A complete application in a minute — tailored resume and cover letter, ready to send.
Carsome Sdn Bhd is hiring a Senior Application Security Engineer to identify, validate, and drive remediation of security vulnerabilities across Carsome Group’s applications and DevSecOps pipelines. The role blends offensive security with DevSecOps engineering to scale security through automation.
This hands-on position requires expertise in internal/external penetration testing, OWASP Top 10/ASVS, and CI/CD security practices.
The Senior Application Security Engineer is a hands-on technical role, responsible for identifying, validating, and driving remediation of security vulnerabilities across Carsome Group’s applications and DevSecOps CI/CD pipelines. The role combines strong offensive security skills (internal penetration testing) with DevSecOps engineering, and a mandate to scale the security function through automation.
Plan, scope, and execute internal penetration tests against web, mobile, and API applications and internal network/infrastructure assets, producing clear technical reports with risk ratings and remediation guidance.
Triage and validate findings generated by Application Security tooling (SAST/DAST/SCA), Bug Bounty tooling, and DevSecOps CI/CD pipeline scans, filtering false positives and duplicates and confirming real, exploitable issues before escalation to engineering.
Own and continuously improve the vulnerability triage and remediation workflow, including SLA prioritization based on exploitability, asset exposure (public/private), and asset criticality.
Design, build, and maintain automation workflows to automatically classify, prioritize, and route vulnerability findings into Jira with minimal manual intervention.
Partner with DevOps/Platform engineering to embed security gates (SAST, DAST, SCA, secrets and container/image scanning) into CI/CD pipelines, and continuously tune tooling to reduce noise.
Perform manual secure code review and threat modelling for high-risk features and new services.
Coordinate and support the bug bounty programme and external VAPT engagements, including validating and triaging externally reported findings.
Track and report on remediation SLA compliance, elevate breaches, and drive the exception / risk-acceptance process for findings that cannot be remediated within SLA.
Mentor the mid-level Security Engineer and act as the technical escalation point for complex or high-severity findings.
Stay current with emerging attack techniques, OWASP Top 10/ASVS, and cloud-native application security practices, and champion secure coding practices across engineering teams.
5+ years of experience in application security, penetration testing, or a related offensive security role, with demonstrable experience performing internal and/or external penetration tests.
Strong hands-on experience with web and API application security testing methodologies (OWASP Top 10, OWASP ASVS) using tools such as Burp Suite Professional.
Solid understanding of DevSecOps practices and CI/CD pipeline security (SAST, DAST, SCA, container and secrets scanning); GitLab CI/CD experience is a plus.
Practical experience triaging and validating findings from automated scanning platforms and prioritizing remediation based on risk.
Familiarity with Jira-based vulnerability management and SLA-driven remediation processes.
Strong written and verbal communication skills, able to translate technical findings into clear, actionable reports for engineering and leadership audiences.
Relevant certifications (e.g., OSCP, OSWE, GWAPT, CEH, eWPT, eCPPT, eMAPT) are highly regarded.
Your application will include the following questions:
CARSOME is Southeast Asia’s largest integrated car e-commerce platform. With operations across Malaysia, Indonesia, Thailand and Singapore, CARSOME aims to digitize the region’s used car industry by reshaping and elevating the car buying and selling experience.
The company provides end-to-end solutions to consumers and used car dealers, from car inspection to ownership transfer to financing, promising a service that is trusted, convenient and efficient. CARSOME currently transacts around 100,000 cars annually and has more than 2,000 employees across all its offices.
For more information, please visit www.carsome.my