7 часов назад
Senior Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Application Security): Securing applications and infrastructure through vulnerability analysis, remediation management, and security automation with an accent on SAST/DAST, CI/CD integration, and risk-based prioritization. Focus on conducting source-code reviews, driving vulnerability resolution, managing bug bounty reports, and applying scripting and AI/ML tooling to reduce security risk.
Location: Bangkok, Thailand; hybrid workplace
Company
operates global B2B payment and digital commerce solutions, consumer storefronts, and digital content distribution services across more than 70 markets.
What you will do
- Partner with engineering teams to build products securely by default and manage security audits and remediation.
- Conduct risk assessments, vulnerability analyses, and scanning across networks, systems, middleware, databases, and application architectures.
- Manage the vulnerability remediation lifecycle using risk-based prioritization and industry standards.
- Implement and manage SAST and DAST in CI/CD pipelines, perform source-code security reviews, and advise developers on remediation.
- Manage externally reported vulnerabilities and bug bounty submissions.
- Lead application and infrastructure risk-reduction initiatives using automation and AI/ML tooling where appropriate.
Requirements
- 5+ years of cybersecurity experience, including 3+ years focused on vulnerability management.
- 3+ years of hands-on software development and scripting with Java, Node, and Python.
- Ability to write scripts and simple web applications to address security needs.
- Solid foundations in networking, operating systems, and applications.
- Experience independently identifying risks, taking ownership, and driving remediation to completion.
- Strong stakeholder management and communication skills with technical and non-technical audiences.
Nice to have
- Experience building internal security tools, dashboards, or CI/CD integrations.
- Experience with bug bounty programs, penetration testing, and vulnerability assessment.
- Knowledge of cloud security, container security, AI security, DevSecOps, and CI/CD security tools.
- Relevant security certifications such as OSCP, OSWE, cloud security certifications, GPEN, or CREST.
- Experience in a technology or financial services company.
Culture & Benefits
- Permanent employment in a global organization with employees from 57 nationalities across 23 locations.
- Culture focused on respect, ownership, collaboration, and taking initiative.
- Opportunity to work with global payment, digital commerce, and content distribution products.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 часа назад
Application Security Engineer (Cybersecurity)
8 часов назад
Senior Application Security Engineer (Software Supply Chain)
4 часа назад
Senior Application Security Engineer (SCA/SAST)
15 часов назад
Security Software Developer (Cybersecurity)
5 часов назад
Software Engineer (Cybersecurity)
5 часов назад