Get more replies from employers
Send a job-specific resume in minutes.
Jora Malaysia is seeking a senior software security engineer to lead remediation of vulnerabilities across Web and API surfaces. You will work from vulnerability and pentest reports to implement fixes in production code and guide secure development practices.
Strong experience with OWASP top 10, CI/CD security, and bug bounty triage will be highly valued. Familiarity with containerized environments and Kubernetes is a plus.
Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.
Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.
Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
Familiarity with Kubernetes and containerized application environments is a bonus.
5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.
Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.
Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
Familiarity with Kubernetes and containerized application environments is a bonus.
Vulnerability Remediation: