- Jalan PJU 7/24 Petaling Jaya Selangor Malaysia 47810

Lokasi Kerja
Penerangan Kerja
Kelayakan
5+ years of software engineering experience with strong fullstack skills — backend (Node.js/Go/Python/.NET/PHP/Rust/Ruby/Java or equivalent) and frontend (React/Vue/Angular/SolidJS or equivalent) — enough to confidently read, debug, and patch real production code across the stack, not just review it.
Solid, practical understanding of web and API vulnerability classes (OWASP Top 10, OWASP API Security Top 10) and how to actually fix them in code, not just describe them.
Comfortable working directly from vulnerability scan reports, pentest reports, and bug bounty submissions to root-cause and fix issues.
Familiarity with CI/CD pipelines and experience resolving findings from embedded SAST/SCA/DAST tooling as part of the development workflow.
Experience working with bug bounty programs and triaging external researcher submissions is a bonus.
Familiarity with Kubernetes and containerized application environments is a bonus.
Tanggungjawab
Vulnerability Remediation:
Own end-to-end remediation of vulnerabilities identified through Web, API, Bug Bounty submissions, and external penetration tests.
Write and ship code-level fixes for application vulnerabilities (e.g., OWASP Top 10, OWASP API Security Top 10, authentication flaws, injection, SSRF, insecure deserialization) directly in relevant codebases (GitHub/GitLab/Bitbucket).
Triage findings from Security tools (SAST/SCA/Secrets/DAST) to validate true positives and prioritize based on exploitability and business risk.
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
Build lightweight internal tooling/scripts to help automate triage, tracking, or reporting of vulnerability and posture data where useful (e.g., feeding dashboards, Jira, or a reporting tool).
Manfaat
Kemahiran
TAMAN JAYA
0.3 km
ASIA JAYA
1.1 km
UNIVERSITI
2.0 km
Peringatan Penting
Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.