Senior Security Engineer (AI/Cloud)
ByteDance
About the Team The Team is researching offensive and defensive technology and skills to continuously improve the company's fundamental security, data security, and business security levels. We strive to minimize the impact of 0-day vulnerabilities and incidents. Our team provides a range of security services, including SDLC, vulnerability management, extreme critical risks discovery, supply chain security, network defense, red teaming, underground market crackdown, threat detection, emergency response, threat intelligence, and information security investigation.
Job Responsibilities:
- Responsible for the security construction of ByteDance's overseas cloud products and infrastructure. This mainly involves conducting security assessments of newly launched cloud products and penetration testing of existing cloud products.
- Continuously reduce the operational, configuration, and exposure risks of overseas cloud products and infrastructure. This includes vulnerability management and promoting the governance of common risks across various infrastructure types through security scoring and special governance initiatives.
- Research new attack and defense technologies. Discover better vulnerability discovery methods, research better vulnerability defense measures to prevent systems from being easily compromised, and attempt to use AI combined with various technical characteristics to improve attack and defense capabilities.
Requirements
Minimum Qualification(s):
- Familiarity with common risks, including their principles, attack and defense strategies, and systematic governance and construction approaches.
- Proficiency in at least one of the following programming languages: Golang, Python, Java, or NodeJS, with the ability to conduct code review and development.
- In-depth knowledge of security technologies in one or more of the following fields: AI security, devsecops, big data, networking, virtualization, zero trust.
- A good sense of professional ethics, good interest, and a desire for long-term development in this field.
Preferred Qualification(s):
- Candidates who have reported high-impact vulnerabilities or won famous security competitions (CTF&AWD&Exercise) are preferred.
- Candidates who have good practical results in security of AI or the application of AI in the security field are preferred.
Skills
- Cybersecurity
- Go
- Java
- Networking
- Nodejs
- Python
- Security engineering

