Senior Application Security Engineer
Job description
About the role
Bybit is seeking a Senior Application Security Engineer to join their security team and help protect the company's digital asset exchange platform from evolving threats. This role focuses on identifying and addressing security weaknesses in software applications throughout the entire development lifecycle, from initial design through production deployment. The engineer will work closely with development teams across multiple offices to build secure, reliable systems that handle cryptocurrency trading and sensitive financial operations. The position is based in either Abu Dhabi, UAE or Kuala Lumpur, Malaysia, and reports to the head of application security within the broader security organization.
Key facts
What you'll do
Conduct thorough security reviews of application code and architecture to find potential vulnerabilities before any code reaches production environments.
Collaborate with software development teams to integrate security checks into the continuous integration and delivery pipelines used for every release.
Perform penetration testing and static and dynamic analysis on web applications and backend services to validate security posture.
Design and implement security controls for APIs, authentication flows, and data protection mechanisms that safeguard user assets and information.
Investigate security incidents, trace root causes through detailed forensic analysis, and develop remediation strategies to prevent future occurrences.
Create and maintain comprehensive security documentation including threat models, risk assessments, and security guidelines for development teams to follow.
Mentor junior engineers and raise security awareness across the organization through regular training sessions and knowledge sharing workshops.
Evaluate third-party libraries and dependencies for known security risks and recommend mitigation steps or alternative solutions when needed.
Work with product managers to define security requirements for new features and product launches before development begins.
Monitor emerging threat landscapes and apply relevant findings to strengthen the company's application defenses on an ongoing basis.
Coordinate with external security researchers and bug bounty participants to validate reported vulnerabilities and manage disclosure processes.
Contribute to the development of security standards and best practices that govern how applications are built and deployed.
Requirements
Bachelor's degree in computer science, information security, or a related technical field, or equivalent practical experience in software development.
Five or more years of experience in application security, software security engineering, or a closely related discipline within a professional setting.
Strong understanding of common web application vulnerabilities including injection flaws, cross-site scripting, broken access controls, and security misconfigurations.
Hands-on experience with secure coding practices in languages such as Python, Java, Go, or JavaScript across multiple projects.
Familiarity with security testing tools including Burp Suite, OWASP ZAP, or equivalent automated scanning platforms for web application assessment.
Knowledge of cloud security fundamentals and how to secure applications deployed on platforms like AWS or similar cloud providers.
Experience working in a fast-paced environment with multiple competing priorities and tight delivery timelines under pressure.
Excellent written and verbal communication skills for presenting detailed security findings to both technical teams and non-technical stakeholders.
Proven track record of driving security improvements within engineering organizations and influencing development practices across cross-functional teams.
Understanding of secure software development lifecycle methodologies and how to embed security gates into each phase of development.
Nice to have
Experience with cryptocurrency or financial technology platforms and their unique security challenges, regulatory requirements, and compliance obligations.
Professional certifications such as Certified Application Security Engineer or Offensive Security Certified Professional demonstrate advanced expertise in the field.
Familiarity with containerization and orchestration tools like Docker and Kubernetes in security contexts including image scanning and runtime protection.
Previous involvement in open-source security projects or public vulnerability research disclosures shows initiative and deep technical curiosity.
Experience with DevSecOps practices and tooling that embed security testing directly into the software development workflow.
Skills & tools
Proficiency in application security testing methodologies including OWASP Top Ten and the OWASP Application Security Verification Standard.
Experience with code review tools and secure development frameworks used in enterprise-scale software organizations.
Ability to write custom scripts for automating security testing, vulnerability detection, and remediation tracking workflows.
Understanding of encryption standards and secure key management practices for protecting sensitive user data at rest and in transit.
Knowledge of regulatory frameworks relevant to financial services and data protection compliance requirements.
Comfort with Linux-based environments and command-line security tooling for daily security operations and investigations.
Familiarity with identity and access management systems, OAuth flows, and token-based authentication mechanisms.
Practical notes
This role requires coordination across multiple time zones given the Abu Dhabi and Kuala Lumpur office locations where the team operates.
Candidates should expect to participate in on-call rotation for handling security incidents and urgent vulnerability responses during all hours.
The position involves regular interaction with engineering, product, and compliance teams across the organization to align security with business goals.
Bybit operates in a regulated industry, so adherence to internal policies and external compliance standards is essential for this role.
The Senior Application Security Engineer will have the opportunity to shape security strategy and influence the direction of application security at Bybit.
About the company
Bybit Fintech Limited, known as Bybit, is a Dubai based centralized cryptocurrency exchange. The platform has faced regulatory warnings in several jurisdictions.