Jobs and Careers
MO

Senior Security Engineer (Code Review & Pentest)

ModeFair
ModeFair HQ, United Statesfull_timeVerifiedPosted 29 Feb 2024

About the role

Overview:

We are seeking a highly skilled and motivated Senior Security Engineer with a specialization in code reviews and penetration testing to join our Security division. This is an internal role focused on meticulously testing our projects to identify and mitigate security vulnerabilities. Ideal candidates will have a strong background in conducting security code reviews for languages such as Java, and integrating these reviews as part of the software development sprints. Successful candidate will play a crucial role in ensuring the security of our applications through comprehensive assessments, the development of custom tools if necessary, and collaboration with our Engineering division. This senior position is vital for maintaining the integrity and resilience of our systems against cybersecurity threats, thereby safeguarding our data and our customer's trust.

Location: Work From Home (reside in Kuala Lumpur or Selangor)

Employment Type:

  • This is a full-time position under direct company payroll.

  • We are not considering part-time, contract, freelance candidates, or recruitment agency submissions for this role.

Why Consider This Role:

  • Seeking Strong Candidates: Salary Negotiable!

  • Excel in work, earn A+ in 2-3 years with our salary booster program

Key Qualifications:

  • Degree in Cybersecurity, Computer Science, Information Security, or a related field.

  • Malaysian nationality is a prerequisite.

  • Experience working with reputable cybersecurity companies, within the Big 4, or in large organizations that place a high emphasis on security, code reviews and penetration testing is highly desirable. We value professionals who have been exposed to advanced cybersecurity practices and have actively contributed to security projects in environments where security is a critical component of the operational framework.

  • While a minimum of three years of hands-on experience in source code review is required, proficiency in Java is a must, with experience in additional languages such as Kotlin, TypeScript, Swift, etc., being highly advantageous. Candidates with more years of experience will be preferred, particularly those with a strong background in security code reviews and penetration testing.

  • Familiarity with security tools and frameworks (e.g., Metasploit, Burp Suite, OWASP ZAP)

  • Awareness of security standards and frameworks (e.g., OWASP Top 10, SANS Top 25) is advantageous.

  • An understanding of AWS security practices, including securing applications and hosts within the AWS ecosystem, is highly valued.

  • Strong problem-solving and analytical skills.

  • Good communication and reporting skills.

  • Ability to mentor and guide junior team members, helping them overcome technical challenges and grow professionally.

  • Certifications in cybersecurity (e.g., OSCP, GWAPT, CEH) are a plus but not required.

Work From Home Requirements:

  • Due to the sensitive nature of this role, candidates must ensure a stable and secure internet connection at home. This is crucial for maintaining confidentiality and integrity while handling security-related tasks remotely.

  • The company will provide a laptop for work purposes.

Attendance Obligations:

  • Candidates must be willing to actively participate in company activities on a quarterly basis.

  • Attendance at important physical meetings is mandatory, and candidates are expected to attend without exception, regardless of whether they work from home or their location within Malaysia.

Responsibilities:

  • Perform code reviews and static code analysis to detect security flaws.

  • Conduct comprehensive penetration tests on our applications, identifying vulnerabilities and security issues.

  • Develop and utilize custom tools and scripts to automate security testing processes.

  • Collaborate with the Engineering division to understand application functionalities and architecture.

  • Provide actionable insights and recommendations to remediate identified vulnerabilities.

  • Develop and enforce application security best practices and policies.

  • Conduct security assessments and reviews during the pre-deployment phase of our development cycle.

  • Evaluate and strengthen the security settings for applications hosting at our infrastructure, including both local data centers and public cloud environments like AWS. This includes regular security audits, configuration reviews,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ModeFair

View company profile →