Application Security Lead

Salmon Group Ltd

Kuala Lumpur

On-site

MYR 280,000 - 420,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Salmon Group Ltd in Kuala Lumpur is seeking an experienced security leader to own application security across mobile banking, payments, and regulated products. You’ll conduct threat modeling, security reviews, and CI/CD tooling, reporting to the Group CISO and collaborating with engineering and Bank IS teams.

Ideal candidates have 7+ years in application security, hands-on mobile testing, and a proven secure SDLC track record, plus familiarity with regulatory requirements and SBOM practices.

Qualifications

  • 7+ years in application security with ownership over both technical work and process.
  • Built or substantially improved a secure SDLC in a fast-moving product org.
  • Run threat modeling on real product features and influenced design decisions.
  • Owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance.
  • Hands-on mobile security testing (iOS and/or Android) in production contexts.
  • Understand modern supply chain attack vectors and how to reduce exposure via tooling and process.
  • Able to automate repetitive security work with Python or Bash.

Responsibilities

  • Risk-driven security ownership: focus on high-risk systems and data flows.
  • Secure SDLC: insert security gates and threat modeling early in delivery.
  • CI/CD and supply chain: assess current pipeline, reduce noise, improve scanners.
  • Regulatory and cross-team work: translate gaps for BSP examiners and coordinate launches.

Skills

Threat modeling
Vulnerability management
Mobile security testing
CI/CD security
Python Bash scripting
Supply chain security
Communication
Regulatory familiarity
OSS/Tooling knowledge

Tools

OWASP ASVS
MASVS
SBOM tooling
AWS

Job description

The Role

You’ll own application security across our mobile banking platform, payments stack, and a growing set of regulated products. The work is hands‑on, you’ll conduct threat modeling, security reviews, CI/CD tooling – with real process ownership. You’ll report to the Group CISO and work closely with both our engineering teams and the Bank IS function.

Responsibilities
Risk-driven security ownership
  • Identify which systems, data flows, and product changes carry the highest real‑world risk and focus work around that, not around tool coverage or compliance checklists
  • Decide when a security gate is worth slowing down a release and when it isn’t, own that call and be able to explain it to engineering and the CISO
  • Maintain a risk register for application‑layer exposures: what’s open, what’s accepted, what’s being fixed, and why in that order
Secure SDLC
  • Figure out where in our delivery process security decisions are actually being made and put controls there
  • Run threat modeling for high‑stakes product changes before design is locked, not after
  • Build a mobile security testing baseline that the team runs themselves
CI/CD and supply chain
  • Assess what the current pipeline actually catches versus what it produces as noise and fix the ratio before adding more scanners
  • Own supply chain posture: dependency pinning, SBOM, internal registry, and the response process when a package gets compromised
  • Own secrets detection and remediation end‑to‑end
Regulatory and cross‑team work
  • Translate application security gaps into language that satisfies BSP examiners without over‑engineering the evidence
  • Coordinate security input into new product launches across our Group and Bank structure
Requirements
Experience
  • 7+ years in application security, with meaningful ownership over both technical work and process
  • Has built or substantially improved a secure SDLC in a fast‑moving product org
  • Has run threat modeling on real product features and influenced design decisions as a result
  • Has owned vulnerability management end‑to‑end: triage, remediation tracking, SLA management, risk acceptance
  • Has done hands‑on mobile security testing (iOS and/or Android) in a production context, not just UAT
  • Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion – and knows how to reduce exposure at the tooling and process level
  • Comfortable writing Python or Bash to automate repetitive security work
Technical Skills
  • SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage
  • API security: authentication flows, token handling, common abuse patterns
  • Mobile security: OWASP ASVS/MASVS applied in practice
  • Supply chain: SBOM generation and dependency risk management
  • Secrets management: detection, remediation, and structural prevention
  • Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure
Nice to have
  • Experience in a regulated environment (financial services or similar)
  • Familiarity with PCI-DSS, ISO 27001, or BSP MORB
  • Certifications: OSCP, GWEB, GWAPT, CSSLP
Communication
  • Strong written English; most day-to-day alignment is async
  • Can explain a security issue clearly to an engineer and summarize the same issue for a non-technical stakeholder
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Application Security Engineer
Lead Application Security Engineer

Encora Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Architect
Security Architect

Confidential • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Senior Security Business Partner – Product Security
Senior Security Business Partner – Product Security

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 260,000
App Security Lead: Threat Modeling & Secure SDLC
App Security Lead: Threat Modeling & Secure SDLC

Salmon Group Ltd • Kuala Lumpur

On-site
MYR 280,000 - 420,000
Senior Application Security Specialist
Senior Application Security Specialist

Swift • Kuala Lumpur

On-site
Senior Application Security Specialist
Senior Application Security Specialist

Swift Software • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Security Architect
Security Architect

Teleport • Kuala Lumpur

On-site
MYR 120,000 - 210,000
Application Security Engineer
Application Security Engineer

Respond.io • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Mental health allowance
Flexible working hours
Competitive compensation
+1
Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Digital+ • Kuala Lumpur

On-site
MYR 180,000 - 360,000
Senior Security Advisor & Technical Project Manager
Senior Security Advisor & Technical Project Manager

Hong Leong Bank Berhad • Petaling Jaya

On-site
MYR 180,000 - 300,000