About the Company:
As a part of Ecommerce Engineering team, we exist for wow customer experiences, world class service excellence and hyper growing revenue. To achieve this, we build scalable & extensible architecture to support fast business growth & expansion, we create high performance & resilient backend system to handle increasing customer requests and we setup stable & fault-tolerant mechanisms to guarantee the customer experience. Creating disruptive products & resilient platforms for customers with world-class talents and cutting-edge technology is our vision and our commitment to the company.
About the Role:
- Responsible for web-side protocol analysis and parameter reverse engineering, and improving solutions;
- Continuously iterate on-device attack and defense capabilities, and explore the construction of a fully automated adversarial system.
Qualifications
- Bachelor's degree or above in Computer Science, Software Engineering, Information Security, or related fields, with at least 3 years of practical work experience in Web reverse engineering.
- Successful reverse engineering experience with mainstream Websites (e.g., social media, e-commerce, finance) is required, enabling independent completion of the entire process from decomplication to logical analysis.
- Strong logical analysis and problem-solving skills are essential; the ability to quickly identify technical bottlenecks in the reverse engineering process and develop solutions.
- Preference will be given to candidates with information security certifications (e.g., CEH, OSCP) or experience contributing to open-source reverse engineering tools.
- Excellent documentation and communication skills are required; the ability to clearly present reverse engineering results and collaborate effectively with the team.
- Both English and Mandarin speaking is required.
Required Skills
- Proficient in JavaScript reverse engineering, with AST (Abstract Syntax Tree) analysis capabilities (Babel Parser), and familiar with common JS obfuscation (string encryption, control flow flattening) and deobfuscation techniques;
- Proficient in browser debugging (Chrome DevTools), automation frameworks (Puppeteer/Playwright), and experience with Chromium kernel modifications is a plus;
- Familiar with web anti-scraping measures (browser fingerprinting & behavior, TLS fingerprinting, etc.) and human-machine identification measures (click/slider CAPTCHA, reCaptcha, Akamai, etc.);
- Familiar with common application layer protocols (HTTP/WebSocket), and possess network packet capture and analysis capabilities (Charles/Wireshark);
- Familiar with common encryption algorithms (RSA/AES/HMAC) and interface signature mechanisms;
- Proficient in web security, with experience in discovering and exploiting OWASP Top 10 vulnerabilities, and familiar with WAF (Web Application Firewall) and other security protections;
- Possess Python/Node.js development skills and be able to independently write automation tools.