- Jalan PJU 7/24 Petaling Jaya Selangor Malaysia 47810

Working Location
Job Description
Requirements
5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.
Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.
Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
Familiarity with Kubernetes and containerized application environments is a bonus.
Responsibilities
Vulnerability Remediation:
Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).
Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
Build lightweight internal tooling/scripts to help automate triage, tracking, or reporting of vulnerability and posture data where useful (e.g., feeding dashboards, Jira, or a reporting tool).
Benefits
Skills
TAMAN JAYA
0.3 km
ASIA JAYA
1.1 km
UNIVERSITI
2.0 km
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.