Himalayas logo
CXM Direct LLCCL

Web Application Security Engineer

CXM Direct is a prominent player in the global forex and CFD trading industry, established in 2015.

CXM Direct LLC

Employee count: 51-200

Hong Kong only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Position Overview

We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.

This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.

Core Responsibilities

Offensive Security (Penetration Testing)

The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.

You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL/TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.

Defensive Security (Blue Team Operations)

On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.

You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.

Purple Team Collaboration

As a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.

You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.

Security Integration and Automation

You will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.

Requirements

Required Qualifications

  • Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
  • ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
  • Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
  • Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
  • Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
  • Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
  • Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF/IPS
  • Hands-on experience configuring and tuning web application firewalls and deep packet inspections

Preferred Qualifications

Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.

Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.

Benefits

Competitive Compensation

Medical

Gym Allowance

Company Events

Personal Growth

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level
Senior

Location requirements

Hiring timezones

Hong Kong +/- 0 hours

About CXM Direct LLC

Learn more about CXM Direct LLC and their company culture.

View company profile

CXM Direct is a prominent player in the global forex and CFD trading industry, established in 2015. As part of our mission, we offer reliable trading solutions tailored to both retail and institutional clients. At CXM Direct, we leverage cutting-edge technology to empower traders with a seamless trading experience. Our expert team consists of seasoned professionals with decades of experience in the Asia Pacific, US, and European markets.

We take pride in our diverse range of trading instruments, which includes currency pairs, indices, commodities, and cryptocurrencies. This breadth of options allows our customers to build diverse portfolios and manage their trading strategies effectively. Notably, we offer swap-free trading options, competitive spreads, and significant leverage, enabling traders to maximize their potential. With a focus on customer service and satisfaction, we maintain strong relationships with tier-one liquidity providers to guarantee our clients benefit from deep liquidity pools. Our goal is to create an optimal trading environment that helps our clients achieve their financial objectives.

Claim this profileCXM Direct LLC logoCL

CXM Direct LLC

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

3 remote jobs at CXM Direct LLC

Explore the variety of open remote roles at CXM Direct LLC, offering flexible work options across multiple disciplines and skill levels.

View all jobs at CXM Direct LLC

Remote companies like CXM Direct LLC

Find your next opportunity by exploring profiles of companies that are similar to CXM Direct LLC. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
CXM Direct LLC hiring Web Application Security Engineer • Remote (Work from Home) | Himalayas