Lead Analyst, Technology Centre

AIA Hong Kong and Macau

Kuala Lumpur

On-site

MYR 90,000 - 140,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

AIA Digital+ in Malaysia is hiring an Application Security Analyst to support vulnerability analysis, validation, and remediation advisory for secure software delivery.

You will review findings from SAST/SCA tools, assess exploitability and business impact, and work with development teams to remediate issues, while staying updated on OWASP guidance and modern attack techniques.

Qualifications

  • Minimum 3 years of experience in Application Security or related areas.
  • Experience with SAST/SCA or similar tooling.
  • Knowledge of OWASP Top 10, CWE and secure coding principles.

Responsibilities

  • Analyze, triage, and validate findings from SAST/SCA and other tools.
  • Review code to understand vulnerability context in Java, Python, JavaScript.
  • Provide risk-based remediation guidance to development teams.
  • Document analysis, risk, and remediation recommendations.

Skills

Application Security
Vulnerability analysis
SAST
SCA
OWASP Top 10

Education

Bachelor's degree

Tools

Veracode
Checkmarx
SonarQube

Job description

Are you ready to shape a better tomorrow? AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives. If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you. Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment. If you want to shape a brighter future at AIA Digital+, please read on.

About the Role

We are seeking an Application Security Analyst to support the organization’s Application Security capability, with primary focus on vulnerability analysis, validation, and remediation advisory for application security findings. The role will be responsible for reviewing findings generated by application security tools, including Static Application Security Testing and Software Composition Analysis, and determining whether the reported issues are genuine vulnerabilities, false positives, informational findings, or tool-generated inaccuracies. The candidate should have sufficient application security and secure coding knowledge to assess exploitability, business impact, and remediation options. The successful candidate will work closely with application development teams to validate findings, explain security risks, recommend practical remediation actions, and support secure software delivery.

Roles and Responsibilities

Analyze, triage, and validate application security findings generated by SAST, SCA, and other application security testing tools. Differentiate genuine vulnerabilities from false positives, informational findings, duplicate findings, and tool-generated inaccuracies. Review application source code to understand vulnerability context and identify potential security weaknesses. Assess exploitability, attack surface, attack path, and potential business impact of reported vulnerabilities. Provide risk-based remediation guidance to application teams. Review code written in Java, Python, JavaScript, and other commonly used programming languages to support vulnerability validation. Work with development teams to explain security findings, clarify remediation actions, and support closure of identified issues. Document vulnerability analysis, triage decisions, risk ratings, business impact, and remediation recommendations. Track application security findings, remediation progress, recurring issues, and key application security metrics. Support secure software development practices by providing application security advisory to project and development teams. Stay updated on application security threats, common vulnerability patterns, secure coding practices, OWASP guidance, CWE weaknesses, and emerging attack techniques.

Required Experience and Skills

Minimum 3 years of experience in Application Security, Information Security, Secure Software Development, or related areas. Hands-on experience with application security testing, vulnerability validation, secure code review, or vulnerability assessment. Experience working with SAST, SCA, or similar application security tools. Good understanding of OWASP Top 10, OWASP Web Security Testing Guide, CWE, and secure coding principles. Ability to analyze security findings and determine whether issues are exploitable, relevant, or false positives. Ability to understand source code and application logic in Java, Python, JavaScript, or similar programming languages. Knowledge of common web application security issues such as injection, broken access control, insecure authentication, insecure deserialization, cryptographic weaknesses, and insecure configuration. Good understanding of authentication, authorization, access control, input validation, session management, and encryption concepts. Ability to communicate security risks and remediation guidance clearly to technical and non-technical stakeholders. Strong analytical, problem-solving, documentation, and follow-up skills. Proactive mindset, ownership, integrity, and ability to work independently.

Preferred Experience

Experience with application security tools such as Veracode, Checkmarx, SonarQube, Snyk, Nexus IQ, GitHub Advanced Security, or similar solutions. Exposure to manual application security testing or penetration testing would be an added advantage, particularly for understanding exploitability, CWE weakness patterns, attack paths, and remediation validation. Experience validating application vulnerabilities against industry guidance such as OWASP Web Security Testing Guide, OWASP Top 10, OWASP API Security Top 10, or CWE. Familiarity with API security testing and common API security risks. Familiarity with secure SDLC, DevSecOps practices, CI/CD pipelines, and security gates. Exposure to software engineering, application development, or secure coding practices. Basic understanding of container security, cloud application security, or modern application architecture security concepts would be an advantage. Experience supporting application teams in vulnerability remediation, remediation verification, and closure tracking. Experience preparing vulnerability analysis documentation, triage notes, risk justification, or remediation recommendations.

Education

Bachelor's degree in Computer Science, Software Engineering, Information Security, Information Technology, or related disciplines.

Preferred Certifications

Relevant certifications in application security, secure software development, secure SDLC, secure coding, vulnerability management, or information security would be an added advantage. Examples include CISSP, CSSLP, CASE, GWEB, GSSP-JAVA, Security+, or equivalent certifications.

Build a career with us

As we help our customers and the community live healthier, longer, better lives. You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date. At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. It's about finding new ways to not only better people's lives, but to better the communities and environments we live in. As the largest listed company on the Hong Kong Stock Exchange, we’ve been proudly making a difference for people and communities across Asia for over a century. And we build on this every day with our ambition to engage one billion people to live Healthier, Longer, Better Lives by 2030. If you work at AIA, you play an important part in this movement. Which is why we give you every opportunity to learn, grow and shape your career - your way. Inspiring and supporting you to thrive - not just at work, but in life. Believe in better with AIA. View our AIA LinkedIn page Bring your difference to AIA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA Hong Kong and Macau • Malaysia

On-site
MYR 120,000 - 180,000
Lead Analyst, Testing
Lead Analyst, Testing

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 100,000 - 167,000
Assistant Manager, Technology Centre
Assistant Manager, Technology Centre

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Lead Analyst, Technology Centre (Security Analyst)
Lead Analyst, Technology Centre (Security Analyst)

AIA Digital+ • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Analyst, Cloud Application Transformation
Analyst, Cloud Application Transformation

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Lead Analyst, Operations
Lead Analyst, Operations

AIA Hong Kong and Macau • Kuala Lumpur

On-site
Assistant Manager, Enterprise Platform Transformation
Assistant Manager, Enterprise Platform Transformation

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Intern, Testing
Intern, Testing

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Business Analyst, Specialist
Business Analyst, Specialist

AIA Hong Kong and Macau • Kampung Cendana

On-site
MYR 90,000 - 150,000
Business Analyst, Specialist
Business Analyst, Specialist

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 90,000 - 130,000