pAs a Product Security Analyst, you will be a key member of the team responsible for ensuring the security of Qualgo's products throughout their entire lifecycle. You will work closely with product managers, engineers, and the security team to integrate security into the design, development, testing, and deployment of our products. You will be a hands‑on security expertise, conducting threat modeling, security reviews, and providing guidance on secure coding practices. You will be a champion for "security by design" and help build a culture of security within the product development organization. /p h3Key responsibilities /h3 pbThreat Modeling: /b /p pConduct threat modeling sessions with product and engineering teams to identify potential security vulnerabilities in new and existing features. /p pSpecifically address threats relevant to VPN protocol vulnerabilities, server compromise, man‑in‑the‑middle attacks, DNS leaks or E2EE weaknesses, message forgery, impersonation, account takeover. /p pDevelop and maintain threat models for all products. /p pbSecurity Requirements Definition: /b /p pTranslate security best practices and regulatory requirements (e.g., Vietnamese cybersecurity laws, data privacy regulations) into concrete, actionable security requirements for product teams. /p pEnsure that security requirements are incorporated into product specifications and user stories. /p pSpecifically address requirements related to blocking, anti‑tracking, malware/phishing protection, parental controls and E2EE, secure messaging, group chats /p pbSecurity Design Reviews: /b /p pReview product designs and architectures to identify potential security flaws. /p pProvide guidance to engineers on secure design principles. /p pEnsure that security is considered at every stage of the design process. /p pSpecifically review designs related to VPN protocol implementation, server infrastructure, and client‑side security features. Review E2EE implementation, key management, and authentication mechanisms. /p pbCode Reviews (Security Focus): /b /p pConduct security‑focused code reviews to identify vulnerabilities and ensure adherence to secure coding practices. /p pFocus on areas of code relevant to security, such as authentication, authorization, encryption, data validation, and network communication. /p pReview code related to VPN protocol implementations, network handling, and security features. Review E2EE implementation (e.g., Signal Protocol or MLS integration), key management, and message handling. /p pbSecurity Testing: /b /p pWork with QA and engineering teams to develop and execute security tests, including penetration testing, vulnerability scanning, and fuzzing. /p pCoordinate with external security researchers or penetration testing firms as needed. /p pSpecifically test VPN functionality, server security, and client‑side security features. Test E2EE implementation, message integrity, and authentication mechanisms. /p pbSecure Development Lifecycle (SDL): /b /p pPromote and implement secure development lifecycle (SDL) practices throughout the organization. /p pDevelop and deliver security training to engineers. /p pDevelop and maintain secure coding guidelines. /p pbVulnerability Management: /b /p pTrack and manage security vulnerabilities identified in our products. /p pWork with engineering teams to prioritize and remediate vulnerabilities. /p pbIncident Response (Product Focus): /b /p pParticipate in incident response activities related to product security vulnerabilities. /p pContribute to post‑incident analysis and lessons learned. /p pWork closely with product managers, engineers, designers, and security team. /p pCommunicate effectively with both technical and non‑technical stakeholders. /p h3Qualifications /h3 pBachelor's degree in Computer Science, Information Security, or a related field. /p pMinimum of 2+ years of experience in product security, application security, or penetration tester. /p pStrong understanding of security principles and best practices. /p pExperience with threat modeling methodologies (e.g., STRIDE, DREAD). /p pExperience with secure coding practices and common security vulnerabilities (e.g., OWASP Top 10). /p pExperience with security testing tools and techniques. /p pExperience with VPN technologies (WireGuard, OpenVPN) is a strong plus /p pExperience with end‑to‑end encryption (E2EE) and messaging protocols (e.g., Signal Protocol, MLS) is a strong plus. /p pExperience with mobile application security (iOS and Android) is a plus. /p pExperience with cloud security (AWS, GCP, Azure) is a plus. /p pExperience working in an Agile environment. /p h3Skills /h3 pStrong technical skills in software security. /p pExcellent communication and collaboration skills. /p pAbility to explain complex security concepts to non‑technical audiences. /p pAbility to work independently and as part of a team. /p pPassion for building secure and trustworthy products. /p pFluency in English is a plus. /p h3What we offer /h3 p01. /p pWork on products that protect users’ data and make a real difference in people’s lives. /p p02. /p pGreat work deserves great rewards — enjoy competitive pay and recognition for contribution and impact you make. /p p03. /p pFuel your growth with hands‑on learning. Enjoy extra leaves, and premium healthcare for you and your family. /p p04. /p pCollaborate, create, and celebrate — a modern workspace built for teamwork, fun, and innovation. /p p05. /p h3Young dynamic environment /h3 pWork with stunning colleagues where creativity thrives, ideas are welcome, and every day brings new challenges and opportunities. /p #J-18808-Ljbffr
Kontaktdaten:
Qualgo Technologies Vietnam Co., Ltd. Recruiting-Team