Senior Software Engineer-Security
Location: Kuala Lumpur, Malaysia
Years of Experience: 5+ Years
Job Summary: We are seeking a highly skilled Senior Security Engineer with a strong background in application security to join our team. The ideal candidate will possess extensive knowledge in performing Vulnerability Assessments and Penetration Testing (VAPT), executing Red Team engagements, and integrating DevSecOps practices into CI/CD pipelines. This role requires collaboration with cross-functional teams to enhance security measures and ensure compliance with industry standards.
Responsibilities
- Perform comprehensive Vulnerability Assessments and Penetration Testing (VAPT) across web applications, APIs, cloud environments, and enterprise infrastructure to identify and mitigate security risks.
- Execute Red Team engagements by emulating real-world adversary tactics using the MITRE ATT&CK framework to evaluate organizational security posture and detection capabilities.
- Integrate DevSecOps practices into CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, Checkmarx, SonarQube, Trivy, and Semgrep, enabling automated SAST, DAST, SCA, and secrets scanning.
- Conduct threat modeling, secure code reviews, and infrastructure-as-code assessments for Terraform and CloudFormation, ensuring secure cloud deployments and compliance with security standards.
- Perform cloud security assessments across Azure and AWS environments, implementing secure secrets management with Azure Key Vault and strengthening cloud security controls.
- Collaborate with developers, architects, and security teams to perform root cause analysis, recommend remediation strategies, and enhance secure application development practices.
- Produce detailed technical reports, risk assessments, and executive-level security findings with actionable remediation recommendations aligned with OWASP, NIST, and SSDF frameworks.
- Leverage expertise in offensive security tools including Burp Suite, Nmap, Metasploit, ScoutSuite, Prowler, and Pacu, while maintaining an OSCP-certified approach to continuous security improvement and proactive threat defense.
Mandatory Skills
- Strong knowledge of application security principles and practices.
- Experience with Vulnerability Assessments and Penetration Testing (VAPT).
- Proficiency in using offensive security tools such as Burp Suite, Nmap, and Metasploit.
- Hands-on experience with cloud security assessments in Azure and AWS.
- Familiarity with the MITRE ATT&CK framework.
Preferred Skills
- Experience with DevSecOps practices and CI/CD pipeline integration.
- Knowledge of secure coding practices and threat modeling.
- Familiarity with infrastructure-as-code tools like Terraform and CloudFormation.
- Understanding of security frameworks such as OWASP, NIST, and SSDF.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 5+ years of experience in security engineering or a related role.
- OSCP certification or equivalent is highly desirable.
If you are passionate about security and have the required skills, we encourage you to apply and join our dynamic team in Kuala Lumpur.
Application Security, Vulnerability Assessment