Назад
Company hidden
12 часов назад

Application Security Engineer

Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Malaysia/China
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Node.js/AWS): Building Secure SDLC capabilities and application security controls across software supply chains, CI/CD, cloud infrastructure, and application code with an accent on threat modeling, AI-assisted SAST, vulnerability management, and edge protection. Focus on tracing vulnerabilities to root cause, prioritizing exploitable risks, hardening GitHub and AWS environments, and responding to application security incidents.

Location: Kuala Lumpur, Malaysia

Company

hirify.global is an AI-powered business messaging platform for managing customer conversations across chat, calls, and email.

What you will do

  • Own software supply-chain security across Node ecosystems, including dependency, open-source license, SCA, and container image scanning in CI/CD.
  • Run threat modeling, tune AI-assisted SAST pipelines, and coordinate penetration tests from scoping through remediation and retesting.
  • Secure GitHub organizations and AWS infrastructure through secret scanning, hardened CI/CD workflows, IAM least privilege, and threat detection.
  • Triage security signals and improve endpoint detection capabilities.
  • Tune AWS WAF and Network Firewall policies to protect against DDoS, injection attacks, bots, and malicious traffic.
  • Build security tooling and act as the primary technical responder for application security incidents.

Requirements

  • 3+ years of experience in application security with strong AppSec fundamentals.
  • Ability to read Node.js and JavaScript code, trace vulnerabilities to their root cause, and validate fixes.
  • Experience with dependency, license, and container scanning tools such as Socket.dev, Dependabot, Trivy, or Semgrep.
  • Experience with threat modeling, penetration test coordination, GitHub security, and hardened CI/CD workflows.
  • Experience with AWS security services including GuardDuty, Inspector, Detective, CloudTrail, WAF, and Network Firewall.
  • Ability to build security tools, scanners, or CI plugins with Python, TypeScript, or Bash, and explain risks clearly in plain English.

Culture & Benefits

  • Globally distributed and collaborative working environment.
  • Flexible working environment and working hours.
  • Competitive compensation package.
  • Mental health allowance.
  • Virtual social events and online game sessions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →