Information Security Engineer

Carsome

Selangor

On-site

MYR 180,000 - 260,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Dental insurance
Health insurance
Maternity leave
Opportunities for promotion
Parental leave
Professional development

Job summary

Jora Malaysia is seeking a senior software security engineer to lead remediation of vulnerabilities across Web and API surfaces. You will work from vulnerability and pentest reports to implement fixes in production code and guide secure development practices.

Strong experience with OWASP top 10, CI/CD security, and bug bounty triage will be highly valued. Familiarity with containerized environments and Kubernetes is a plus.

Qualifications

  • 5+ years of software engineering experience with full-stack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent).
  • Solid understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to fix them in code.
  • Comfortable working from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
  • Familiarity with CI/CD pipelines and resolving findings from embedded SAST/SCA/DAST tooling.
  • Experience with bug bounty programs and triaging external researcher submissions is a bonus.
  • Familiarity with Kubernetes and containerized application environments is a bonus.

Responsibilities

  • Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
  • Write and ship code-level fixes for application vulnerabilities directly in relevant codebases.
  • Triage findings from security tools to validate true positives and prioritize based on exploitability and business risk.
  • Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
  • Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
  • Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow.
  • Build lightweight internal tooling/scripts to help automate triage, tracking, or reporting of vulnerability and posture data.

Skills

Full-stack development
Backend development
Frontend development
Vulnerability remediation
OWASP knowledge
CI/CD
Bug bounty experience
Kubernetes

Tools

GitHub/GitLab/Bitbucket
SAST/SCA/DAST tooling
CI/CD tooling
Bug bounty platforms
Containerization (Kubernetes)

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.

Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.

Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.

Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.

Experience working with bug bounty programs and triaging external researcher submissions is a bonus.

Familiarity with Kubernetes and containerized application environments is a bonus.

Requirement
  • 5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.

  • Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.

  • Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.

  • Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.

  • Experience working with bug bounty programs and triaging external researcher submissions is a bonus.

  • Familiarity with Kubernetes and containerized application environments is a bonus.

Responsibility

Vulnerability Remediation:

  • Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
  • Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).
  • Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.
  • Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
  • Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
  • Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
  • Build lightweight internal tooling/scripts to help automate triage, tracking, or reporting of vulnerability and posture data where useful (e.g., feeding dashboards, Jira, or a reporting tool).
Benefits
  • Dental insurance
  • Health insurance
  • Maternity leave
  • Opportunities for promotion
  • Parental leave
  • Professional development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Engineer
Network Security Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Cybersecurity Engineer
Cybersecurity Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Security Engineer – Vulnerability Management - VAPT
Security Engineer – Vulnerability Management - VAPT

Ascendion • Cyberjaya

On-site
MYR 60,000 - 120,000
Application Security Engineer
Application Security Engineer

Puresoftware • Kuala Lumpur

On-site
MYR 90,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services Malaysia • Kuala Lumpur

On-site
MYR 89,000 - 167,000
Salary 8k-15k MYR
Certifications support
Career development
Security Engineer
Security Engineer

Job Search Asia • Petaling Jaya

On-site
MYR 90,000 - 150,000
EPF
SOCSO
EIS
Staff IT Security Engineer
Staff IT Security Engineer

Michael Page • Penang

On-site
MYR 194,000 - 238,000
Comprehensive benefits
Permanent position
DEVOPS / SECURITY ENGINEER
DEVOPS / SECURITY ENGINEER

WABO SOFTWARE SDN BHD • Johor Bahru

On-site
MYR 96,000 - 144,000
Cyber Security Engineer
Cyber Security Engineer

Crestino Tech Solution • Selangor

On-site
MYR 90,000 - 150,000
Network Security Engineer (Junior Level)
Network Security Engineer (Junior Level)

DIGITAL DEFENSE SOLUTION SDN. BHD. • Selangor

On-site
MYR 48,000 - 72,000
Cell phone reimbursement
Health insurance
Maternity leave
+2