Назад
Company hidden
7 часов назад

Senior Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/Singapore/UAE +3 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Application Security): Securing applications and infrastructure through vulnerability analysis, remediation management, and security automation with an accent on SAST/DAST, CI/CD integration, and risk-based prioritization. Focus on conducting source-code reviews, driving vulnerability resolution, managing bug bounty reports, and applying scripting and AI/ML tooling to reduce security risk.

Location: Bangkok, Thailand; hybrid workplace

Company

hirify.global operates global B2B payment and digital commerce solutions, consumer storefronts, and digital content distribution services across more than 70 markets.

What you will do

  • Partner with engineering teams to build products securely by default and manage security audits and remediation.
  • Conduct risk assessments, vulnerability analyses, and scanning across networks, systems, middleware, databases, and application architectures.
  • Manage the vulnerability remediation lifecycle using risk-based prioritization and industry standards.
  • Implement and manage SAST and DAST in CI/CD pipelines, perform source-code security reviews, and advise developers on remediation.
  • Manage externally reported vulnerabilities and bug bounty submissions.
  • Lead application and infrastructure risk-reduction initiatives using automation and AI/ML tooling where appropriate.

Requirements

  • 5+ years of cybersecurity experience, including 3+ years focused on vulnerability management.
  • 3+ years of hands-on software development and scripting with Java, Node, and Python.
  • Ability to write scripts and simple web applications to address security needs.
  • Solid foundations in networking, operating systems, and applications.
  • Experience independently identifying risks, taking ownership, and driving remediation to completion.
  • Strong stakeholder management and communication skills with technical and non-technical audiences.

Nice to have

  • Experience building internal security tools, dashboards, or CI/CD integrations.
  • Experience with bug bounty programs, penetration testing, and vulnerability assessment.
  • Knowledge of cloud security, container security, AI security, DevSecOps, and CI/CD security tools.
  • Relevant security certifications such as OSCP, OSWE, cloud security certifications, GPEN, or CREST.
  • Experience in a technology or financial services company.

Culture & Benefits

  • Permanent employment in a global organization with employees from 57 nationalities across 23 locations.
  • Culture focused on respect, ownership, collaboration, and taking initiative.
  • Opportunity to work with global payment, digital commerce, and content distribution products.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →