management etc.
- Develop and maintain secure coding guidelines and standards.
- Conduct architectural / security requirement reviews to identify/assess potential security risks and mitigate security risks that may be caused by new products, new functions, bug fixes, etc..
- Develop and implement security controls and countermeasures to mitigate identified risks.
- Conduct regular security audits or penetration testing.
- Ensure compliance with relevant security standards and regulations (e.g., OWASP).
- Stay up-to-date with the latest security threats and vulnerabilities and incident in the community etc.
- For the company's product business area, conduct pre-research to deep understand the business and reserve security tech research
- Gradually form a basis for risk identification based on different products and security solution
- Communicate security risks and recommendations to stakeholders.
- Provide guidance and mentorship to the teams on security suggestions and secure coding practices.
Requirements
- A bachelor's degree or above in computer science or a related field
- More than 6 years of application security experience or software development, more than 10 years is preferred
- Strong understanding and execution of software development principles and SDLC
- Proficient in mainstream Web application development technology, Java-based tech stack is preferred
- Proficient in the causes and solutions of OWASP TOP 10 security issues
- Proficient in technical implementation of common security solutions
- Understand the basic techniques of penetration testing and security testing
- Familiar with the use of static security scanning tools for code, as well as problem analysis and solution design
- Understand the basic knowledge of mobile and web security
- Systematically grasp the formation mechanism of application security vulnerabilities and have the ability to design corresponding solutions (in line with industry best security practices)
- Understand the thinking of threat modeling and attack surface analysis, actual combat experience is preferred
- Bilingual English/Mandarin is required to be able to coordinate with overseas partners and stakeholders.
- Ability to work independently and as part of a team.
- Strong problem-solving and analytical skills.
Skills Required
- Bachelor's degree or above in computer science or a related field
- More than 6 years of application security experience or software development
- More than 10 years of experience
- Strong understanding and execution of software development principles and SDLC
- Proficient in mainstream web application development technologies (Java-based tech stack preferred)
- Proficient in causes and solutions of OWASP Top 10 security issues
- Proficient in technical implementation of common security solutions
- Understanding of basic penetration testing and security testing techniques
- Familiarity with static security scanning tools for code and ability to analyze findings and design solutions
- Understanding of mobile and web security fundamentals
- Ability to systematically identify application security vulnerabilities and design corresponding solutions following industry best practices
- Understanding of threat modeling and attack surface analysis
- Actual hands-on experience with threat modeling/attack surface analysis
- Bilingual English/Mandarin for coordination with overseas partners
- Ability to work independently and collaboratively in teams
- Strong problem-solving and analytical skills
Binance Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Binance and has not been reviewed or approved by Binance.
-
Career-Linked Recognition & Rewards — Performance-linked bonuses can be sizable in favorable crypto cycles, lifting total compensation. Attractive packages in engineering and specialized roles indicate strong rewards for in-demand skills.
-
Flexible Benefits — Remote-first flexibility and work-from-anywhere options add meaningful value to the overall rewards package. Flexible schedules and location independence are presented as core perks.
-
Retirement Support — Binance.US includes a 401(k) as part of its benefits. This provides a conventional retirement pillar alongside cash and bonus components.
Binance Insights
What We Do
Binance is the world’s leading blockchain and cryptocurrency infrastructure provider with a financial product suite that includes the largest digital asset exchange by volume. Trusted by millions worldwide, the Binance platform is dedicated to increasing the freedom of money for users, and features an unmatched portfolio of crypto products and offerings, including: trading and finance, education, data and research, social good, investment and incubation, decentralization and infrastructure solutions, and more. For more information, visit: https://www.binance.com






