Product Security Engineer

Agensi Pekerjaan Penta Consultancy Sdn. Bhd

Kuala Lumpur

On-site

MYR 180,000 - 300,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Agensi Pekerjaan Penta Consultancy Sdn. Bhd is seeking a senior security engineer focused on product security to lead threat modeling, secure SDLC implementation, and security reviews across multiple product lines in Malaysia.

You will partner with engineering, product, and technology teams, drive secure coding practices, oversee vulnerability remediation, and ensure AWS security controls, data protection, and API security meet regulatory and business requirements.

Qualifications

  • Minimum 4–6 years in product/security engineering roles.
  • Experience in threat modeling, secure architecture reviews, and application security assessments.
  • Proven track record implementing or operating Secure SDLC processes.

Responsibilities

  • Develop, implement, and maintain product security standards and practices.
  • Lead security reviews, threat modeling, and risk assessments across SDLC.
  • Coordinate with engineering and product teams to remediate vulnerabilities.
  • Manage cloud security assessments (AWS) and identity/network protections.
  • Develop security policies, baselines, and awareness initiatives for engineering teams.
  • Act as the primary product security expert and advocate for best practices.

Skills

Threat modeling
Secure architecture design
Application security assessments
Secure SDLC ownership
Cross-functional collaboration
Independent ownership

Education

Bachelor's degree in Computer Science / Information Security

Tools

SAST tools
DAST tools
SCA tools
Vulnerability management platforms
IAM & KMS knowledge

Job description

  • Develop, implement, and maintain product security standards, frameworks, and best practices across all product lines within the organization.
  • Design and establish a comprehensive System Security Framework covering authentication, OTP lifecycle management, data protection, secrets management, encryption, key management, and access controls.
  • Conduct security architecture reviews, threat modeling exercises, and risk assessments throughout the software development lifecycle.
  • Define, implement, and manage a Secure Software Development Lifecycle (Secure SDLC), including security requirements, design reviews, testing, and release approval processes.
  • Lead application security activities including secure code reviews, vulnerability assessments, penetration testing coordination, SAST, DAST, software composition analysis, and dependency management.
  • Perform security assessments of cloud environments, primarily AWS, focusing on identity management, network security, data protection, and configuration hardening.
  • Review and provide security sign-off recommendations for product releases, ensuring security requirements are met prior to deployment.
  • Partner closely with engineering, product, and technology teams across multiple regions to identify, prioritize, and remediate security vulnerabilities.
  • Manage vulnerability remediation activities, track security risks, and provide regular reporting to senior management and stakeholders.
  • Coordinate with external security auditors, penetration testing providers, and compliance assessors.
  • Develop and maintain security policies, standards, baselines, guidelines, and security awareness initiatives for engineering teams.
  • Act as the primary product security subject matter expert and advocate security best practices across the organization.
Job Requirements:
  • Bachelor's Degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related discipline.
  • Minimum 4-6 years of hands-on experience in Product Security, Application Security, Cybersecurity, or related security engineering roles.
  • Strong experience in threat modeling, secure architecture design reviews, and application security assessments.
  • Proven experience designing, implementing, or operating Secure SDLC processes within software development environments.
  • Hands-on experience with application security tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and vulnerability management platforms.
  • Strong understanding of authentication mechanisms, authorization models, OTP implementations, encryption technologies, key management systems (KMS), secrets management, and secure coding practices.
  • Experience securing cloud environments, preferably AWS, including IAM, networking, storage security, monitoring, and configuration management.
  • Strong knowledge of OWASP Top 10, secure development practices, API security, mobile security, and software supply chain security.
  • Ability to work independently as the primary security owner while effectively influencing cross-functional engineering teams.
  • Experience working within fintech, digital payments, cryptocurrency, blockchain, wallet security, or regulated environments is an added advantage.
  • Professional certifications such as OSCP, CISSP, GWAPT, AWS Security Specialty, CEH, or equivalent are preferred.
  • Demonstrated stability in career progression with a proven track record of delivering security initiatives and driving measurable improvements.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Architect
Product Security Architect

Confidential Careers • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Product Security Architect
Product Security Architect

Confidential • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Security Business Partner – Product Security
Senior Security Business Partner – Product Security

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Senior Security Business Partner – S-SDLC / Product Security
Senior Security Business Partner – S-SDLC / Product Security

Atome • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Senior Application Security Specialist – AppSec / DevSecOps
Senior Application Security Specialist – AppSec / DevSecOps

Randstad Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 210,000
Lead Application Security Engineer
Lead Application Security Engineer

Encora Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Product Executive
Product Executive

10 Infinity Sdn. Bhd. • Petaling Jaya

On-site
MYR 60,000 - 90,000
Regional Assistant Manager, Security Engineering
Regional Assistant Manager, Security Engineering

ZUS COFFEE • Selangor

On-site
MYR 180,000 - 300,000
Senior Security Operations Engineer (SecOps)
Senior Security Operations Engineer (SecOps)

Randstad Malaysia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Engineer
Security Engineer

CDN5 • Malaysia

On-site
MYR 50,000 - 80,000