jobs in Provido Global

全职 Application Security Manager 工作, 薪水, Provido Global Federal Territory 公司招聘中 - Ricebowl

Application Security Manager

Provido Global

Undisclosed

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

At Provido Global, we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence.

Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world.

As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact.
If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here.

Why We Need You

Application Security Manager is responsible for defining, implementing, and leading the application security program across the organization's products, platforms, and software development lifecycle.

This role drives secure software development practices, threat modeling, secure code review, application vulnerability management, and security testing across web, mobile, API, and client and server applications.

The Lead partners closely with engineering, DevOps, product, and development teams to embed security into the SDLC, mature DevSecOps tooling and automation, and reduce application-layer risk across the organization's customer-facing and internal applications.

The role is based on-site in Kuala Lumpur and requires strong technical depth in application security, hands-on engineering credibility, and the ability to influence engineering leaders, technology teams and business stakeholders.

What You’ll Be Doing

  • Lead the application security program by setting strategy, standards, secure coding guidelines, and policies covering web, mobile, API, and application security across the organization.

  • Drive threat modeling, architecture security reviews, and secure design consultations for new products, digital services, platforms, and customer-facing features.

  • Own the application security testing toolchain — SAST, DAST, SCA, IAST, secrets scanning, and fuzz testing — and integrate it into CI/CD pipelines across engineering and studio teams.

  • Manage the application vulnerability lifecycle, including triage, prioritization, remediation tracking, SLA enforcement, and reporting to engineering leadership and executive stakeholders.

  • Lead manual secure code reviews, coordinate penetration testing engagements, and operate the bug bounty program, validating findings and driving remediation with development teams.

  • Build and deliver secure coding training, developer enablement programs, and security champions networks across engineering and development organizations.

  • Partner with DevOps and platform teams to harden build pipelines, container images, cloud-native workloads, and backend services against application-layer attacks.

  • Maintain awareness of application security threats and trends affecting the technology organizations, and Southeast Asia regulatory expectations relevant to the organization.


What You Bring to the Team

  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or a related discipline.

  • 5+ years of experience in application security, product security, or secure software engineering, including at least 2 years in a lead or senior individual contributor capacity.

  • Strong understanding of common application vulnerabilities (OWASP Top 10, OWASP API Top 10, OWASP Mobile Top 10), exploitation techniques, and defensive coding patterns.

  • Hands-on experience with SAST, DAST, SCA, and IAST tooling and their integration into CI/CD pipelines (e.g., Checkmarx, Veracode, Snyk, Semgrep, Burp Suite, OWASP ZAP).

  • Proficiency in at least one modern programming language (C#, C++, Java, Go, Python, JavaScript/TypeScript) and the ability to read and review code across multiple technology stacks.

  • Availability to work on-site in Kuala Lumpur and support occasional out-of-hours engagement with global engineering teams across time zones.


Preferred Skills

  • Professional certifications such as OSCP, OSWE, GWAPT, GMOB, CSSLP, CISSP, Burp Suite Certified Practitioner, or equivalent application security credentials.

  • Experience securing interactive digital products, including client-server architectures, real-time services, or user abuse prevention.

  • Experience with cloud-native application security on AWS, Azure, or GCP, including Kubernetes, serverless, and container security.

  • Familiarity with threat modeling methodologies (STRIDE, PASTA, attack trees) and security architecture review practices at scale.

  • Knowledge of OWASP SAMM, BSIMM, NIST SSDF, or similar secure software development maturity frameworks.

  • Understanding of compliance-focused environments and the importance of documented analysis, control adherence, secure SDLC governance, and audit support.


Why You’ll Love Working with Us

  • Employee Benefits & Advantages

At Provido Global, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment.

  • Competitive Compensation & Performance Incentives
Provido Global offers an attractive salary package and performance-based bonuses to recognize and reward your contribution.
  • Flexible Working Options
We support remote and hybrid working models to help you maintain a healthy work-life balance.
  • Health & Well-being Support
We provide comprehensive health insurance, wellness initiatives, and resources to support both physical and mental well-being.
  • Career Advancement & Development Programs
We invest in continuous learning through training programs, mentorship, and clearly defined career development paths.
  • Team-Oriented & Inclusive Workplace
Our culture is built on diversity, inclusion, and collaboration. Every voice matters and innovation is encouraged.
  • Team Events & Social Activities
We organize regular team-building activities and social events to strengthen relationships and create a positive, connected workplace.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多