Đến nội dung chính
Tuyển Dụng
← RONTECH

Senior Fullstack Developer Java, Golang, Python

RONTECH · Hồ Chí Minh
Ứng tuyển tại trang chính thức ↗
Loại hình
Toàn thời gian
Hình thức
Tại văn phòng
Cấp bậc
Nhân viên
Ngành nghề
CNTT - Phần mềm
Mức lương
Thương lượng
Địa điểm
Not Available, Hồ Chí Minh, Hồ Chí Minh

Tổng quan

  • Full social, health & unemployment insurance
  • Develop backend, frontend, and mobile features for Mobile Device Management (MDM) products, ensuring high-quality code, performance, and security. Contribute to building a competitive MDM product in the Vietnamese market.
  • Develop backend services including device management APIs, policy engines, and command queues.
  • Build web dashboards (Admin Consoles) for MDM administrators.
  • Develop mobile agent applications on Android and/or iOS for managed devices.
  • Implement MDM features such as remote lock/wipe, kiosk mode, and app blacklisting/whitelisting.
  • Contribute to device security flows: enrollment, attestation, key provisioning, and certificate lifecycle (under Tech Lead guidance).
  • Write unit and integration tests to ensure code coverage meets requirements.
  • Participate in code reviews and contribute to architectural and procedural improvements.
  • Fix bugs, optimize performance, and resolve technical debt.
  • Stay updated with Android Enterprise, Apple MDM protocol, and SCEP/DEP.
  • Your Skills and Experience

Yêu cầu

  • 1. Education
  • Bachelor's degree in IT, Computer Science, Information Security, or equivalent.
  • 2. Experience
  • 3–5 years of experience in software development. Prior experience in mobile development or device security products is preferred.
  • 3. Technical Skills
  • a) Software Development
  • Backend: Golang, Java, Node.js or Python; RESTful API, SQL/NoSQL databases.
  • Frontend: React.js or Vue.js, TypeScript, responsive design.
  • Mobile: Android (Kotlin/Java) or iOS (Swift); React Native is a plus.
  • Cloud: AWS basic (EC2, S3, Lambda), Firebase Cloud Messaging.
  • Tools: Git, Docker, CI/CD, Agile/Scrum.
  • b) Hardware Security & Trusted Execution
  • Working knowledge of on-device security chips/environments and how to use them in real-world applications (deep expertise in all platforms is not required):
  • Basic understanding of SEP, key generation/storage via Secure Enclave–backed keys, biometric-bound keys, and Keychain access control.
  • Use Android Keystore with StrongBox, understand differences between software, TEE-backed, and StrongBox-backed keys; familiarity with Key Attestation.
  • Familiarity with PCRs, sealed storage, remote attestation, and EK/AIK; able to learn on the job for desktop agent work.
  • Familiarity with HSM / cloud KMS concepts; integration experience (AWS KMS, GCP KMS, Azure Key Vault, or PKCS#11) is a plus.
  • Understand Root of Trust, Secure Boot, Verified Boot, and attestation concepts.
  • c) Cryptography & Applied Cryptography
  • Understand and correctly use common cryptographic algorithms for each problem; designing cryptographic protocols from scratch is not required:
  • AES-128/256 with GCM, CBC, CTR modes; avoid nonce reuse and padding oracles; familiarity with ChaCha20-Poly1305.
  • RSA (PKCS#1 v1.5, OAEP, PSS) ≥ 2048 bits; understand why RSA-PSS is preferred for signatures.
  • ECDSA, EdDSA (Ed25519), ECDH/X25519 over NIST and Curve25519; understand why ECC is preferred on mobile.
  • SHA-2, SHA-3, HMAC; KDFs such as HKDF, PBKDF2, Argon2, scrypt.
  • Awareness of ML-KEM (Kyber), ML-DSA (Dilithium), and post-quantum trends is a plus.
  • Use well-vetted libraries (Tink, libsodium, BoringSSL, BouncyCastle, JCA/JCE, CryptoKit); never roll custom cryptography.
  • d) Data Encryption & Digital Signatures
  • Able to implement common data protection mechanisms in MDM products following the Tech Lead's design:
  • FDE, FBE on Android, FileVault/APFS, envelope encryption (DEK/KEK) at the implementation level.
  • TLS 1.2/1.3, mTLS between MDM server and agent, certificate pinning, OCSP stapling, HSTS; aware of common attacks.
  • X.509, CSR, certificate chain validation, OCSP/CRL, SCEP, EST, ACME at the usage level.
  • Sign and verify commands/policies, APK/IPA signing & verification, JWT/JWS for API authentication.
  • Understand key lifecycle and separation of signing keys from encryption keys.
  • Familiarity with FIPS 140-2/140-3, NIST SP 800-series, and Vietnamese cryptographic regulations is a plus.
  • 4. Soft Skills
  • High level of autonomy and proactive problem-solving.
  • Eagerness to learn and stay updated with new technologies.
  • Strong collaboration skills and willingness to support teammates.
  • Security mindset — ability to think like an attacker.
  • English reading comprehension for technical documentation.

Quyền lợi

  • Negotiable based on capability
  • Full Social, Health, and Unemployment Insurance.
  • Other benefits to be discussed during the interview.
  • Monday – Friday, 8:00 AM – 5:00 PM.
Chế độ thưởngĐào tạo

Tóm tắt thông tin từ tin tuyển dụng chính thức. Xem bản gốc ↗

Quan tâm đến vị trí này?

Bạn sẽ được chuyển đến trang ứng tuyển chính thức của nhà tuyển dụng.

Ứng tuyển tại trang chính thức ↗
Đây là doanh nghiệp của bạn? Nhận quản lý trang, yêu cầu chỉnh sửa hoặc gỡ bỏ
→