Lead Security Engineer, Product Security (Taiwan)
Circle is a global financial technology firm that enables businesses of all sizes to harness the power of digital currency and public blockchains for payments, commerce and financial applications worldwide. Circle platforms and products provide a suite of internet-native financial services for payments, treasury infrastructure and capital formation. Circle is also a principal developer of USD Coin (USDC), which has become the fastest growing dollar digital currency in the world. USDC has grown to over 44+ billion in circulation and supported over $1.7+ trillion in transactions in the past year. Circle’s payments and treasury infrastructure services available through the Circle Account and APIs helps bridge the legacy financial system and digital currency and blockchain based finance. Combined, Circle’s suite of services helps companies to participate in a more open, global and inclusive financial system.
What you’ll be part of:
With the mission “To raise global economic prosperity through the frictionless exchange of value,” Circle was founded on the belief that the internet, blockchains and digital currency will rewire the global economic system, creating a fundamentally more open, inclusive, efficient and integrated world economy. We envision a global economy where people and businesses everywhere can more freely connect and transact with each other with new technologies for digital money and internet-native finance. We believe such a system can raise prosperity for people and companies everywhere. Our mission is powered by the values we espouse and which we expect all Circlers to respect. We are Multistakeholder, serving the needs of our customers, our shareholders, our employees and families, our local communities and our world. Furthermore, we are also Mindful, Driven by Excellence, and High Integrity.
What you’ll be responsible for:
The Circle Security Team works to protect Circle; our customers, clients and partners; and the financial markets upon which we rely. The security engineering team leads preventive security across the company.
As a member of this team, you’ll lead projects and be responsible for key deliverables of the security program while collaborating across Circle teams. You will continue to learn and stay current in a fun and rapidly evolving environment.
What you'll work on:
- Work with the product management and software engineering teams during all phases of the SDLC to ensure that applications are designed and implemented securely.
- Test web applications and the underlying systems for vulnerabilities using both tools and manual techniques; manage the remediation of findings through resolution.
- Recommend code changes to eliminate vulnerabilities.
- Automate security tests within the CI/CD pipeline.
- Help develop secure coding standards and training materials based on findings seen in Circle’s environment to empower engineers to write more secure code.
- Research vulnerabilities specific to blockchain technologies and incorporate this knowledge into current practices.
- Serve as an escalation point to investigate security alerts and identify incidents.
- Investigate vulnerability reports related to Circle products and services.
- Manage vendors to conduct penetration tests and other security-related projects.
- Influence continuous improvement of the application security program.
- Support other security team projects such as threat modeling, vulnerability scanning and audits.
You will aspire to our four core values:
- Multistakeholder - you have dedication and commitment to our customers, shareholders, employees and families and local communities.
- Mindful - you seek to be respectful, an active listener and to pay attention to detail.
- Driven by Excellence - you are driven by our mission and our passion for customer success which means you relentlessly pursue excellence, that you do not tolerate mediocrity and you work intensely to achieve your goals.
- High Integrity - you seek open and honest communication, and you hold yourself to very high moral and ethical standards. You reject manipulation, dishonesty and intolerance.
What you’ll bring to Circle:
- 7+ years of total experience in a Security role.
- 3+ years of experience as a security engineer that has been leading projects and developing resolutions in cybersecurity.
- Enthusiasm for securing and breaking software.
- Experience with common attack techniques and conducting penetration tests.
- Experience designing software security features including, but not limited to, access control features, logging and monitoring features, input validation and session management.
- Experience automating security tests in cloud based CI/CD pipelines.
- Experience working with SAST and DAST testing processes and tools.
- Working knowledge of public and private key cryptography.
- Familiarity with techniques for making software robust against common attacks.
- Self-motivated and creative problem solver able to work independently with minimal guidance.
- Strong ability to work collaboratively across teams.
- Ability to manage multiple competing priorities and use good judgment to establish priorities on the fly.
- Experience working in financial services or financial technology desired.
- Bachelor's degree in computer science, computer engineering, cyber security or related field. Equivalent experience is also accepted.
- Certifications such as CISSP, CEH or similar will receive favorable consideration but are not required.
- Experience working on applications deployed within AWS highly desired.
- Experience with at least several of the following is required: Java, GoLang, Angular JS, Rest API’s, JSON, Python or GraphQL.
- Experience with application development on iOS and/or Android is preferred but not required.
- Fluency in English and Mandarin is required.
We are an equal opportunity employer and value diversity at Circle. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Something looks off?