Job Search and Career Advice Platform

Enable job alerts via email!

Manager, IT Security

Great Eastern

Kuala Lumpur

On-site

MYR 120,000 - 160,000

Full time

4 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading regional financial institution in Kuala Lumpur is looking for a Manager, Application Security. This hands-on role focuses on strengthening the enterprise application security posture through activities like penetration testing and secure code reviews. The ideal candidate should have extensive IT security experience, a strong technical background, and familiarity with regulations such as MAS TRM and BNM RMiT. This position requires collaboration with multiple teams to ensure timely remediation and compliance with regulatory standards.

Qualifications

  • 7+ years of IT security experience, with at least 4 years in penetration testing.
  • Strong technical knowledge of web, mobile, and API security.
  • Working knowledge of MAS TRM, MAS Cyber Hygiene, and BNM RMiT requirements.

Responsibilities

  • Conduct penetration testing for web, mobile, and API applications.
  • Perform secure code reviews and software composition analysis.
  • Work with development and DevOps to ensure timely remediation.

Skills

Penetration testing
Secure code review
Vulnerability assessments
Software composition analysis
Container image assurance

Education

Bachelor’s degree in Information Security, Computer Science, or related field
Professional certifications such as CREST, OSCP+, OSEP, or GPEN

Tools

Burp Suite
OWASP ZAP
Fortify
Checkmarx
Black Duck
Nessus
Aqua
Qualys
Job description

The Manager, Application Security is responsible for strengthening our enterprise application security posture. This is a hands‑on individual contributor role responsible for performing penetration testing, secure code review, software composition analysis, container image assurance, and vulnerability assessments, as well as managing findings and supporting compliance with financial industry regulations. The role requires strong technical expertise, practical testing skills, and familiarity with regulatory requirements such as MAS TRM Guidelines and BNM RMiT Policy Document.

Responsibilities
  • Conduct penetration testing for web, mobile, and API applications.
  • Perform secure code reviews, software composition analysis, and container image assurance to identify vulnerabilities early in the SDLC.
  • Perform vulnerability assessments for applications, middleware, and supporting systems.
  • Utilise industry‑standard tools such as Burp Suite, OWASP ZAP, Fortify, Checkmarx, Black Duck, Nessus, Aqua and Qualys.
  • Triage, validate, and prioritise security findings from security assessments.
  • Work with development, DevOps, and infrastructure teams to ensure timely remediation.
  • Track and report remediation progress, ensuring closure within timelines required by regulatory instruments and Technology Security Standards.
  • Provide guidance to developers and project teams on secure coding practices.
  • Embed application security controls and tools (SAST, DAST, SCA, IAST) into CI/CD pipelines.
  • Maintain security documentation and provide evidence for audits and regulatory reviews.
  • Ensure compliance with internal policies, regulatory obligations, and industry best practices.
  • Support audits, risk assessments, and regulatory inspections involving application security.
Qualifications
  • Bachelor’s degree in Information Security, Computer Science, or related field.
  • Professional certifications such as CREST, OSCP+, OSEP, or GPEN.
  • 7+ years of IT security experience, with at least 4 years of direct experience in project‑based and annual penetration testing for web, mobile, and API applications.
  • Experienced in secure code reviews, software composition analysis, container image assurance, and vulnerability assessments.
  • Strong technical knowledge of web, mobile, and API security, including OWASP Top 10 and common attack vectors.
  • Hands‑on expertise with security testing tools mentioned above.
  • Working knowledge of MAS TRM, MAS Cyber Hygiene, and BNM RMiT requirements.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.