蚂蚁金服Ant International-Web Application Security Engineer-Malaysia
任职要求
● 3+ years in application security, with exposure to both client-facing (consulting) and corporate environments. ● Hands-on experience with tools like Burp Suite, Metasploit, OWASP ZAP, or Nessus. ● Familiarity with programming/scripting languages (e.g., Python, Java, JavaScript). ● Excellent communication skills to convey risks to technical and non-technical audiences.
工作职责
● Conduct security assessments (SAST, DAST, SCA) and penetration testing to identify vulnerabilities in web/mobile applications and APIs. ● Perform risk analysis and provide actionable remediation recommendations. ● Collaborate with development teams to integrate security practices into SDLC (e.g., threat modeling, secure code reviews). ● Develop and maintain security standards, policies, and playbooks aligned with frameworks like OWASP, NIST, or ISO 27001. ● Engage with clients or internal teams to articulate security risks and mitigation strategies
The Role We’re looking for highly motivated Application Security engineers with an adversarial mindset to help strengthen Tesla’s overall security posture. You'll get hands-on with a wide array of technologies – including websites, robots, and energy systems – and learn how they interconnect, where they fail, and how to make them stronger. In this role, you’ll emulate both internal and external threat actors to uncover weaknesses across our most critical products and infrastructure. From designing real-world attack scenarios to conducting deep technical assessments, your work will directly shape how we defend systems at scale. If you’re passionate about CTFs, vulnerability research, exploit development, or just love “breaking things” to understand them better, this role is for you. Whether it’s writing custom tooling, crafting a successful phishing campaign, or gaining domain admin, you’ll have the freedom to get creative. You’ll be operating in a high-impact, complex environment spanning thousands of systems, services, and endpoints. At Tesla, you’ll use your offensive skills to drive meaningful change and contribute to one of the most ambitious roadmaps in tech today. Responsibilities • Breaking everything you touch and helping us fix it. • Conducting penetration tests against Tesla networks, applications and services. • Conduct proactive Application Security exercises to simulate real-world external adversaries and insider threats, identifying vulnerabilities and assessing the effectiveness of organizational cybersecurity defenses. • Performing security assessments on third-party services and software. • Collaborating cross functionally with engineers to develop secure services. • Auditing source code for security vulnerabilities. • Develop/implement automated systems to help spot known security exposures.
As a pivotal member of the Copilot Team, you will bring unique perspectives and expertise to the organization, driving innovative features and delivering transformative AI-powered experiences:• This is an IC role, Coding / engineering design time >70%• Manage complex projects from conception to implementation, with a focus on delivering AI-driven user interfaces and performance-optimized web applications.• Coordinate technical delivery through sprints, fostering collaboration throughout the project lifecycle.• Collaborate across geographies and time zones to establish best practices and develop automated processes that mitigate development risks.• Investigate and debug complex performance issues in applications, ensuring optimal user experience and system efficiency.• Design and implement performance testing strategies to proactively address bottlenecks.• Work closely with Product Designers, Product Managers, and Engineers to deliver AI-enhanced products that delight users.• Drive team-wide investments in infrastructure and foundational systems to support long-term technical roadmaps.• Solve technical challenges to deliver outstanding outcomes for customers and the business.
• Design, implement, deploy and maintain the highly scalable and available web storefronts or our live games • Share ownership of the service architecture and technical solutions to build towards our long term vision • Contribute to best practices on security, reliability and availability • Periodically offer 24/7, first-line support to the production environments, as part of a rotating on-call duty • Work in collaboration with the Supercell X team and our stakeholders such as the game teams and Player Support to deliver seamless player experiences • Bring a strong product mindset, including setting technical direction, aligning development goals with business objectives, and communicating with stakeholders