- Kuala Lumpur Federal Territory Malaysia
Lokasi Kerja
Penerangan Kerja
Tanggungjawab
At Provido Global, we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence.
Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world.
As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact.
If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here.
Why We Need You
Application Security Manager is responsible for defining, implementing, and leading the application security program across the organization's products, platforms, and software development lifecycle.
This role drives secure software development practices, threat modeling, secure code review, application vulnerability management, and security testing across web, mobile, API, and client and server applications.
The Lead partners closely with engineering, DevOps, product, and development teams to embed security into the SDLC, mature DevSecOps tooling and automation, and reduce application-layer risk across the organization's customer-facing and internal applications.
The role is based on-site in Kuala Lumpur and requires strong technical depth in application security, hands-on engineering credibility, and the ability to influence engineering leaders, technology teams and business stakeholders.
What You’ll Be Doing
Lead the application security program by setting strategy, standards, secure coding guidelines, and policies covering web, mobile, API, and application security across the organization.
Drive threat modeling, architecture security reviews, and secure design consultations for new products, digital services, platforms, and customer-facing features.
Own the application security testing toolchain — SAST, DAST, SCA, IAST, secrets scanning, and fuzz testing — and integrate it into CI/CD pipelines across engineering and studio teams.
Manage the application vulnerability lifecycle, including triage, prioritization, remediation tracking, SLA enforcement, and reporting to engineering leadership and executive stakeholders.
Lead manual secure code reviews, coordinate penetration testing engagements, and operate the bug bounty program, validating findings and driving remediation with development teams.
Build and deliver secure coding training, developer enablement programs, and security champions networks across engineering and development organizations.
Partner with DevOps and platform teams to harden build pipelines, container images, cloud-native workloads, and backend services against application-layer attacks.
Maintain awareness of application security threats and trends affecting the technology organizations, and Southeast Asia regulatory expectations relevant to the organization.
What You Bring to the Team
Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or a related discipline.
5+ years of experience in application security, product security, or secure software engineering, including at least 2 years in a lead or senior individual contributor capacity.
Strong understanding of common application vulnerabilities (OWASP Top 10, OWASP API Top 10, OWASP Mobile Top 10), exploitation techniques, and defensive coding patterns.
Hands-on experience with SAST, DAST, SCA, and IAST tooling and their integration into CI/CD pipelines (e.g., Checkmarx, Veracode, Snyk, Semgrep, Burp Suite, OWASP ZAP).
Proficiency in at least one modern programming language (C#, C++, Java, Go, Python, JavaScript/TypeScript) and the ability to read and review code across multiple technology stacks.
Availability to work on-site in Kuala Lumpur and support occasional out-of-hours engagement with global engineering teams across time zones.
Preferred Skills
Professional certifications such as OSCP, OSWE, GWAPT, GMOB, CSSLP, CISSP, Burp Suite Certified Practitioner, or equivalent application security credentials.
Experience securing interactive digital products, including client-server architectures, real-time services, or user abuse prevention.
Experience with cloud-native application security on AWS, Azure, or GCP, including Kubernetes, serverless, and container security.
Familiarity with threat modeling methodologies (STRIDE, PASTA, attack trees) and security architecture review practices at scale.
Knowledge of OWASP SAMM, BSIMM, NIST SSDF, or similar secure software development maturity frameworks.
Understanding of compliance-focused environments and the importance of documented analysis, control adherence, secure SDLC governance, and audit support.
Why You’ll Love Working with Us
At Provido Global, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment.
Peringatan Penting
Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.