Application Security Engineer AppSec
Bjak · Remote – worldwide
- Salary
- Not stated
- Posted
- 5d ago
- Source
- Himalayas
Job description
About BJAK
The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.
Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.
Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.
We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.
If you're this person, we'd love to talk to you.
The Role
Secure BJAK's web applications, APIs, and backend services, coordinating with mobile stakeholders on cross-platform risks. Embed security into design, development, testing, and release workflows.
What You Will Build
• Perform security reviews, code reviews, and testing for web applications, APIs, and backend services.
• Identify, prioritize, and help remediate injection, broken access control, authentication, and configuration vulnerabilities.
• Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines.
• Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.
• Coordinate with mobile engineers on cross-platform findings and backend controls protecting native iOS and Android clients.
• Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation.
• Provide secure coding guidance, track remediation, retest fixes, and improve developer security awareness.
What We Look For
• Degree in Computer Science, Cybersecurity, or related discipline, or equivalent experience.
• 3+ years in application security, penetration testing, or secure software development.
• Experience implementing and owning SC TRM and BNM RMiT application security and secure SDLC requirements.
• Strong understanding of OWASP Top 10, OWASP API Security Top 10, web vulnerabilities, API security, and secure design.
• Hands-on experience with Burp Suite, OWASP ZAP, SAST, DAST, and dependency scanning tools.
• Experience reviewing TypeScript/Node.js and Python services; familiarity with Swift, Kotlin, AWS, and GCP.
• Able to work closely with developers, explain findings, and support remediation.
Language
English is our main working language across global teams. Strong English communication is required.
Originally posted on Himalayas
Saffa.global isn't the employer or recruiter. Never pay anyone for a job offer, visa or "processing fee".
Similar jobs
Senior Support Engineer
Town Web · Remote – Anywhere in the World
Headquarters: United States URL: https://townweb.com Senior Support Engineer Town Web · HeyGov · ClerkMinutes. Remote, Central US hours. $85,000 to $105,000 a year. Open to candidates in the United States, Canada, the United Kingdom, and Ireland. About us We make municipal software built for clerks: websites residents can use, forms and payments that replace stacks of paper, and meeting minutes…
Director, Enterprise Sales Engineering - US Central
Datadog · Remote – Anywhere in the World
Headquarters: Illinois, USA, Remote; Michigan, USA, Remote; Texas, USA, Remote As a Director, Enterprise Sales Engineering, you will lead a team of frontline leaders, driving account strategy, deal execution, operational excellence, and team development across your region. This is a strategic leadership role with regional impact within North America. You will act as a force multiplier by owning…
SIRT Engineer Expression of Interest Form
GitLab · Remote – worldwide
GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations.
MSP Technical Support Specialist
Hire Hangar · Remote – incl. South Africa
Join Hire Hangar and work with fast-growing global companies while building a long-term career.
Senior Research Engineer
AssemblyAI · Remote – Anywhere in the World
Headquarters: Remote Why AssemblyAI AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. Our models serve 600M+ inference calls monthly, process 1M+ hours of audio daily, and power 2 billion+ end-user experiences. The Voice AI space is at an inflection point; we’re looking for folks truly excited to join a small team and help define the future of…
Senior Engineer
G2i · Remote – worldwide
Loom Overview Watch this loom videofrom our CEO, Gabe Greenberg, for more details about the role!