Cybersecurity Engineer - Threat Modelling

at Jane Street · Quant · Hong Kong · Cybersecurity

Seeking a Cybersecurity Engineer with an offensive security background to join the Cybersecurity team. The role involves hands-on vulnerability identification and remediation, partnering with teams to integrate security from the ground up, and performing threat modeling. Responsibilities include analyzing security implications, building security solutions, and communicating security principles to system owners. The role requires strong technical skills, problem-solving abilities, and excellent communication.

What you'd actually do

  1. strengthen the security posture of our applications, data, infrastructure, and processes
  2. partner with various teams across the firm, guide teams to analyze the security implications of design decisions and guide them to build security into their applications from the ground up
  3. leverage your hands-on offensive background to identify threats
  4. dive deep into the technical details and help build tailored security solutions and develop creative approaches to complex challenges
  5. practical threat modeling skills and the ability to translate security principles into concrete architectural improvements

Skills

Required

  • Offensive security background
  • Build and implement secure solutions
  • Evaluate security tradeoffs
  • Make risk-based decisions
  • Teach others and transfer knowledge about threat modeling
  • Strong Linux background
  • Scripting ability
  • Take accountability
  • Document decision-making rationale
  • Fluent in English

Nice to have

  • Proficiency in any programming language

What the JD emphasized

  • hands-on technical expertise to uncover and remediate vulnerabilities
  • build security into their applications from the ground up
  • hands-on offensive background
  • practical threat modeling skills
  • security principles
  • security controls
  • risk analysis
Read full job description

About the Position

We're looking for a hands-on Cybersecurity Engineer to join our Cybersecurity team to strengthen the security posture of our applications, data, infrastructure, and processes.

The role combines both hands-on technical expertise to uncover and remediate vulnerabilities and people skills to partner with various teams across the firm, guide teams to analyze the security implications of design decisions and guide them to build security into their applications from the ground up.

The role will leverage your hands-on offensive background to identify threats and require you to dive deep into the technical details and help build tailored security solutions and develop creative approaches to complex challenges. This role will require practical threat modeling skills and the ability to translate security principles into concrete architectural improvements.

The role also involves having conversations with system owners who understand their applications but may not recognize potential exploits, partnering with them to identify and help resolve vulnerabilities, and balancing tradeoffs between security controls and business requirements.

As a member of the Cybersecurity team, you’ll join a skilled group of programmers and security experts dedicated to keeping the firm safe. Our work covers a wide range of topics, from software engineering and DevOps to risk analysis, security governance, and cyber awareness.

About You

  • Offensive security background
  • Can help build and implement secure solutions from the ground up
  • Equally comfortable breaking down complex problems on a whiteboard and taking a hands-on approach to problem-solving and troubleshooting
  • Skilled at evaluating security tradeoffs and making risk-based decisions
  • An excellent communicator who thrives on talking to people and building relationships; a collaborative mindset is a must
  • Ability to teach others and transfer knowledge about threat modeling
  • Strong Linux background — you know your way around a terminal and are confident in your scripting ability
  • Comfortable taking accountability and able to document your decision-making rationale
  • Proficiency in any programming language is a plus
  • Fluent in English

If you're a recruiting agency and want to partner with us, please reach out to agency-partnerships@janestreet.com.