job description
Join a dynamic Information Security team as an Application Security Engineer in the heart of Bali! This is a unique opportunity to work closely with Engineering, Infrastructure, and cross-functional teams to ensure the security and resilience of our applications in a fast-paced, innovative environment.
As a key player in safeguarding our digital assets, you will identify vulnerabilities, implement robust security measures, and drive best practices across the software development lifecycle. Your expertise will directly contribute to protecting our systems from emerging threats while enabling seamless, secure user experiences.
Based in Baliâs vibrant tech hubsâCanggu, Ubud, Denpasar, or surrounding areasâyouâll collaborate with global teams while enjoying the islandâs inspiring work-life balance. If youâre passionate about application security, threat modeling, and secure coding, weâd love to hear from you!
Responsibility
- Conduct comprehensive security assessments (SAST/DAST) on applications to identify and mitigate vulnerabilities.
- Develop and enforce secure coding standards and best practices across development teams.
- Collaborate with Engineering and DevOps to integrate security controls into CI/CD pipelines.
- Perform threat modeling and risk assessments for new and existing applications.
- Monitor and respond to security incidents, conducting root cause analysis and remediation.
- Automate security testing processes to improve efficiency and scalability.
- Educate teams on OWASP Top 10, secure design principles, and emerging security threats.
- Stay ahead of industry trends and recommend proactive security enhancements.
Qualifications
- Bachelorâs degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 3+ years of experience in Application Security, Penetration Testing, or Secure SDLC.
- Proficiency in SAST/DAST tools (e.g., Burp Suite, OWASP ZAP, SonarQube, Checkmarx).
- Strong knowledge of OWASP Top 10, SANS Top 25, and common web application vulnerabilities.
- Experience with secure coding practices (e.g., Python, Java, JavaScript, Go).
- Familiarity with cloud security (AWS, GCP, Azure) and containerization (Docker, Kubernetes).
- Certifications such as CISSP, CEH, OSCP, or CSSLP are a plus.
- Excellent problem-solving, communication, and teamwork skills.