Lead Application Security Engineer
Encora10 · Kuala Lumpur · 2026-06-22
About this role
<p>Key Responsibilities:&nbsp;<br>● Threat Modeling: Lead design reviews for new banking features (Payments, Transfers,&nbsp;<br>KYC). Identify logic flaws before code is written.&nbsp;<br>● Pipeline Automation: Architect and maintain the SAST/DAST/SCA tooling in the CI/CD&nbsp;<br>pipeline (e.g., SonarQube, Snyk, GitLab CI) to block vulnerabilities automatically.&nbsp;<br>● Code Review: Perform manual code audits on high-risk components (Authentication,&nbsp;<br>Ledger logic) in Java, Kotlin, or Swift.&nbsp;<br>● Cloud &amp; AI Patterns: Deliver API, container, cloud, and AI security design patterns.&nbsp;<br>Ensure that developers have "paved roads" (secure templates) for deploying&nbsp;<br>microservices and AI models.&nbsp;<br>● Culture: Act as a mentor to the development team, running secure coding workshops and&nbsp;<br>championing a "Security Champion" program.&nbsp;</p> <p>Technical Requirements:&nbsp;<br>● 5+ years in Application Security with a background in Software Development.&nbsp;<br>● Proficiency in at least one core language: Java (Spring Boot), Node.js, or Go.&nbsp;<br>● Deep understanding of OWASP Top 10 and SANS Top 25.&nbsp;<br>● Experience with CI/CD integration (Jenkins, GitHub Actions).&nbsp;<br>● Bonus: Experience in Fintech or Banking.</p>
Skills asked for
- ci/cd
- gitlab ci
- java
- kotlin
- swift
- microservices
- spring boot
- node.js
Similar jobs
- Solution Lead - Application and MobileEncora10 · Kuala Lumpur
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.