Lead Analyst, Technology Centre (Security Analyst)

AIA Digital+ Malaysia

Kuala Lumpur

On-site

MYR 70,000 - 110,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

AIA Digital+ Malaysia in Kuala Lumpur is seeking a Lead Analyst in Technology Centre (Security Analyst) to strengthen our application security capabilities. You will review findings from SAST and SCA, validate vulnerabilities, and advise remediation steps to secure software delivery.

Collaborate with development teams, explain risks, and document analyses, risk ratings, and remediation plans. A strong background in OWASP top 10, secure coding, and hands-on tool experience (Veracode, Checkmarx,

Qualifications

  • 3 years of experience in Application Security, Information Security, Secure Software Development, or related areas.
  • Hands-on experience with application security testing, vulnerability validation, secure code review, or vulnerability assessment.
  • Experience working with SAST, SCA, or similar tools.
  • Good understanding of OWASP Top 10, OWASP Web Security Testing Guide, CWE, and secure coding principles.
  • Ability to analyze security findings and determine exploitability and relevance.
  • Knowledge of common web app security issues such as injection, broken access control, insecure authentication, insecure deserialization, cryptographic weaknesses, and insecure configuration.
  • Familiarity with API security testing and secure SDLC, DevSecOps, CI/CD pipelines.
  • Experience with application security tools such as Veracode, Checkmarx, SonarQube, Snyk, Nexus IQ, GitHub Advanced Security.

Responsibilities

  • Analyze, triage, and validate application security findings generated by SAST, SCA, and other testing tools.
  • Differentiate genuine vulnerabilities from false positives, informational findings, or duplicates.
  • Review application source code to understand vulnerability context and identify weaknesses.
  • Assess exploitability, attack surface, attack path, and business impact of reported vulnerabilities.
  • Provide risk-based remediation guidance to application teams.
  • Explain findings to development teams and support remediation closure.
  • Document vulnerability analysis, triage decisions, risk ratings, business impact, and remediation recommendations.
  • Track findings, remediation progress, recurring issues, and key application security metrics.
  • Stay updated on threats, OWASP guidance, CWE weaknesses, and emerging attack techniques.

Skills

Application Security
Vulnerability Analysis
Secure Coding
SAST/SCA
OWASP
Threat Modeling

Education

Bachelor's degree in Computer Science
Bachelor's degree in Software Engineering
Bachelor's degree in Information Security

Tools

Veracode
Checkmarx
SonarQube
Snyk
Nexus IQ
GitHub Advanced Security

Job description

Lead Analyst, Technology Centre (Security Analyst)

In AIA Digital+, we serve as AIA’s Group-led Technology, Digital & Analytics hub by evolving innovative technology to shape the future. We aim to design & develop a detailed, human centered experiences to positively impact the lives of millions of people.

Join us as a part of AIA Group today!

What is this role about?

We are seeking an Application Security Analyst under SG Tech to support the organization’s Application Security capability, with primary focus on vulnerability analysis, validation, and remediation advisory for application security findings.

The role will be responsible for reviewing findings generated by application security tools, including Static Application Security Testing (SAST) and Software Composition Analysis (SCA), and determining whether the reported issues are genuine vulnerabilities, false positives, informational findings, or tool-generated inaccuracies. The candidate should have sufficient application security and secure coding knowledge to assess exploitability, business impact, and remediation options.

The successful candidate will work closely with application development teams to validate findings, explain security risks, recommend practical remediation actions, and support secure software delivery.

Analyze, triage, and validate application security findings generated by SAST, SCA, and other application security testing tools.

Differentiate genuine vulnerabilities from false positives, informational findings, duplicate findings, and tool-generated inaccuracies.

Review application source code to understand vulnerability context and identify potential security weaknesses.

Assess exploitability, attack surface, attack path, and potential business impact of reported vulnerabilities.

Provide risk-based remediation guidance to application teams.

Work with development teams to explain security findings, clarify remediation actions, and support closure of identified issues.

