Senior Application Security Engineer

Carsome Sdn Bhd

Petaling Jaya

On-site

MYR 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Carsome Sdn Bhd is hiring a Senior Application Security Engineer to identify, validate, and drive remediation of security vulnerabilities across Carsome Group’s applications and DevSecOps pipelines. The role blends offensive security with DevSecOps engineering to scale security through automation.

This hands-on position requires expertise in internal/external penetration testing, OWASP Top 10/ASVS, and CI/CD security practices.

Qualifications

  • 5+ years of experience in application security, penetration testing, or a related offensive security role.
  • Hands-on web and API security testing using OWASP Top 10/ASVS.
  • Experience with SAST/DAST/DAST tools and triaging findings.
  • Familiarity with DevSecOps practices and CI/CD security.
  • Relevant certifications (e.g., OSCP, GWAPT, CEH) are highly regarded.

Responsibilities

  • Plan and execute internal penetration tests for web, mobile, and API apps.
  • Triage findings from tooling (SAST/DAST/SCA) and bug bounty inputs.
  • Embed security gates into CI/CD pipelines and reduce noise in tooling.
  • Perform manual secure code review and threat modelling for high-risk features.
  • Coordinate bug bounty engagements and external VAPT activities.

Skills

Penetration testing
Security assessment
Security reporting
Threat modelling
Security automation

Tools

Burp Suite Pro
GitLab CI/CD
Jira

Job description

The Senior Application Security Engineer is a hands-on technical role, responsible for identifying, validating, and driving remediation of security vulnerabilities across Carsome Group’s applications and DevSecOps CI/CD pipelines. The role combines strong offensive security skills (internal penetration testing) with DevSecOps engineering, and a mandate to scale the security function through automation.

Key Responsibilities

Plan, scope, and execute internal penetration tests against web, mobile, and API applications and internal network/infrastructure assets, producing clear technical reports with risk ratings and remediation guidance.

Triage and validate findings generated by Application Security tooling (SAST/DAST/SCA), Bug Bounty tooling, and DevSecOps CI/CD pipeline scans, filtering false positives and duplicates and confirming real, exploitable issues before escalation to engineering.

Own and continuously improve the vulnerability triage and remediation workflow, including SLA prioritization based on exploitability, asset exposure (public/private), and asset criticality.

Design, build, and maintain automation workflows to automatically classify, prioritize, and route vulnerability findings into Jira with minimal manual intervention.

Partner with DevOps/Platform engineering to embed security gates (SAST, DAST, SCA, secrets and container/image scanning) into CI/CD pipelines, and continuously tune tooling to reduce noise.

Perform manual secure code review and threat modelling for high-risk features and new services.

Coordinate and support the bug bounty programme and external VAPT engagements, including validating and triaging externally reported findings.

Track and report on remediation SLA compliance, elevate breaches, and drive the exception / risk-acceptance process for findings that cannot be remediated within SLA.

Mentor the mid-level Security Engineer and act as the technical escalation point for complex or high-severity findings.

Stay current with emerging attack techniques, OWASP Top 10/ASVS, and cloud-native application security practices, and champion secure coding practices across engineering teams.

Requirements

5+ years of experience in application security, penetration testing, or a related offensive security role, with demonstrable experience performing internal and/or external penetration tests.

Strong hands-on experience with web and API application security testing methodologies (OWASP Top 10, OWASP ASVS) using tools such as Burp Suite Professional.

Solid understanding of DevSecOps practices and CI/CD pipeline security (SAST, DAST, SCA, container and secrets scanning); GitLab CI/CD experience is a plus.

Practical experience triaging and validating findings from automated scanning platforms and prioritizing remediation based on risk.

Familiarity with Jira-based vulnerability management and SLA-driven remediation processes.

Strong written and verbal communication skills, able to translate technical findings into clear, actionable reports for engineering and leadership audiences.

Relevant certifications (e.g., OSCP, OSWE, GWAPT, CEH, eWPT, eCPPT, eMAPT) are highly regarded.

Your application will include the following questions:

  • Which of the following statements best describes your right to work in Malaysia?
  • What's your expected monthly basic salary?
  • How many years' experience do you have as an Application Security Engineer?
  • Which of the following types of qualifications do you have?

CARSOME is Southeast Asia’s largest integrated car e-commerce platform. With operations across Malaysia, Indonesia, Thailand and Singapore, CARSOME aims to digitize the region’s used car industry by reshaping and elevating the car buying and selling experience.

The company provides end-to-end solutions to consumers and used car dealers, from car inspection to ownership transfer to financing, promising a service that is trusted, convenient and efficient. CARSOME currently transacts around 100,000 cars annually and has more than 2,000 employees across all its offices.

For more information, please visit www.carsome.my

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer: Pen Tests & CI/CD Security
Senior AppSec Engineer: Pen Tests & CI/CD Security

Carsome Sdn Bhd • Petaling Jaya

On-site
MYR 180,000 - 240,000
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH Management Ltd. • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

Grab • Petaling Jaya

On-site
MYR 220,000 - 360,000
Term Life Insurance & Medical Coverage
GrabFlex benefits package
Parental & Birthday leave
+2
Senior I, Workplace Technology
Senior I, Workplace Technology

Carsome Sdn Bhd • Petaling Jaya

On-site
MYR 180,000 - 240,000
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

GrabTaxi Holdings Pte. Ltd. • Petaling Jaya

On-site
MYR 180,000 - 300,000
Term Life Insurance
Medical Insurance
GrabFlex benefits
+4
Senior Application Engineer (Malaysia)
Senior Application Engineer (Malaysia)

InsiderSecurity • Kuala Lumpur

On-site
MYR 89,000 - 134,000
Annual flexi benefits
Health screening reimbursement
18 days annual leave
Senior Application Engineer (Malaysia)
Senior Application Engineer (Malaysia)

Insider Security Pte Ltd • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Competitive salary package
Annual flexi benefits
18 days annual leave
+1
Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH • Kuala Lumpur

On-site
MYR 140,000 - 230,000
Senior Application Engineer
Senior Application Engineer

INSIDERSECURITY MALAYSIA SDN. BHD. • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Annual 18 days leave
Annual flexi benefits
Health screening expenses
+1
Senior Cyber Security Operations Engineer
Senior Cyber Security Operations Engineer

Oxydata Software Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000