

Search by job, company or skills

Location: Kuala Lumpur, Malaysia
Role: Application Security Engineer
Department: Backend
About Respond.io
Founded in Hong Kong in early 2017, respond.io is an AI-powered business messaging platform that helps companies manage customer conversations across chat, calls and email — all in one place.
Trusted by businesses in over 127 countries and recognized by G2 and SME100, respond.io enables fast-growing companies around the world to capture, convert, and retain customers at scale.
We operate as a globally distributed team with employees based around the world, contributing to a diverse and inclusive culture. Join us, and be part of a team that is shaping the future of customer conversation management!
Our Culture
At respond.io, we move fast, work smart, and always keep our customers at the heart of what we do. Here's what we stand for:
Role Description
At respond.io, security is a platform engineering discipline, not a gate. Our security team builds Secure SDLC capabilities (Software supply-chain security, AI-assisted SAST, Security automation and AppSec perimeter controls) so developers can ship secure software fast.
We're hiring an Application Security Engineer to own two problems that define modern product security: the security of the code we write, and the security of the code we depend on. That means threat modeling across application and infrastructure, running a SAST pipeline that surfaces real vulnerabilities instead of noise, and securing everything that enters our build, from dependencies to IDEs and container images to CI/CD pipelines, prioritized by what's actually exploitable.
This is a hands-on engineering role. You'll build the tooling and guardrails that prevent entire classes of vulnerabilities, own vulnerability management from detection through verified remediation and act as technical first responder when incidents happen.
Key Responsibilities
What We're Looking For
What's in it for you
Job ID: 153237377
Skills:
AWS, Python, Identity And Access Management, PowerShell, Microsoft Intune, Logic Apps, KQL, Microsoft Defender, conditional access
Skills:
Java, Spring Boot, Node.js, Jenkins, Application Security, Sonarqube, Owasp Top 10, CI CD integration, Go, Snyk, SANS Top 25, GitLab CI, GitHub Actions
Skills:
threat modeling , Spring Boot, Java, Node.js, Owasp Top 10, Jenkins, DAST, SCA, GitHub Actions, GitLab CI, Go, SANS Top 25, SAST
Skills:
.NET, Java, Fortify, DAST, Javascript, Azure DevOps, Burp Suite, Saml, Sonarqube, Oauth, Kubernetes, Python, Owasp Top 10, Docker, Jenkins, SCA, WhiteSource, Snyk, GitLab CI, Checkmarx, OWASP Dependency-Check, openid, OWASP ZAP, REST API security, SAST