Posted today · be early
Application Security Engineer AppSec
Bjak
WorldwideremotePosted today
Skill Required
Application-Security-EngineerAppSec-EngineerSenior-Application-Security-EngineerApplication-Security-AnalystApplication-Security-SpecialistLead-Application-Security-EngineerApplication-Security-EngineeringApplication-Security-ArchitectAppSec-EngineeringApplication-Security-LeadSecurity-EngineerSecurity EngineerApplication DevelopersecurityPenetration TestingOWASPCybersecurityCD pipelinesBurp SuiteTypeScriptNode.jsbuildingAndroidTestNGPythonKotlindesignSwiftCI/CDAPIsiOSAWSGCPandCICDFulltime
Key highlights
- 3+ years in application security, penetration testing, or secure software development
- Required experience with SC TRM and BNM RMiT
- Strong English communication required
Role overview
BJAK is a leading insurance platform in Southeast Asia, founded in 2019 with a mission to provide smarter ways for people to plan, save, and grow their money. The company is expanding into spending, saving, investing, exchanging, and traveling, employing a global team of over 20 nationalities. The role involves securing BJAK's web applications, APIs, and backend services, coordinating with mobile stakeholders on cross-platform risks, and embedding security into design, development, testing, and release workflows.
Responsibilities
- Perform security reviews, code reviews, and testing for web applications, APIs, and backend services.
- Identify, prioritize, and help remediate injection, broken access control, authentication, and configuration vulnerabilities.
- Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines.
- Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.
- Coordinate with mobile engineers on cross-platform findings and backend controls protecting native iOS and Android clients.
- Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation.
- Provide secure coding guidance, track remediation, retest fixes, and improve developer security awareness.
Requirements
- Degree in Computer Science, Cybersecurity, or related discipline, or equivalent experience.
- 3+ years in application security, penetration testing, or secure software development.
- Experience implementing and owning SC TRM and BNM RMiT application security and secure SDLC requirements.
- Strong understanding of OWASP Top 10, OWASP API Security Top 10, web vulnerabilities, API security, and secure design.
- Hands-on experience with Burp Suite, OWASP ZAP, SAST, DAST, and dependency scanning tools.
- Experience reviewing TypeScript/Node.js and Python services.
- Able to work closely with developers, explain findings, and support remediation.
- Strong English communication is required.
Nice to have
- Familiarity with Swift, Kotlin, AWS, and GCP.
Additional details
- English is our main working language across global teams.
- Originally posted on Himalayas