
Senior Application Security Architect
BinancePosted 4/16/2025

Senior Application Security Architect
Binance
Job Location
Job Summary
We are seeking a Senior Application Security Architect to design and implement secure application architectures for Binance's blockchain ecosystem. The ideal candidate will have over 6 years of experience in application security, proficiency in Java-based tech stack, and knowledge of OWASP TOP 10 security issues. They will work with a talented team to develop and maintain secure coding guidelines, conduct architectural reviews, and provide guidance on security suggestions and best practices. With a strong understanding of software development principles and SDLC, the candidate will ensure compliance with relevant security standards and regulations. Binance offers a competitive salary, company benefits, and flexible remote work options.
Job Description
Responsibilities
- Design and implement secure application architectures, considering factors like authentication, authorization, data protection, and vulnerability management etc.
- Develop and maintain secure coding guidelines and standards.
- Conduct architectural / security requirement reviews to identify/assess potential security risks and mitigate security risks that may be caused by new products, new functions, bug fixes, etc..
- Develop and implement security controls and countermeasures to mitigate identified risks.
- Conduct regular security audits or penetration testing.
- Ensure compliance with relevant security standards and regulations (e.g., OWASP).
- Stay up-to-date with the latest security threats and vulnerabilities and incident in the community etc.
- For the company's product business area, conduct pre-research to deep understand the business and reserve security tech research
- Gradually form a basis for risk identification based on different products and security solution
- Communicate security risks and recommendations to stakeholders.
- Provide guidance and mentorship to the teams on security suggestions and secure coding practices.
Requirements
- A bachelor's degree or above in computer science or a related field
- More than 6 years of application security experience or software development, more than 10 years is preferred
- Strong understanding and execution of software development principles and SDLC
- Proficient in mainstream Web application development technology, Java-based tech stack is preferred
- Proficient in the causes and solutions of OWASP TOP 10 security issues
- Proficient in technical implementation of common security solutions
- Understand the basic techniques of penetration testing and security testing
- Familiar with the use of static security scanning tools for code, as well as problem analysis and solution design
- Understand the basic knowledge of mobile and web security
- Systematically grasp the formation mechanism of application security vulnerabilities and have the ability to design corresponding solutions (in line with industry best security practices)
- Understand the thinking of threat modeling and attack surface analysis, actual combat experience is preferred
- Bilingual English/Mandarin is required to be able to coordinate with overseas partners and stakeholders.
- Ability to work independently and as part of a team.
- Strong problem-solving and analytical skills.