Team Introduction
Our team is responsible for securing the company's infrastructure across every layer—from internal corporate infrastructure and engineering platforms to externally facing cloud infrastructure. We work closely with engineering teams to build security into the entire infrastructure lifecycle through secure design, vulnerability research, security reviews, governance, and automation. In this team, you'll have opportunities to have first-hand exposure to the strategy of the company in key security initiatives, especially in building scalable and secure-by-design systems and solutions.
We are looking for talented individuals to join our team. As a graduate, you will get opportunities to pursue bold ideas, tackle complex challenges, and unlock limitless growth.
Successful candidates must be able to commit to an onboarding date by the end of the year. Please state your availability and graduation date clearly in your resume.
Candidates can apply to a maximum of two positions and will be considered for jobs in the order you apply. The application limit is applicable to our Company and its affiliates' jobs globally. Applications will be reviewed on a rolling basis - we encourage you to apply early.
Responsibilities
- As a member of the Infrastructure Security team, you will focus on 2–3 of the following areas based on your interests, experience, and the team's priorities;
- Vulnerability Research – Conduct vulnerability research on modern technologies, including cloud-native platforms, containers, virtualization, operating systems, and distributed systems.
- Product Security Reviews – Perform security reviews for new products, architectures, and infrastructure components.
- Security Engineering & AI – Explore and develop AI-powered solutions for security engineering, including vulnerability discovery, security analysis, code review, and security automation.
- Security Governance – Develop security standards, best practices, and engineering guidance for infrastructure teams.
- Security Tooling – Build internal tools to improve vulnerability detection, security testing, and developer experience.
Minimum Qualifications
- Individuals who are completing or have recently completed a Bachelor's/ Master's degree in Computer Science, Cybersecurity, Software Engineering or a related discipline.
- Solid understanding of common vulnerability classes, including memory corruption, web security, authentication and authorization issues, and logic flaws.
- Hands-on experience in vulnerability discovery, security research, penetration testing, or exploit development.
- Experience with one or more programming languages such as C/C++, Go, Python, Rust, or Java.
- Passion for offensive security, infrastructure security, and continuous learning.
Preferred Qualifications
- Publicly disclosed CVE vulnerabilities.
- Contributions to well-known open-source security projects or widely used GitHub repositories.
- Strong rankings or awards in well-known security competitions (e.g. DEF CON CTF, HITCON CTF, Real World CTF, GeekPwn, XCTF, Blue Water, or similar).
- Publications or presentations at leading security conferences, such as Black Hat, USENIX Security, NDSS, ACM CCS, or other top-tier venues.
- Experience applying Large Language Models (LLMs) or AI agents to security workflows, such as code analysis, vulnerability detection, security automation, or offensive security research.
- Experience with cloud platforms (AWS, Azure, GCP), Kubernetes, container security, virtualization, or infrastructure-as-code security.
- Contributions to security tooling, fuzzers, static analysis, dynamic analysis, or exploit frameworks.