SENIOR SOFTWARE ENGINEER - Application Security

Happiest Minds Technologies

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Happiest Minds Technologies in Kuala Lumpur, Malaysia, seeks a Senior Software Engineer-Security to lead VAPT, red team exercises, and DevSecOps integration within CI/CD pipelines. You will collaborate with cross-functional teams to strengthen security controls and align with OWASP, NIST, and SSDF.

The role requires 5+ years in security engineering, hands-on experience with Burp Suite, Nmap, Metasploit, and cloud security assessments in Azure and AWS, plus OSCP or equivalent desirable.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 5+ years of experience in security engineering or related role.
  • OSCP certification or equivalent desirable.

Responsibilities

  • Perform comprehensive Vulnerability Assessments and Penetration Testing (VAPT) across web apps, APIs, cloud environments, and enterprise infrastructure.
  • Execute Red Team engagements emulating real-world adversaries using MITRE ATT&CK.
  • Integrate DevSecOps practices into CI/CD pipelines with tools like GitHub Actions, GitLab CI, Jenkins, Checkmarx, SonarQube, Trivy, and Semgrep.
  • Conduct threat modeling, secure code reviews, and IaC assessments for Terraform and CloudFormation.

Skills

application security
VAPT
Burp Suite
Nmap
Metasploit
cloud security
MITRE ATT&CK
DevSecOps
CI/CD

Education

Bachelor's degree in Computer Science or related field

Tools

Burp Suite
Nmap
Metasploit
ScoutSuite
Prowler
Pacu
Terraform
CloudFormation

Job description

Senior Software Engineer-Security

Location: Kuala Lumpur, Malaysia

Years of Experience: 5+ Years

We are seeking a highly skilled Senior Security Engineer with a strong background in application security to join our team. The ideal candidate will possess extensive knowledge in performing Vulnerability Assessments and Penetration Testing (VAPT), executing Red Team engagements, and integrating DevSecOps practices into CI/CD pipelines. This role requires collaboration with cross-functional teams to enhance security measures and ensure compliance with industry standards.

Responsibilities
  • Perform comprehensive Vulnerability Assessments and Penetration Testing (VAPT) across web applications, APIs, cloud environments, and enterprise infrastructure to identify and mitigate security risks.
  • Execute Red Team engagements by emulating real-world adversary tactics using the MITRE ATT&CK framework to evaluate organizational security posture and detection capabilities.
  • Integrate DevSecOps practices into CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, Checkmarx, SonarQube, Trivy, and Semgrep, enabling automated SAST, DAST, SCA, and secrets scanning.
  • Conduct threat modeling, secure code reviews, and infrastructure-as-code assessments for Terraform and CloudFormation, ensuring secure cloud deployments and compliance with security standards.
  • Perform cloud security assessments across Azure and AWS environments, implementing secure secrets management with Azure Key Vault and strengthening cloud security controls.
  • Collaborate with developers, architects, and security teams to perform root cause analysis, recommend remediation strategies, and enhance secure application development practices.
  • Produce detailed technical reports, risk assessments, and executive-level security findings with actionable remediation recommendations aligned with OWASP, NIST, and SSDF frameworks.
  • Leverage expertise in offensive security tools including Burp Suite, Nmap, Metasploit, ScoutSuite, Prowler, and Pacu, while maintaining an OSCP-certified approach to continuous security improvement and proactive threat defense.
Mandatory Skills
  • Strong knowledge of application security principles and practices.
  • Experience with Vulnerability Assessments and Penetration Testing (VAPT).
  • Proficiency in using offensive security tools such as Burp Suite, Nmap, and Metasploit.
  • Hands-on experience with cloud security assessments in Azure and AWS.
  • Familiarity with the MITRE ATT&CK framework.
Preferred Skills
  • Experience with DevSecOps practices and CI/CD pipeline integration.
  • Knowledge of secure coding practices and threat modeling.
  • Familiarity with infrastructure-as-code tools like Terraform and CloudFormation.
  • Understanding of security frameworks such as OWASP, NIST, and SSDF.
Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in security engineering or a related role.
  • OSCP certification or equivalent is highly desirable.

Application Security, Vulnerability Assessment

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer: VAPT, Red Team & DevSecOps
Senior Security Engineer: VAPT, Red Team & DevSecOps

Happiest Minds Technologies • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services Sdn. Bhd. • Kuala Lumpur

On-site
MYR 90,000 - 180,000
Cyber Security Consultant
Cyber Security Consultant

ABeam Consulting Malaysia • Petaling Jaya

On-site
MYR 60,000 - 120,000
Security Engineer – Vulnerability Management - VAPT
Security Engineer – Vulnerability Management - VAPT

Ascendion • Cyberjaya

On-site
MYR 60,000 - 120,000
Senior Wintel Security Engineer / Infrastructure Security Enginee
Senior Wintel Security Engineer / Infrastructure Security Enginee

Unison Group • Kuala Lumpur

On-site
MYR 120,000 - 190,000
Security Operation Engineer - BAU
Security Operation Engineer - BAU

ADI Resourcing • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Cybersecurity Engineer
Cybersecurity Engineer

Mission Consultancy Services Malaysia • Kuala Lumpur

On-site
MYR 89,000 - 167,000
Salary 8k-15k MYR
Certifications support
Career development
Senior BAU (Senior Security Operation Engineer)
Senior BAU (Senior Security Operation Engineer)

ADI Resourcing • Kuala Lumpur

On-site
MYR 110,000 - 170,000
Senior Application Engineer (Malaysia)
Senior Application Engineer (Malaysia)

Insider Security Pte Ltd • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Competitive salary package
Annual flexi benefits
18 days annual leave
+1