Senior Offensive Security Engineer

Security Remote Hong Kong, Remote - Asia, Singapore 2 months ago
Apply for this role
Listed via Greenhouse · Redirects to Bitmex's careers page

Job Description

About BitMEX

BitMEX stands as a globally leading exchange for crypto derivatives, offering traders a professional-grade trading platform. Since its inception in 2014, BitMEX has maintained an impeccable security record with “no coin lost, ever!”.

Our platform caters to cryptocurrency derivatives traders by providing low latency, deep liquidity, and maximum availability. Currently, BitMEX offers more than 100 derivatives contracts, 16 pairs for spot trading, and an easy covert function between 30+ different cryptocurrencies.

In 2015, BitMEX revolutionised the market by inventing the Perpetual Swap, which has since become the most widely traded crypto product. Demonstrating a commitment to transparency, since 2021, BitMEX has been among the first exchanges to regularly publish its on-chain Proof of Reserves and Proof of Liabilities, ensuring that the funds available exceed the total client balances."

For more information on BitMEX, company initiatives and our products, please visit the BitMEX Blog or www.bitmex.com, and follow LinkedIn, Discord, Telegram and X.

Overview

This is an opportunity for an intermediate/senior level Offensive Security Professional to join our Product Security team. As an experienced researcher you will help maintain critical security systems within our architecture, as well as assisting the wider engineering and devops practices with their activities. In Product Security our mission is to continuously improve the security posture of BitMEX from the inside, and we are looking for someone capable and flexible who can work with our excellent staff on that mission!

A crypto trading exchange is a security environment that is fairly rare in the infosec industry: we regularly get attacked by nation-state APT groups, we have continuous attempts by everyone from script kiddies to our own users trying to find ways to illegitimately extract money from us, and we protect vast amounts of crypto. All at the same time having a software stack that requires extreme uptime, minimal latency, and absolute accuracy in how it takes and processes orders.

If you want to help protect an environment where the threats are very real and continuous, this is the job for you. We will check that you are not from the DPRK, be warned; it would not be the first (or second, or third) time.

Key Responsibilities

  • Manage our bug bounty program, reviewing reports, engaging with researchers and cooperating with software engineering to fix bugs
  • Reviewing the outcomes of external penetration tests, replicating issues and again, working with engineering to fix findings
  • Conducting internal penetration tests on our software and infrastructure stack
  • Red and purple team exercises to test our monitoring
  • Security research & threat Intelligence, working with security response
  • Application security & code reviews, internal training of engineers
  • Being part of incidents to help triage and investigate issues

Qualifications

  • 5+ Years in Information Security.
  • Proven expertise in offensive security either through certifications, recognition, or referees.
  • Strong communication skills and work ethic: contribute actively to the company and become ‘known’
  • Candidates with less experience will be considered for an Offensive Security Engineer position.

Nice to have

  • Experience with Kubernetes, Istio, Envoy and the AWS cloud platform would be useful. Advanced skills in these (and affiliated technologies) are a bonus but not required.
  • Experience with GitHub CI/CD / Actions and/or ArgoCD is a bonus but not required
  • Experience with derivatives and cryptocurrency is a bonus but not required.
  • Development expertise in Go is a bonus but not required

Why BitMEX?

BitMEX offers a dynamic environment that blends intense work, a vibrant culture, and diversity. We actively recruit across time zones to meet growing demands and attract top global talent.

We're seeking determined, responsible, and collaborative individuals to join us in building a leading cryptocurrency ecosystem. We value meticulousness, agility, and simplicity. As a 24/7 global exchange, we look for adaptable team players who can excel in a diverse, cross-market environment.

We provide flexible arrangements to our remote contract talents with:

  • Work from home to help you find the perfect balance between work, family and personal life
  • Paid holidays and leave so you won’t miss out any important events
  • Team building & offsite events to bring our global team closer
  • Don’t forget the advantage of our Beyond Border Remote Working policy, where you get to work away from your home country
  • Option to choose to be paid in fiat or crypto currency, providing the flexibility to shape your financial freedom

#LI-CH1

Does this sound like the type of working culture you can thrive in? Apply online now!

About Bitmex

Bitmex is actively hiring on The Code Deck.

All Bitmex jobs →

More from Bitmex

Senior Infrastructure Security Engineer
Remote · Security
Trading Technology Engineer (Java/Quant)
Germany, Switzerland, United Kingdom, United States · Backend
Senior Software Engineer, Trading Technology (Query Stack)
Afghanistan, Albania, Algeria, Andorra, Angola, Antarctica, Armenia, Austria, Azerbaijan, Bahrain, Belarus, Belgium, Benin, Bosnia and Herzegovina, Botswana, Bouvet Island, Bulgaria, Burkina Faso, Burundi, Cabo Verde, Cameroon, Central African Republic, Chad, Comoros, Congo, Congo, The Democratic Republic of the, Cook Islands, Croatia, Curaçao, Cyprus, Czechia, Côte d'Ivoire, Denmark, Djibouti, Egypt, Equatorial Guinea, Eritrea, Estonia, Eswatini, Ethiopia, Faroe Islands, Finland, France, French Guiana, French Southern Territories, Gabon, Gambia, Georgia, Germany, Ghana, Gibraltar, Greece, Greenland, Guadeloupe, Guernsey, Guinea, Guinea-Bissau, Heard Island and McDonald Islands, Holy See (Vatican City State), Hungary, Iceland, Iran, Iraq, Ireland, Isle of Man, Israel, Italy, Jersey, Jordan, Kazakhstan, Kenya, Kuwait, Kyrgyzstan, Latvia, Lebanon, Lesotho, Liberia, Libya, Liechtenstein, Lithuania, Luxembourg, Madagascar, Malawi, Mali, Malta, Martinique, Mauritania, Mauritius, Mayotte, Moldova, Monaco, Montenegro, Morocco, Mozambique, Namibia, Netherlands, Niger, Nigeria, North Macedonia, Norway, Oman, Palestine, State of, Poland, Portugal, Qatar, Romania, Russian Federation, Rwanda, Réunion, Saint Barthélemy, Saint Helena, Ascension and Tristan da Cunha, Saint Martin (French part), Saint Pierre and Miquelon, San Marino, Sao Tome and Principe, Saudi Arabia, Senegal, Serbia, Seychelles, Sierra Leone, Sint Maarten (Dutch part), Slovakia, Slovenia, Somalia, South Africa, South Sudan, Spain, Sudan, Svalbard and Jan Mayen, Sweden, Switzerland, Syrian Arab Republic, Tajikistan, Tanzania, Togo, Tunisia, Turkey, Turkmenistan, Uganda, Ukraine, United Arab Emirates, United Kingdom, Uzbekistan, Western Sahara, Yemen, Zambia, Zimbabwe, Åland Islands · Backend
Crypto Trading Product Designer
Remote · Design
Growth Engineer (Data Systems)
Remote · Data
Career Toolkit

Ready to apply?

Check your CV against this job, generate a cover letter, and prep for the interview — all in one place.

Open Career Toolkit →
For Employers

Want this spot?

Pin your listing to the top of every search with a gold Featured badge. From £49.

Feature a listing →

Paste your CV

We'll save it so you can tailor it to any job with one click.