Security Engineer
Software Engineering · Full-time
Singapore
About BIT:
BIT (formerly Matrixport) is a global digital asset financial services and infrastructure group. Headquartered in Singapore and founded in 2019, BIT bridges traditional finance and digital assets through governance-driven financial services and technology.
The firm manages over US$7 billion in assets and facilitates more than US$7 billion in monthly trading volume. BIT offers services including custody, trading, asset and wealth management, liquidity and financing solutions, and tokenised real-world assets (RWA), serving institutional and professional investors globally.
BIT Group entities maintain a licensed and regulated footprint across Singapore, Hong Kong, Switzerland, the United Kingdom, the United States and Bhutan.
For more information, visit www.bit.com
Why Join Us
At BIT, we tackle complex problems as a team. We encourage openness and promote transparency, respect, and inclusivity. Every team member is valued and has a voice that can be heard. We are always in search of intellectually curious and entrepreneurial individuals who are keen on making an impact in the crypto ecosystem and in building a better product for the next one billion users.
Responsibilities
- Participate in and drive our S-SDLC (Secure Software Development Lifecycle) program, including security requirements, secure code review, security testing, secure release, and ongoing security operations.
- Implement, operate, and optimize security platforms and policies, including SIEM, EDR, vulnerability management tools, Zero Trust, IAM, DLP, and WAF.
- Monitor and analyze logs and security alerts to detect, investigate, and respond to potential incidents. Perform initial triage, support incident classification and response, and contribute to post-incident reviews.
- Support vulnerability management and incident response: vulnerability monitoring and early warning, risk analysis, remediation coordination, retesting and verification, and closed-loop improvement.
- Support IT and security audits, including preparing and providing the evidence required by audit processes.
- Evaluate existing cybersecurity processes and recommend improvements to protect against external and internal threats, fraud, and theft.
- Partner with DevOps, IT, R&D, and business teams to align on risks and remediation plans, and provide security consulting, day-to-day security guidance, and risk assessments.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Information/Network Security, or a related field.
- 2+ years of experience in product/application security, security operations, or security engineering.
- Solid fundamentals in networking and operating systems, with a good understanding of common vulnerabilities and how to mitigate them.
- Hands-on experience with common security tools and platforms, and the ability to understand typical attack chains and interpret security alerts.
- Strong communication skills, with the ability to work effectively with stakeholders in both English and Chinese.
- Strong ownership: risk-aware, and able to track vulnerabilities and incidents through to closure.
- Strong collaboration: able to align with R&D, IT/Operations, and business teams on risks and remediation plans.
- Documentation and process mindset: able to turn experience into standards, SOPs, reports, and post-incident review materials.
- Strong learning ability: willing to close skill gaps through hands-on practice.
- Working knowledge of firewalls, IDS/IPS, VPNs, DDoS protection, and SOC operations is desirable.
- Experience in threat and vulnerability assessment, penetration testing, or forensic analysis is an advantage.
- Experience supporting IT or security audits is an advantage.
By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Policy. <https://www.BIT.com/privacy-candidate>