Application Security Engineer
ModeFairAbout the role
Overview:
We are on the lookout for a dedicated individual with a keen interest in application security and the competencies required to ensure our business applications are safeguarded against known security vulnerabilities and logic flaws. This role offers the chance to collaborate with our full stack engineers to bolster the security of our software applications and services at various stages of the software development lifecycle.
Location: Work From Home (reside in Kuala Lumpur or Selangor).
Employment Type:
This is a full-time position under direct company payroll.
We are not considering part-time, contract, freelance candidates, or recruitment agency submissions for this role.
Why Consider This Role:
Starting salary range is RM7,000 - RM10,000.
For experienced Application Security Specialists, we are willing to negotiate.
Excel in work, earn A+ in 2-3 years with our salary booster program.
Responsibilities:
Tasked with recommending and integrating security best practices within the software development lifecycle to guarantee that applications are delivered free from security vulnerabilities, threats and risks effectively addressed.
Develop and implement secure application development strategies, standards, and guidelines to enhance the organization's Application Security standards.
Conduct Application Security evaluations through source code reviews, static code analysis, threat modeling, vulnerability research, code scanning, and security testing, along with providing recommendations for effective remediation measures. (e.g., penetration testing)
Collaborate closely with the Engineering division to address vulnerability mitigations and assist in eliminating false positives from static and dynamic security reports.
Participate in our project sprints to guarantee that security measures are integrated into every release cycle.
Introduce or upgrade our CI/CD pipeline by incorporating tools and automation techniques to bolster the security of our applications.
Identify and address security gaps, and refine security protocols and procedures in the application development workflow.
Boost the security knowledge among development teams by implementing secure coding training platforms.
Foster awareness and facilitate code review sessions with Engineers, providing training on security standards, policies, and best practices with an emphasis on secure coding practices for Web and Mobile Applications.
Guide junior engineers in application security and penetration testing best practices, aiding their development and team integration.
Key Qualifications:
A Bachelor's degree in computer science, cybersecurity, or a related discipline.
Malaysian nationality is a prerequisite.
Minimum of 2 years' experience in relevant fields.
Experience in application source code review (e.g., Java), penetration testing and ethical hacking.
Experience in using popular penetration testing tools and frameworks such as Metasploit, Nmap, Burp Suite, Kali Linux, etc.
Good foundation on different operating systems, networks, protocols, and applications, with particular emphasis on Linux servers, etc.
Proficiency in at least one programming language, such as Java, Kotlin, TypeScript.
Creative problem-solving abilities with a knack for bypassing security measures and defenses.
Strong analytical and critical thinking skills.
Knowledge of cloud security principles and experience securing applications hosting on cloud environments (e.g., AWS) including the use of cloud-native security tools.
Keep abreast of the latest trends in application security, including vulnerabilities affecting applications and servers.
Work From Home Requirements:
Due to the sensitive nature of this role, candidates must ensure a stable and secure internet connection at home. This is crucial for maintaining confidentiality and integrity while handling security-related tasks remotely.
The company will provide a laptop for work purposes.
Attendance Obligations:
Candidates must be willing to actively participate in company activities on a quarterly basis.
Attendance at important physical meetings is mandatory, and candidates are expected to attend without exception, regardless of whether they work from home or their location within Malaysia.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s