An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Randstad Malaysia is seeking a Senior Application Security Specialist to strengthen security across the Software Development Lifecycle, DevSecOps and architecture. The role is hands-on, partnering with software engineering, Agile and DevOps teams to build secure applications and services.
You will embed Secure by Design and Shift‑Left practices, perform threat modelling, risk assessments and security reviews, and guide security controls across cloud-native environments.
about the company
Our client is a global financial technology and financial messaging organisation supporting critical financial services and institutions worldwide. The organisation operates within a highly regulated, security-critical technology environment where cybersecurity, application security, resilience and secure software development are fundamental to business operations.
With continued investment in cloud-native technologies, APIs, microservices, containers and DevSecOps, the organisation is strengthening its Application Security capability to ensure security is embedded throughout the software development lifecycle.
You will join an international and diverse technology security environment, working alongside experienced cybersecurity, engineering, architecture and technology professionals across global teams.
about the job
We are looking for a Senior Application Security Specialist to strengthen the organisation's Application Security, Product Security and Security Architecture capabilities.
This is a hands‑on Application Security / DevSecOps / Security Architecture role where you will act as a trusted security partner to software engineering, Agile, DevOps and DevSecOps teams, helping them build and operate secure applications and services.
You will be responsible for embedding security‑by‑design and shift‑left security practices throughout the Software Development Lifecycle (SDLC), from architecture and design through development, testing, deployment and operations.
Key responsibilities include:
Candidates with experience in the following areas will be highly relevant:
Application Security | Product Security | Security Architecture | Threat Modelling | Risk Assessment | Secure SDLC | DevSecOps | Security-by-Design | Shift-Left Security | OWASP Top 10 | SAST | DAST | SCA | API Security | API Testing | Container Security | Cloud Security | CI/CD Security | Vulnerability Management
Experience with AWS, Azure, GCP, Kubernetes, Docker, microservices or other cloud‑native technologies will be advantageous.
about the manager/team
You will join an international Application Security and IT Security team working closely with software engineering, architecture, DevOps and DevSecOps teams.
The team operates in a highly collaborative and technically complex environment, where security is embedded into technology delivery rather than treated as a separate function.
You will work with experienced cybersecurity professionals and technical SMEs across different countries and disciplines, with opportunities to contribute ideas, introduce new security approaches and influence how security is implemented across critical applications and services.
The ideal candidate is a hands‑on Application Security professional who can combine strong technical security knowledge with the ability to influence developers, engineers, architects and business stakeholders.
experience
4 years
skills
application security, cyber security, DevSecOps, Agile, Cloud Native, SAST, DAST, SCA
qualifications
application security, cyber security, DevSecOps, Agile, Cloud Native, SAST, DAST, SCA
education
Bachelor Degree