Document vulnerability analysis, triage decisions, risk ratings, business impact, and remediation recommendations.

Track application security findings, remediation progress, recurring issues, and key application security metrics.

Support secure software development practices by providing application security advisory to project and development teams.

Stay updated on application security threats, common vulnerability patterns, secure coding practices, OWASP guidance, CWE weaknesses, and emerging attack techniques.

Requirements:

3 years of experience in Application Security, Information Security, Secure Software Development, or related areas.

Hands-on experience with application security testing, vulnerability validation, secure code review, or vulnerability assessment.

Experience working with SAST, SCA, or similar application security tools.

Good understanding of OWASP Top 10, OWASP Web Security Testing Guide, CWE, and secure coding principles.

Ability to analyze security findings and determine whether issues are exploitable, relevant, or false positives.

Knowledge of common web application security issues such as injection, broken access control, insecure authentication, insecure deserialization, cryptographic weaknesses, and insecure configuration.

Good understanding of authentication, authorization, access control, input validation, session management, and encryption concepts.

Preferred Experience

Experience with application security tools such as Veracode, Checkmarx, SonarQube, Snyk, Nexus IQ, GitHub Advanced Security, or similar solutions.

Exposure to manual application security testing or penetration testing would be an added advantage, particularly for understanding exploitability, CWE weakness patterns, attack paths, and remediation validation.

Experience validating application vulnerabilities against industry guidance such as OWASP Web Security Testing Guide, OWASP Top 10, OWASP API Security Top 10, or CWE.

Familiarity with API security testing and common API security risks.

Familiarity with secure SDLC, DevSecOps practices, CI/CD pipelines, and security gates.

Exposure to software engineering, application development, or secure coding practices.

Basic understanding of container security, cloud application security, or modern application architecture security concepts would be an advantage.

Experience supporting application teams in vulnerability remediation, remediation verification, and closure tracking.

Experience preparing vulnerability analysis documentation, triage notes, risk justification, or remediation recommendations.

Education

Bachelor's degree in Computer Science, Software Engineering, Information Security, Information Technology, or related disciplines.

Preferred Certifications

Relevant certifications in application security, secure software development, secure SDLC, secure coding, vulnerability management, or information security would be an added advantage. Examples include CISSP, CSSLP, CASE, GWEB, GSSP-JAVA, Security+, or equivalent certifications

AIA Digital+ Malaysia (AIA IT (M) Sdn. Bhd. (202201010550)(1456247-A)) is a technology, digital and analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.

AIA Digital+ Malaysia (AIA IT (M) Sdn. Bhd. (202201010550)(1456247-A)) is a technology, digital and analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Analyst, Technology Centre (Security Analyst)
Lead Analyst, Technology Centre (Security Analyst)

AIA Digital+ • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Lead Analyst, Technology Centre
Lead Analyst, Technology Centre

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 90,000 - 140,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA Digital+ Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 160,000
Senior Application Security Lead
Senior Application Security Lead

AIA Digital+ Malaysia • Kuala Lumpur

On-site
MYR 70,000 - 110,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA Hong Kong and Macau • Malaysia

On-site
MYR 120,000 - 180,000
Lead Application Security Analyst
Lead Application Security Analyst

AIA Digital+ • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Assistant Manager, Technology Centre
Assistant Manager, Technology Centre

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Analyst, Business Analyst
Senior Analyst, Business Analyst

AIA Digital+ Malaysia • Kuala Lumpur

On-site
MYR 60,000 - 120,000
Information & Cybersecurity, Consultant
Information & Cybersecurity, Consultant

AIA Malaysia • Kuala Lumpur

On-site
MYR 70,000 - 90,000
Senior Analyst, Digital Distribution Solution (SIT Tester)
Senior Analyst, Digital Distribution Solution (SIT Tester)

AIA Digital+ Malaysia • Kuala Lumpur

On-site
MYR 67,000 - 134,000