Application Security Engineer

Carsome

Selangor

On-site

MYR 180,000 - 300,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Dental insurance
Health insurance
Maternity leave
Parental leave
Opportunities for promotion
Professional development

Job summary

Carsome in Malaysia is seeking a senior software engineer with 5+ years of experience, strong fullstack skills across backend and frontend, and a focus on secure coding.

You will remediate vulnerabilities from scans and pentest reports, work with CI/CD and Kubernetes, and contribute to security tooling and bug bounty processes.

Qualifications

  • 5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review them.
  • Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code.
  • Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
  • Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
  • Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
  • Familiarity with Kubernetes and containerized application environments is a bonus.

Responsibilities

  • Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
  • Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).
  • Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.
  • Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
  • Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
  • Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline

Skills

Node.js
Go
Python
.NET
PHP
Rust
Ruby
Java
React
Vue
Angular
SolidJS
OWASP Top 10
API security
CI/CD
Kubernetes
Bug bounty
GitHub
GitLab
Bitbucket
SAST
SCA
DAST

Tools

GitHub
GitLab
Bitbucket
SAST
SCA
DAST

Job description

5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.

Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.

Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.

Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.

Experience working with bug bounty programs and triaging external researcher submissions is a bonus.

Familiarity with Kubernetes and containerized application environments is a bonus.

Requirement

  • 5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.

  • Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.

  • Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.

  • Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.

  • Experience working with bug bounty programs and triaging external researcher submissions is a bonus.

  • Familiarity with Kubernetes and containerized application environments is a bonus.

Responsibility

Vulnerability Remediation:

  • Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.

  • Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).

  • Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.

  • Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.

  • Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.

  • Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.

  • Build lightweight internal tooling/scripts to help automate triage, tracking, or reporting of vulnerability and posture data where useful (e.g., feeding dashboards, Jira, or a reporting tool).

Benefits
  • Dental insurance
  • Health insurance
  • Maternity leave
  • Opportunities for promotion
  • Parental leave
  • Professional development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Network Security Engineer
Network Security Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Application Security Engineer
Application Security Engineer

Respond.io • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Mental health allowance
Flexible working hours
Competitive compensation
+1
Security Engineer – Vulnerability Management & VAPT
Security Engineer – Vulnerability Management & VAPT

Ascendion • Cyberjaya

On-site
MYR 120,000 - 180,000
Vulnerability Response Specialist
Vulnerability Response Specialist

Two95 International Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Application Security Lead
Application Security Lead

Salmon Group Ltd • Kuala Lumpur

On-site
MYR 280,000 - 420,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH • Kuala Lumpur

On-site
MYR 140,000 - 240,000
DevSecOps Engineer (Application & Endpoint)
DevSecOps Engineer (Application & Endpoint)

Respond • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Culture and growth
Competitive pay
Mental health allowance
+2
Lead Analyst, Technology Centre (Security Analyst)
Lead Analyst, Technology Centre (Security Analyst)

AIA Digital+ • Kuala Lumpur

On-site
MYR 90,000 - 150,000
VAPT Security Engineer: Exploitability & Remediation
VAPT Security Engineer: Exploitability & Remediation

Ascendion • Cyberjaya

On-site
MYR 120,000 - 180,000