jobs in Happiest Minds Technologies

全职 SENIOR SOFTWARE ENGINEER - Application Security 工作, 薪水, Happiest Minds Technologies Federal Territory 公司招聘中 - Ricebowl

SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies

Undisclosed

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

Application Security - Vulnerability Operations Center

Location: KL

Years of Experience: 5+ Years

Job Summary: We are seeking a skilled Application Security Analyst with a strong background in application security principles and practices. The ideal candidate will possess in-depth knowledge of vulnerability types, risk assessment, and DevSecOps processes. This role requires a proactive individual who can enhance our vulnerability triage operations and collaborate effectively with cross-functional teams to ensure secure application development.

Responsibilities

  • Possess a strong understanding of vulnerability types (OWASP Top 10, CWE, CVE, misconfiguration, insecure API) and clearly explain common attack techniques.
  • Demonstrate capability in vulnerability prioritization based on exploitability, asset criticality, and business context.
  • Uplift DevSecOps vulnerability triage operations to enhance effectiveness and efficiency.
  • Perform manual and semi-automated triage of vulnerability findings, providing expert judgment on severity, exploitability, and business impact.
  • Conduct false positive analysis, de-duplication, and tool output normalization.
  • Provide technical input during project releases to prepare triage readiness.
  • Identify and correlate recurring vulnerability data across projects or business units to observe trends and streamline triage processes.
  • Collaborate with application teams, DevOps, BISOs, and developers to explain vulnerabilities and risks clearly.
  • Participate in security tool PoC/PoV and selection processes.
  • Drive implementation and integration of selected tools into the triage workflow to enhance automation, data accuracy, and analyst efficiency.
  • Design and implement automation workflows for enrichment, de-duplication, and ticketing.
  • Contribute to strategic planning and continuous improvement of VOC capabilities.
  • Prepare documentation and reporting on knowledge base documentation and playbook creation, maintaining accurate records of analysis, risk decisions, and triage actions.
  • Provide guidance to developers and application teams on secure coding best practices.

Mandatory Skills

  • Strong knowledge of security standards, CVSS scoring, EPSS, CWE, CVE, KEV database, and MITRE ATT&CK.
  • Experience with CVSS tuning, exploit intelligence, and SLA tagging.
  • Familiarity with exploitation techniques, including SQL injection, XSS, CSRF, SSRF, and RCE.
  • Proficiency in one or more scripting languages (JavaScript, Python, PowerShell, Bash) and automation platforms.
  • Advanced knowledge of vulnerability assessment tools and threat modeling.
  • Strong analytical and communication skills, with excellent stakeholder communication and incident coordination abilities.
  • Ability to explain technical vulnerabilities clearly to developers and other stakeholders.
  • Critical thinking skills to trigger deep-rooted problem solving and multi-disciplinary analytical skills.
  • Effective technical writing and documentation skills for SOPs and evaluation reports.

Preferred Skills

  • Experience in a legacy environment with technical debt and internal challenges.
  • Positive mindset for growth and driving change.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in application security or a related field.

Application Security

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多