Network Security Engineer

Carsome

Selangor

On-site

MYR 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Dental insurance
Health insurance
Maternity leave
Opportunities for promotion
Parental leave
Professional development

Job summary

Jora Malaysia is seeking a senior software engineer with 5+ years of fullstack experience to lead vulnerability remediation across Web and API surfaces. You will read reviews from vulnerability scans, triage findings, and ship code fixes directly in core codebases.

Responsibilities include coordinating with DevOps and security teams, maintaining remediation dashboards, and contributing to secure development practices. Familiarity with bug bounty processes is valued.

Qualifications

  • 5+ years of software engineering experience with strong fullstack skills across backend and frontend.
  • Solid understanding of web and API vulnerability classes (OWASP Top 10) and how to fix them in code.
  • Comfortable working from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause issues.
  • Familiarity with CI/CD pipelines and resolving findings from embedded SAST/SCA/DAST tooling.
  • Experience with bug bounty programs and triaging external researcher submissions is a bonus.
  • Familiarity with Kubernetes and containerized app environments is a bonus.

Responsibilities

  • Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
  • Write and ship code-level fixes for application vulnerabilities directly in codebases (GitHub/GitLab/Bitbucket).
  • Triage findings from security tools to validate true positives and prioritize by risk.
  • Work with development teams to remediate findings that require architecture changes and provide secure coding guidance.
  • Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
  • Fix vulnerabilities surfaced by security tooling embedded in CI/CD pipelines to keep the pipeline green.
  • Build lightweight internal tooling/scripts to automate triage, tracking, or reporting.

Skills

Fullstack development
Backend languages
Frontend frameworks
Secure coding
Vulnerability remediation
Bug bounty experience
CI/CD pipelines
Kubernetes familiarity

Tools

CI/CD tooling
SAST/SCA/DAST tooling
GitHub/GitLab/Bitbucket
Kubernetes

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.

Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.

Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.

Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.

Experience working with bug bounty programs and triaging external researcher submissions is a bonus.

Familiarity with Kubernetes and containerized application environments is a bonus.

Requirement
  • 5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.

  • Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.

  • Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.

  • Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.

  • Experience working with bug bounty programs and triaging external researcher submissions is a bonus.

  • Familiarity with Kubernetes and containerized application environments is a bonus.

Responsibility

Vulnerability Remediation:

  • Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
  • Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).
  • Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.
  • Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
  • Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
  • Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
  • Build lightweight internal tooling/scripts to help automate triage, tracking, or reporting of vulnerability and posture data where useful (e.g., feeding dashboards, Jira, or a reporting tool).
Benefits
  • Dental insurance
  • Health insurance
  • Maternity leave
  • Opportunities for promotion
  • Parental leave
  • Professional development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

Carsome • Selangor

On-site
MYR 180,000 - 260,000
Dental insurance
Health insurance
Maternity leave
+3
Cybersecurity Engineer
Cybersecurity Engineer

Carsome • Selangor

On-site
MYR 180,000 - 240,000
Dental insurance
Health insurance
Maternity leave
+3
Security Engineer – Vulnerability Management - VAPT
Security Engineer – Vulnerability Management - VAPT

Ascendion • Cyberjaya

On-site
MYR 60,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services Malaysia • Kuala Lumpur

On-site
MYR 89,000 - 167,000
Salary 8k-15k MYR
Certifications support
Career development
Network Security Engineer (Junior Level)
Network Security Engineer (Junior Level)

DIGITAL DEFENSE SOLUTION SDN. BHD. • Selangor

On-site
MYR 48,000 - 72,000
Cell phone reimbursement
Health insurance
Maternity leave
+2
Application Security Engineer
Application Security Engineer

Puresoftware • Kuala Lumpur

On-site
MYR 90,000 - 180,000
Security Engineer
Security Engineer

Job Search Asia • Petaling Jaya

On-site
MYR 90,000 - 150,000
EPF
SOCSO
EIS
DEVOPS / SECURITY ENGINEER
DEVOPS / SECURITY ENGINEER

WABO SOFTWARE SDN BHD • Johor Bahru

On-site
MYR 96,000 - 144,000
Staff IT Security Engineer
Staff IT Security Engineer

Michael Page • Penang

On-site
MYR 194,000 - 238,000
Comprehensive benefits
Permanent position
Cyber Security Project Analyst
Cyber Security Project Analyst

Golden Agri-Resources • Selangor

On-site
MYR 60,000 - 90,000