Senior Specialist Application Security Engineer

DKSH Management Ltd.

Kuala Lumpur

On-site

MYR 150,000 - 210,000

Full time

30 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

DKSH Management Ltd. in Kuala Lumpur, Malaysia, is seeking a Senior Specialist Application Security Engineer to safeguard our digital landscape across the full software development lifecycle.

You will drive application security assurance, coordinate penetration testing, and lead remediation tracking with stakeholders. You will apply deep knowledge of OWASP Top 10, API security, and secure SDLC practices to deliver practical guidance, reports, and governance across internal, partner, and

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field; certifications preferred.
  • 5+ years in application security, penetration testing, or security assurance.
  • Experience coordinating application penetration testing and remediation tracking.
  • Strong knowledge of OWASP Top 10, API security and secure coding.
  • Experience with Burp Suite, ZAP, Invicti, Qualys and SAST/DAST/SCA tooling.

Responsibilities

  • Coordinate and manage application penetration testing activities.
  • Conduct/lead technical security assessments for web, API, mobile, cloud, and enterprise apps.
  • Own vulnerability tracking from discovery to remediation.
  • Provide remediation guidance for common web vulnerabilities (e.g., SQLi, XSS, auth flaws).
  • Support secure SDLC activities and security sign-off.
  • Prepare executive and technical reports on findings, remediation status, and risk.
  • Drive remediation coordination across application owners, developers, QA, vendors, and security teams.
  • Collaborate with SOC and infrastructure to strengthen defenses against application attacks.
  • Champion secure-by-design and risk-based application delivery.

Skills

Application Security
Penetration Testing Coordination
Vulnerability Management
Secure SDLC
OWASP Top 10
Burp Suite
OWASP ZAP
Invicti
Qualys
SAST/DAST/SCA tooling

Education

Bachelor's degree in Cybersecurity/related field

Tools

Burp Suite
OWASP ZAP
Invicti
Qualys

Job description

Title: Senior Specialist Application Security Engineer

Location: Kuala Lumpur, MY, MY

Global Business Unit: OTH

Job Function: Information Technology

Requisition Number: 246482

About the Role

As an Application Security Engineer, you play a critical role in safeguarding DKSH's digital landscape by driving application security assurance across the full software development lifecycle. Your expertise in penetration testing, vulnerability management, and Application Security (AppSec) governance ensures that internal, third-party, and internet-facing applications are protected, resilient, and aligned with DKSH's security standards.

What You Will Deliver
  • Coordinate and manage application penetration testing activities including scoping, scheduling, evidence collection, vendor coordination, report review, retest tracking, and closure validation to ensure testing outcomes are thorough and actionable.
  • Conduct or support technical security assessments for web, Application Programming Interface (API), mobile, cloud-hosted, and enterprise applications using manual testing and automated tools, delivering findings that drive meaningful risk reduction.
  • Own application vulnerability tracking from discovery through to remediation, ensuring findings are categorized by severity, affected application, owner, risk, due date, and closure status to maintain full visibility and accountability.
  • Provide clear and practical remediation guidance for vulnerabilities including SQL injection, Cross-Site Scripting (XSS), authentication flaws, insecure direct object references, weak encryption, insecure configuration, vulnerable components, and missing logging.
  • Support secure Software Development Lifecycle (SDLC) activities including security requirements, threat modeling inputs, secure coding guidance, release checks, and security sign-off criteria to embed security throughout application delivery.
  • Prepare executive and technical reports summarizing critical and high findings, remediation status, risk themes, aging, recurring weaknesses, and business impact to support informed decision-making.
  • Drive remediation coordination across application owners, developers, Quality Assurance (QA) teams, vendors, infrastructure, and security operations to ensure vulnerabilities are resolved effectively and on time.
  • Influence application teams to validate closure based on evidence, ensuring remediation outcomes are substantive rather than administrative.
  • Collaborate with Security Operations Center (SOC) and infrastructure teams to strengthen prevention and detection capabilities against application attacks, webshell risk, credential abuse, and exploitation attempts.
  • Champion secure-by-design and risk-based application delivery practices across the organization.
What You Bring
  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or equivalent practical experience. Preferred certifications include GWAPT, GWEB, Offensive Security Certified Professional (OSCP), Practical Network Penetration Tester (PNPT), Certified Secure Software Lifecycle Professional (CSSLP), Certified Ethical Hacker (CEH), Security+, or equivalent.
  • 5 or more years of cybersecurity experience with a focus on application security, penetration testing, vulnerability management, secure SDLC, or security assurance.
  • Proven capability in application penetration testing coordination, report review, vulnerability validation, and remediation tracking.
  • Strong knowledge of OWASP Top 10, API security, authentication and session management, secure coding, web server hardening, Web Application Firewall (WAF) concepts, and risk-based remediation.
  • Experience with tools such as Burp Suite, Invicti, OWASP ZAP, Qualys, Microsoft Defender, and Static Application Security Testing/Dynamic Application Security Testing/Software Composition Analysis (SAST/DAST/SCA) tooling, ticketing systems, and reporting dashboards is preferred.
  • Ability to translate technical vulnerabilities into practical, actionable remediation guidance for developers, vendors, system teams, and management.
  • Skilled in maintaining penetration test trackers, vulnerability aging reports, remediation dashboards, and risk acceptance documentation.
Why Join DKSH

At DKSH, we help companies grow in Asia and enable people to perform at their best. You will be part of an organization that values accountability, collaboration, and long-term partnerships. We offer a dynamic environment where your contributions are visible and where you can build a meaningful career in Application Security.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Specialist Application Security Engineer
Senior Specialist Application Security Engineer

DKSH • Kuala Lumpur

On-site
MYR 140,000 - 230,000
Senior Application Security Engineer: AppSec Lead
Senior Application Security Engineer: AppSec Lead

DKSH Management Ltd. • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Senior AppSec Engineer - Lead Secure SDLC & Remediation
Senior AppSec Engineer - Lead Secure SDLC & Remediation

DKSH Group • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Technical Lead Security Operations
Technical Lead Security Operations

DKSH Management Ltd. • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Application Security Engineer
Senior Application Security Engineer

Carsome Sdn Bhd • Petaling Jaya

On-site
MYR 180,000 - 240,000
Senior AppSec Engineer: Lead Secure SDLC & Risk
Senior AppSec Engineer: Lead Secure SDLC & Risk

DKSH • Kuala Lumpur

On-site
MYR 140,000 - 230,000
Manager Business Applications
Manager Business Applications

DKSH Management Ltd. • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Staff Cybersecurity & OT Security Engineer
Staff Cybersecurity & OT Security Engineer

Oxydata Software Sdn Bhd • Penang

On-site
MYR 180,000 - 240,000
Senior Executive - Cybersecurity
Senior Executive - Cybersecurity

BDO Malaysia • Kuala Lumpur

On-site
MYR 60,000 - 110,000
Senior Application Engineer (Malaysia)
Senior Application Engineer (Malaysia)

Insider Security Pte Ltd • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Competitive salary package
Annual flexi benefits
18 days annual leave
+1