freehire launches on Product Hunt on 26 August.

Follow →

Cybersecurity Engineer (Security Operations) - Junior

Summary

Junior cybersecurity engineer at Xiaomi, managing WAF/IDS systems, API security, and vulnerability response to protect global web/mobile apps and ensure compliance with GDPR and PDPA.

Job Summary

Manage and enhance Xiaomi’s international security systems, lead API security framework development, oversee vulnerability management, and ensure compliance with global data protection regulations to safeguard web and mobile applications.

Responsibilities

  • Manage the full lifecycle of core security solutions (WAF, MiShield, HIDS) for Xiaomi’s international business, including configuring policies, optimizing rules, and expanding coverage to protect web and mobile applications against threats such as OWASP Top 10
  • Develop real-time monitoring and alerting frameworks to analyze security logs, detect anomalous traffic and attacks, produce root-cause analysis reports, and improve defense strategies
  • Contribute to the design and implementation of an API security framework for international operations, creating models for abnormal behavior detection and access control to prevent unauthorized data access and API abuse
  • Integrate API security with gateways and microservices, incorporate SAST/DAST tools to promote shift-left security practices, and establish developer security guidelines
  • Oversee vulnerability management processes including scanning, risk assessment, and remediation for international business, implementing high-risk vulnerability response mechanisms and collaborating with R&D teams on code-level fixes
  • Monitor global threat intelligence and zero-day vulnerabilities, organize red/blue team exercises, and refine emergency response protocols
  • Ensure security operations comply with regional regulations such as GDPR and Singapore PDPA, preparing compliance audit reports
  • Collaborate with international business units, local compliance teams, and third-party vendors to provide security technical support and training

Required competencies and certifications

  • Bachelor’s degree or higher in Computer Science, Information Security, or related field
  • Expertise in operating security products such as WAF and IDS
  • Proficiency in API security design and protection, including knowledge of OWASP API Top 10 and gateway security policy deployment
  • Familiarity with vulnerability management tools and processes (e.g., Nessus, Burp Suite), with ability to reproduce vulnerabilities and validate remediation
  • Proficiency in scripting languages like Python and Shell
  • Knowledge of international data security regulations and compliance requirements
  • Ability to communicate effectively in English and Mandarin to support collaboration with Mandarin-speaking stakeholders, regional customers, engineering teams, and colleagues based in China.

Preferred competencies and qualifications

  • Experience in developing security automation tools
  • Professional certifications such as CISSP or CSSLP

See also