Partner with software engineering and infrastructure teams to embed security throughout the software development lifecycle (SDLC) for high-frequency trading platforms. Conduct threat modeling, security code reviews, and architecture assessments across core languages and cloud environments. Requires 5-10 years of hands-on experience in product security, application security, or security architecture.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
Our client is a leading global quantitative investment firm renowned for leveraging advanced technology, cloud infrastructure, and quantitative research to power its high-frequency and systematic trading platforms. As part of its continued investment in secure software engineering and cloud-native technology, the firm is expanding its APAC Security team to strengthen security across business applications, cloud platforms, and core infrastructure in a fast-paced, engineering-driven environment.
We are seeking a Product Security Engineer / Security Architect to partner closely with software engineering and infrastructure teams to embed security throughout the software development lifecycle (SDLC). This position reports directly to the Head of Security in APAC and focuses on secure-by-design principles, threat modeling, security code reviews, and architecture reviews rather than offensive penetration testing.
This role is based in Hong Kong. Comprehensive relocation support and benefits will be provided for qualifying candidates.
Key Responsibilities:
- Product Security & Architecture Review: Partner with software engineering teams to evaluate system designs, review application architecture, and integrate secure-by-design principles into core trading systems and platforms.
- Secure Software Development & Code Review: Conduct security code reviews across core languages (Python, C++, Rust, Go, Java) to identify vulnerabilities, promote secure coding practices, and guide developers on remediation.
- Threat Modeling & Risk Assessment: Perform threat modeling, risk assessments, and vulnerability analysis across business applications, hybrid cloud services, and infrastructure.
- DevSecOps & Security Tooling: Assist with integrating, managing, and automating security testing tools—including SAST, DAST, dependency scanning, and secret detection—within CI/CD pipelines and developer workflows.
- Security Control Implementation: Support the implementation and operation of security controls across cloud environments (AWS/Azure) and operating systems (Linux/Windows).
- Vendor & Third-Party Risk: Conduct security assessments of third-party vendors and external software components to ensure alignment with internal security baselines.
- Advisory & Collaboration: Act as a trusted security partner for engineering and infrastructure teams, providing technical security guidance and fostering a strong security culture.
Looking to advance your Cyber Security career with relocation support? Explore Cyber Security Jobs with Relocation Packages that include comprehensive packages to help you move and settle in your new role.
Qualifications & Requirements:
- 5–10 years of hands-on experience in Product Security, Application Security, Software Engineering, or Security Architecture.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related technical discipline.
- Strong code literacy with hands-on development or code review experience in at least one key language: Python, C++, Rust, Go, or Java/Kotlin.
- Proven experience in threat modeling methodologies, application vulnerability assessment, and architectural reviews (moving away from purely offensive pen testing).
- Hands-on familiarity securing Linux/Windows environments and practical experience with AWS and/or Microsoft Azure (ideally in hybrid cloud setups).
- Practical experience embedding automated security scanning (SAST/DAST/SCA) into modern CI/CD pipelines.
- Previous exposure to low-latency, performance-sensitive systems, financial services, or quantitative trading environments is highly desirable.
- Excellent problem-solving abilities, clear technical communication skills, and a collaborative, pragmatic approach to security engineering.
Discover our full range of relocation jobs with comprehensive support packages to help you relocate and settle in your new location.
To Apply:
Please apply directly to this posting or email us your Resume/CV to [email protected]. Due to the high volume of applications, only shortlisted candidates will be contacted.
About PFCC
We partner with the world’s most sophisticated financial institutions to unlock sustainable value. By merging operational excellence with the power of AI and digital transformation, we ensure our clients are equipped to lead, not just keep pace.
Bridging the Gap between Vision and Technical Mastery, we believe that even the most advanced strategy is only as powerful as the people executing it. That is why we specialize in identifying and placing high-calibre technical talent within the world’s premier financial ecosystems. Whether it’s securing mission-critical infrastructure or driving global digital shifts, we connect elite IT professionals with opportunities at global financial leaders.
Similar Jobs
Explore other opportunities that match your interests