job description
Join a pioneering fintech leader as the Lead Application Security Engineer and shape the future of secure digital banking in Southeast Asia. In this high-impact role, you'll lead the charge in protecting mission-critical financial systems from evolving cyber threats while fostering a culture of security-first development.
Based in Bali's vibrant tech hub (Canggu, Ubud, Denpasar, or surrounding areas), you'll collaborate with cross-functional teams to embed security into every phase of the software development lifecycle. From threat modeling to secure coding practices and CI/CD automation, you'll ensure our digital banking platforms remain resilient against sophisticated attacks while maintaining compliance with global financial regulations.
This is more than a technical role - it's an opportunity to mentor security champions, influence architectural decisions, and drive innovation in secure financial technologies. If you're passionate about building secure systems that protect millions of users and thrive in a dynamic, remote-friendly environment, we want to hear from you.
Enjoy competitive compensation, flexible work arrangements, and the unique work-life balance that Bali offers. Join us in creating the next generation of secure digital banking solutions!
Responsibility
- Lead threat modeling sessions and security architecture reviews for digital banking applications
- Design and implement secure coding standards and best practices across development teams
- Develop and maintain automated security testing in CI/CD pipelines (SAST/DAST/IAST)
- Conduct regular security assessments, penetration testing, and vulnerability management
- Collaborate with DevOps teams to secure containerized environments and cloud infrastructure
- Mentor developers on secure coding practices and security awareness programs
- Drive security incident response and post-mortem analysis for application security events
- Stay ahead of emerging threats and recommend proactive security measures for financial systems
Qualifications
- 8+ years of experience in application security with 3+ years in a leadership role
- Strong expertise in secure coding practices (OWASP Top 10, SANS 25)
- Hands-on experience with security testing tools (Burp Suite, OWASP ZAP, Checkmarx, etc.)
- Proficient in CI/CD security automation and DevSecOps practices
- Experience with financial systems security and compliance (PCI DSS, ISO 27001, etc.)
- Familiarity with cloud security (AWS/Azure/GCP) and container security (Docker, Kubernetes)
- Excellent communication skills to influence stakeholders at all levels
- Relevant certifications (CISSP, CSSLP, OSCP, or similar) are highly desirable