Search by job, company or skills

Senior Application Security Engineer

Early Applicant
  • Posted 7 months ago
  • Be among the first 10 applicants

Job Description

We are looking for a Senior Application Security Engineer who builds secure development workflows, integrates security into CI/CD pipelines, and works hands-on with engineers to prevent critical vulnerabilities before code reaches production.

This role is for a builder who understands how applications fail, and uses that insight to engineer scalable, automated defenses across the SDLC.

Not SOC

Not compliance-only

Not a pentest role

Hands-on AppSec engineering

What You'll Do:

Threat Modeling

  • Lead threat modeling and design reviews for critical banking features (Payments, Transfers, KYC).
  • Identify business logic and architectural risks early — before implementation.

Secure SDLC & Pipeline Automation

  • Design, integrate, and maintain SAST / DAST / SCA controls in CI/CD pipelines.
  • Engineer guardrails that **block vulnerabilities automatically**, not just report them.
  • Ensure security tools are tuned for signal, not noise.

Hands-On Code Security

  • Perform manual code reviews on high-risk components (authentication flows, ledger logic, sensitive services).
  • Work directly with developers to remediate issues with secure design patterns.

Secure Platform & Cloud Patterns

  • Deliver secure-by-default templates (paved roads) for APIs, microservices, containers, cloud workloads, and AI-enabled services.
  • Enable teams to deploy securely without slowing delivery.

Security Enablement & Culture

  • Mentor engineers on secure coding practices.
  • Support and grow a Security Champion culture across engineering teams.

What We're Looking For:

  • Bachelors Degree in Computer Science or equivalent field.
  • 5+ years of Application Security experience, with a background in software development.
  • Strong understanding of secure coding principles and application failure modes.
  • Proficiency in at least one backend language: Java (Spring Boot), Node.js, or Go
  • Hands-on experience integrating security tools into CI/CD pipelines (e.g. GitHub Actions, Jenkins, GitLab CI).
  • Solid knowledge of OWASP Top 10 and SANS Top 25 (applied in real systems, not just theory).
  • Comfortable reviewing production code and discussing trade-offs with engineers.

Why This Role:

  • Shape how secure software is built across a digital bank.
  • Prevent vulnerabilities at scale, not one finding at a time.
  • Work closely with strong engineering teams.
  • High ownership, real impact on critical financial systems.

Good Fit If You Are:

  • A security engineer who codes or reviews code regularly.
  • Interested in **preventing vulnerabilities**, not just detecting them.
  • Comfortable influencing developers through engineering, not enforcement.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 138318505

Similar Jobs

Malaysia, Kuala Lumpur

Skills:

threat modeling MetasploitTerraformSonarqubeAWSCloudformationNmapPenetration TestingJenkinsBurp SuiteDevSecOpsVulnerability AssessmentsOwaspAzureSSDFAzure Key VaultSecure Code ReviewsGitHub ActionsTrivyProwlerpacuScoutSuiteGitLab CICloud Security AssessmentsnistInfrastructure-as-CodeCheckmarxSemgrep

Beware of Scammers

We don’t charge money for job offers