12 часов назад
Application Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (Node.js/AWS): Building Secure SDLC capabilities and application security controls across software supply chains, CI/CD, cloud infrastructure, and application code with an accent on threat modeling, AI-assisted SAST, vulnerability management, and edge protection. Focus on tracing vulnerabilities to root cause, prioritizing exploitable risks, hardening GitHub and AWS environments, and responding to application security incidents.
Location: Kuala Lumpur, Malaysia
Company
is an AI-powered business messaging platform for managing customer conversations across chat, calls, and email.
What you will do
- Own software supply-chain security across Node ecosystems, including dependency, open-source license, SCA, and container image scanning in CI/CD.
- Run threat modeling, tune AI-assisted SAST pipelines, and coordinate penetration tests from scoping through remediation and retesting.
- Secure GitHub organizations and AWS infrastructure through secret scanning, hardened CI/CD workflows, IAM least privilege, and threat detection.
- Triage security signals and improve endpoint detection capabilities.
- Tune AWS WAF and Network Firewall policies to protect against DDoS, injection attacks, bots, and malicious traffic.
- Build security tooling and act as the primary technical responder for application security incidents.
Requirements
- 3+ years of experience in application security with strong AppSec fundamentals.
- Ability to read Node.js and JavaScript code, trace vulnerabilities to their root cause, and validate fixes.
- Experience with dependency, license, and container scanning tools such as Socket.dev, Dependabot, Trivy, or Semgrep.
- Experience with threat modeling, penetration test coordination, GitHub security, and hardened CI/CD workflows.
- Experience with AWS security services including GuardDuty, Inspector, Detective, CloudTrail, WAF, and Network Firewall.
- Ability to build security tools, scanners, or CI plugins with Python, TypeScript, or Bash, and explain risks clearly in plain English.
Culture & Benefits
- Globally distributed and collaborative working environment.
- Flexible working environment and working hours.
- Competitive compensation package.
- Mental health allowance.
- Virtual social events and online game sessions.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →