JobBobsReal-time global job discoveryLive

Lead Application Security Engineer

Encora10 · Kuala Lumpur · 2026-06-22

lead
Apply on the employer's site

About this role

<p>Key Responsibilities: <br>● Threat Modeling: Lead design reviews for new banking features (Payments, Transfers, <br>KYC). Identify logic flaws before code is written. <br>● Pipeline Automation: Architect and maintain the SAST/DAST/SCA tooling in the CI/CD <br>pipeline (e.g., SonarQube, Snyk, GitLab CI) to block vulnerabilities automatically. <br>● Code Review: Perform manual code audits on high-risk components (Authentication, <br>Ledger logic) in Java, Kotlin, or Swift. <br>● Cloud & AI Patterns: Deliver API, container, cloud, and AI security design patterns. <br>Ensure that developers have "paved roads" (secure templates) for deploying <br>microservices and AI models. <br>● Culture: Act as a mentor to the development team, running secure coding workshops and <br>championing a "Security Champion" program. </p> <p>Technical Requirements: <br>● 5+ years in Application Security with a background in Software Development. <br>● Proficiency in at least one core language: Java (Spring Boot), Node.js, or Go. <br>● Deep understanding of OWASP Top 10 and SANS Top 25. <br>● Experience with CI/CD integration (Jenkins, GitHub Actions). <br>● Bonus: Experience in Fintech or Banking.</p>

Skills asked for

Similar jobs

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.