[Security] Senior Application Security Engineer
What security roles in crypto pay
84 salaries · our own dataMost security roles in crypto pay between $142k and $270k, with a median of $200k.
As a Senior Application Security Engineer at Bybit, you lead security auditing and governance across our platform systems serving over 80 million users. You identify risks in business requirements and technical implementations, devise solutions, and drive their adoption across our trading, payments, wealth management, and Web3 ecosystem.
What you'll do
- Conduct manual code security audits on business code written in Java, Golang, JavaScript, C++, and other languages, producing detailed audit reports
- Track domestic and international security developments, analyze and reproduce the latest security vulnerabilities
- Deeply understand the company's product business and identify security risks in business architecture, processes, and logic; provide and drive implementation of corresponding security solutions
- Drive security solution implementation and risk governance across the platform
What you bring
- Associate degree or above (requirements may be relaxed for candidates with strong capabilities)
- At least 3+ years of business development or audit experience based on Java or Go, with experience leading or participating in SDL (Security Development Lifecycle) implementation
- Proficiency in the underlying principles, discovery methods, vulnerable code scenarios, and exploitation techniques of common security vulnerabilities including OWASP Top 10
- Expert-level proficiency in Java and/or Go tech stacks; understanding of language-specific characteristics, common mainstream development frameworks, and relevant code audit experience
- Familiarity with common white-box audit methodologies and the ability to track and reproduce the latest vulnerabilities
- Familiarity with mainstream development frameworks such as SpringMVC, SSM, Gin, or GoZero
- Solid understanding of penetration testing with proficiency in common penetration testing methods and knowledge of common vulnerability principles and exploitation techniques
- Proficiency in using AI tools to enhance security work efficiency
- Strong proactive mindset with excellent logical thinking, communication, coordination, organizational skills, and documentation writing ability
Nice to have
- Submission of high-quality vulnerabilities to domestic or international SRC or bug bounty platforms
- Discovered CVE or CNVD general vulnerabilities
- Java or Go code audit experience with demonstrated results
- Experience with TEE (Trusted Execution Environment) and other security encryption and data protection technical architectures and solution implementation
What we offer
- Study Growth Fund supporting your professional development and continuous learning
- Regular internal team-building activities, workshops, and events
- Global collaboration with a diverse, international team
- Career advancement opportunities within a rapidly expanding global company
- Internal mobility and long-term career development support
About Bybit
Established in 2018, Bybit is one of the world's leading cryptocurrency exchanges and digital financial platforms, serving over 80 million users across more than 200 countries. The company delivers a seamless ecosystem spanning trading, payments, wealth management, custody, institutional services, and Web3, recognized as one of the most trusted and transparent platforms in the digital asset industry.
Context for this role
From the live jobs we track on CryptoJobsHQ, updated daily.
Bybit has 95 open roles on CryptoJobsHQ: 34 in Legal & Compliance, 24 in Engineering and 8 in Security. 2% are fully remote, most of the rest in the US and the UAE. 16 were posted in the last 7 days.
All 95 Bybit roles →1,084 Trading roles are open across crypto right now.
Browse Trading Jobs →- Data Protection Officer at Bitvavo · On-site
- VP, Product Analytics at Crypto.com · Hybrid
- Head of RWA at Solana Foundation · On-site
- Head of OTC Trading at Luno · Remote
