Full Stack Engineer (Frontend Oriented) - Identity & Security
About the Team
The Identity & Security team owns the front door to Binance. We build and operate the registration, login, and account security experience used by every one of our 300M+ users - social login, OAuth and third-party authorization, multi-factor authentication, passkeys and FIDO2, device management, account activity, and account closure.
We are currently building an in-house AI facial recognition security product for KYC verification and user safety, replacing our existing third-party vendor solution. This is a to-C product serving hundreds of millions of users, directly impacting account security and identity verification experience at scale.
Our work sits where three forces meet: enormous scale, strict security and regulatory constraints, and the reality that one extra verification step can block an attacker or lock out a legitimate user. We ship across web, mobile mini programs, and in-app webviews, and we publish the shared authentication libraries and SDKs that the rest of Binance builds on.
Responsibilities
- Design, develop, and maintain the login, registration, and account security applications across web and mobile clients
- Build the in-house AI facial recognition security product end to end - KYC verification, liveness detection, face matching - replacing the existing third-party vendor solution
- Build authentication capabilities end to end: passkeys / FIDO2 (WebAuthn), authenticator apps, security keys, SMS and email verification, and biometric flows
- Own the multi-factor authentication orchestration layer - verification strategy, step-up logic, and user-level customization - balancing security strength against completion rate with measurable outcomes
- Collaborate closely with the AI algorithm team to integrate facial recognition, liveness detection, and other AI model capabilities into the product frontend and backend, building high-concurrency, low-latency online inference services
- Maintain and evolve the shared security component and logic libraries consumed by multiple product applications, and the authentication SDKs published to teams across the company; take responsibility for bundle size, initialization behavior, and backward compatibility
- Develop and operate the Node.js server-side layer: server-side rendering, route-level authentication guards, session validation and redirects, localized routing, and first-paint performance
- Build and refine the BFF layer - aggregating upstream security services and turning raw error codes into results the frontend can consume and users can act on
- Implement platform-specific behavior for web, mini program, and low-end device targets while keeping shared and platform-specific code cleanly separated
- Drive engineering quality: unit and end-to-end test coverage, instrumentation and observability, build and local development experience
- Use funnel and event data to find drop-off in login and verification flows, and drive optimization from evidence rather than intuition
- Collaborate closely with product, design, risk, customer support, backend, iOS, and Android teams; independently own the end-to-end design and delivery of a sub-domain such as passkeys, MFA orchestration, or facial recognition verification
Minimum qualifications
- Bachelor's or Master's degree in Computer Science, Engineering, or equivalent industry experience
- 3-8 years of frontend or full stack engineering experience, including consumer-facing products taken from zero to one or evolved over multiple years
- Strong web fundamentals: HTML, CSS, JavaScript/TypeScript, browser rendering, networking, caching, and performance optimization
- Deep proficiency in React 18+ and TypeScript, with solid command of state management, data-fetching patterns, and complex multi-step form and flow orchestration
- Production Node.js experience: server-side rendering or isomorphic applications, BFF layering, API aggregation and caching, and the ability to independently debug server-side runtime issues
- A clear methodology for modeling complex flows - authentication and verification are highly branched, stateful, interruptible, and resumable, and need to be abstracted into testable, reusable models rather than nested conditionals
- Solid engineering practice: modular architecture, component design, unit and E2E testing, CI/CD, and responsible judgment on breaking changes to shared libraries (versioning, staged rollout, rollback)
- Proficient with AI-assisted development tools (Cursor / Claude Code / Copilot, etc.) with practical experience incorporating them into daily development workflows
- Strong analytical and troubleshooting skills for diagnosing production issues, compatibility problems, and performance bottlenecks independently
- Fluent in Mandarin, able to collaborate effectively with China-based teams
- Effective communication in English within a distributed, cross-timezone, multi-team environment
Nice to have
- Experience at AI / computer vision companies in business-side frontend or fullstack development
- Hands-on experience in identity and authentication: WebAuthn / FIDO2 / passkeys, TOTP, OAuth 2.0 / OIDC, JWT and token lifecycle management, risk engines, or device fingerprinting
- Experience building to-C security products, identity verification, or KYC-related products
- Experience replacing third-party vendor solutions with in-house systems, ensuring smooth business transition
- Knowledge of AI model engineering: model inference services, RAG systems, AI Agent architecture, or computer vision model integration
- Cross-platform experience: mini programs, hybrid applications, and in-app webview bridging and debugging
- Experience shipping shared component libraries or SDKs to third-party consumers - multi-entry bundling, tree-shaking, semantic versioning, and integration support
- Internationalization and localization at scale: date and number formatting, RTL, and regional compliance differences
- Background in finance, payments, or another high-security domain, with an understanding of the product trade-offs compliance imposes
- Experience with monitoring and alerting, staged rollout, and A/B experimentation
- Docker / Kubernetes / CI-CD pipeline experience