Application Security - Vulnerability Operations Center
Location: KL
Years of Experience: 5+ Years
Job Summary: We are seeking a skilled Application Security Analyst with a strong background in application security principles and practices. The ideal candidate will possess in-depth knowledge of vulnerability types, risk assessment, and DevSecOps processes. This role requires a proactive individual who can enhance our vulnerability triage operations and collaborate effectively with cross-functional teams to ensure secure application development.
Responsibilities
- Possess a strong understanding of vulnerability types (OWASP Top 10, CWE, CVE, misconfiguration, insecure API) and clearly explain common attack techniques.
- Demonstrate capability in vulnerability prioritization based on exploitability, asset criticality, and business context.
- Uplift DevSecOps vulnerability triage operations to enhance effectiveness and efficiency.
- Perform manual and semi-automated triage of vulnerability findings, providing expert judgment on severity, exploitability, and business impact.
- Conduct false positive analysis, de-duplication, and tool output normalization.
- Provide technical input during project releases to prepare triage readiness.
- Identify and correlate recurring vulnerability data across projects or business units to observe trends and streamline triage processes.
- Collaborate with application teams, DevOps, BISOs, and developers to explain vulnerabilities and risks clearly.
- Participate in security tool PoC/PoV and selection processes.
- Drive implementation and integration of selected tools into the triage workflow to enhance automation, data accuracy, and analyst efficiency.
- Design and implement automation workflows for enrichment, de-duplication, and ticketing.
- Contribute to strategic planning and continuous improvement of VOC capabilities.
- Prepare documentation and reporting on knowledge base documentation and playbook creation, maintaining accurate records of analysis, risk decisions, and triage actions.
- Provide guidance to developers and application teams on secure coding best practices.
Mandatory Skills
- Strong knowledge of security standards, CVSS scoring, EPSS, CWE, CVE, KEV database, and MITRE ATT&CK.
- Experience with CVSS tuning, exploit intelligence, and SLA tagging.
- Familiarity with exploitation techniques, including SQL injection, XSS, CSRF, SSRF, and RCE.
- Proficiency in one or more scripting languages (JavaScript, Python, PowerShell, Bash) and automation platforms.
- Advanced knowledge of vulnerability assessment tools and threat modeling.
- Strong analytical and communication skills, with excellent stakeholder communication and incident coordination abilities.
- Ability to explain technical vulnerabilities clearly to developers and other stakeholders.
- Critical thinking skills to trigger deep-rooted problem solving and multi-disciplinary analytical skills.
- Effective technical writing and documentation skills for SOPs and evaluation reports.
Preferred Skills
- Experience in a legacy environment with technical debt and internal challenges.
- Positive mindset for growth and driving change.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 5+ years of experience in application security or a related field.
Application Security