Job Summary
Manage and enhance Xiaomi’s international security systems, lead API security framework development, oversee vulnerability management, and ensure compliance with global data protection regulations to safeguard web and mobile applications.
Responsibilities
Manage the full lifecycle of core security solutions (WAF, MiShield, HIDS) for Xiaomi’s international business, including configuring policies, optimizing rules, and expanding coverage to protect web and mobile applications against threats such as OWASP Top 10
Develop real-time monitoring and alerting frameworks to analyze security logs, detect anomalous traffic and attacks, produce root-cause analysis reports, and improve defense strategies
Contribute to the design and implementation of an API security framework for international operations, creating models for abnormal behavior detection and access control to prevent unauthorized data access and API abuse
Integrate API security with gateways and microservices, incorporate SAST/DAST tools to promote shift-left security practices, and establish developer security guidelines
Oversee vulnerability management processes including scanning, risk assessment, and remediation for international business, implementing high-risk vulnerability response mechanisms and collaborating with R&D teams on code-level fixes
Monitor global threat intelligence and zero-day vulnerabilities, organize red/blue team exercises, and refine emergency response protocols
Ensure security operations comply with regional regulations such as GDPR and Singapore PDPA, preparing compliance audit reports
Collaborate with international business units, local compliance teams, and third-party vendors to provide security technical support and training
Required competencies and certifications
Bachelor’s degree or higher in Computer Science, Information Security, or related field
Expertise in operating security products such as WAF and IDS
Proficiency in API security design and protection, including knowledge of OWASP API Top 10 and gateway security policy deployment
Familiarity with vulnerability management tools and processes (e.g., Nessus, Burp Suite), with ability to reproduce vulnerabilities and validate remediation
Proficiency in scripting languages like Python and Shell
Knowledge of international data security regulations and compliance requirements
Ability to communicate effectively in English and Mandarin to support collaboration with Mandarin-speaking stakeholders, regional customers, engineering teams, and colleagues based in China.
Preferred competencies and qualifications
Experience in developing security automation tools
Professional certifications such as CISSP or CSSLP