Get more replies from employers
Send a job-specific resume in minutes.
Jora Malaysia is seeking a senior software engineer with 5+ years of fullstack experience to lead vulnerability remediation across Web and API surfaces. You will read reviews from vulnerability scans, triage findings, and ship code fixes directly in core codebases.
Responsibilities include coordinating with DevOps and security teams, maintaining remediation dashboards, and contributing to secure development practices. Familiarity with bug bounty processes is valued.
Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.
Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.
Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
Familiarity with Kubernetes and containerized application environments is a bonus.
5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.
Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.
Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
Familiarity with Kubernetes and containerized application environments is a bonus.
Vulnerability Remediation: