Source description
About the role
Core experience
3 to 4 years of hands-on product or application security experience — including securing cloud-native, microservices, and mobile applications in production environments.
Strong threat modeling skills — practiced with STRIDE, attack trees, or equivalent frameworks. You can walk a team through a design, surface the real risks, and produce actionable mitigations, not theoretical lists.
Design review depth — able to read an architecture diagram or PRD and identify weak authentication, authorization gaps, data exposure risks, insecure integrations, and systemic issues. Comfortable pushing back with a clear, pragmatic security rationale.
Vulnerability analysis and secure code review — proficient reviewing code (Node.js/TypeScript, Python, Go, or similar) for OWASP Top 10, business logic flaws, authz issues, and supply chain risks. You understand the difference between a CVE and an exploitable vulnerability in context.
Programming proficiency — at least one of Python, TypeScript/Node.js, or Go. You write tooling, not just tickets.
AI and forward-looking capability
Genuine fluency with modern AI tooling — you use LLMs, coding agents, and MCP-based tooling in your day-to-day security work, and can speak to concrete examples of leverage you've created with them.
Understanding of AI/ML security risks — prompt injection, data exfiltration via agents, insecure tool use, model supply chain, and related attack classes. You don't need to be a researcher, but you should be current.
Builder mindset for AI-first security — excited by the idea of architecting security workflows with AI as a first-class capability rather than layering AI on top of existing processes only.
Learning to Execution Mentality — With the evolving space of AI, you must keep up with the next-gen technology being released, cutting the noise and clutter, and applying those insights into tooling and processes.
Ways of working
Pragmatic and high-signal — you focus on high-severity, high-impact findings and are allergic to low-severity noise. You know when to push, when to accept a risk, and when to automate a decision.
Strong written communication — you can reduce a complex finding to a crisp risk statement, a clear recommendation, and a realistic remediation path for a busy engineering team.
Collaborative by default — you drive outcomes through partnership with engineering, not gatekeeping. You're comfortable being the only security voice in a roomful of engineers and earning influence through substance.
Comfortable with ambiguity and ownership — our security team is lean; the role has broad scope and the autonomy that comes with that.
More at ShopBack
Related open roles
Senior / Product Manager - Deal Discovery & Checkout
Hong Kong · Onsite
Senior / Product Manager - Deal Discovery & Checkout
Shenzhen · Onsite
Senior / Product Manager - Deal Discovery & Checkout
SG · Onsite
Venture Lead, Monetization (AI-Native)
China · Onsite
Staff Product Manager, Monetization (AI-Native)
CN · Onsite
Venture Lead, Monetization (AI-Native)
Singapore · Onsite
