Bibit.id is seeking an Application Security Engineer to enhance the security of applications across mobile and backend systems. The ideal candidate will embed with product teams, conduct thorough security reviews, and lead initiatives to promote security awareness. Responsibilities include identifying vulnerabilities through code reviews and testing, alongside collaborating with developers to integrate security into the development lifecycle. Strong knowledge of web and mobile security fundamentals and experience with penetration testing are essential for this role.
Qualifications
Strong understanding of web and mobile security fundamentals.
Hands-on experience with penetration testing and secure code review.
Familiarity with Golang and JavaScript.
Responsibilities
Collaborate closely with engineers, QA, and product managers to ensure security considerations are part of every development stage.
Review application code to identify and mitigate vulnerabilities.
Conduct penetration testing, vulnerability scanning, and static/dynamic analysis.
Partner with teams to assess potential threats and design mitigations.
Manage bug bounty reports submitted by external researchers.
Provide guidance on secure design patterns.
Support investigation and remediation of application-related security incidents.
Promote secure coding practices through knowledge-sharing.
Stay updated on latest vulnerabilities and attack vectors.
Skills
Web and mobile security fundamentals
Penetration testing
Secure code review
Communication of security concepts
Tools
Burp Suite
OWASP ZAP
Snyk
Job description
Bibit.id is seeking an Application Security Engineer to enhance the security of applications across mobile and backend systems. The ideal candidate will embed with product teams, conduct thorough security reviews, and lead initiatives to promote security awareness. Responsibilities include identifying vulnerabilities through code reviews and testing, alongside collaborating with developers to integrate security into the development lifecycle. Strong knowledge of web and mobile security fundamentals and experience with penetration testing are essential for this role.