Engineer Application Security, Cybersecurity

4 days ago


Kuala Lumpur, Kuala Lumpur, Malaysia PSG Global Solutions Full time

This position will help implement and validate the security controls on Worldwide Company applications and will support the Application Security Practice and DevSecOps. The Application Security Engineer will contribute to the implementation, evaluation, and definition of new security standards and processes with company's application properties. This position will also assist in documenting and tracking application security policies, processes, procedures, standards, and controls. This position will apply secure application development best practices and provide support for security analysis and enforcement of defenses and countermeasures at each phase of the software development lifecycle, resulting in high-quality, robust, and reliable software.

Responsibilities/ Duties:

  • Oversee day-to-day activities related to the application security management system and the application security pipeline, including vulnerability management and code review.
  • Integrate security tools, standards, and processes into the Software Development Life Cycle (SDLC).
  • Ensure application teams and QA personnel are trained with the appropriate level of security knowledge to perform their daily activities.
  • Improve and support application security tool deployments, including static, dynamic analysis, runtime testing, and SCA tools.
  • Support the incident response and architecture review processes whenever application security expertise is needed.
  • Manage annual penetration testing services, including both expert consulting and managed services.
  • Define and enforce the vulnerability management process, including vulnerability assessments and penetration tests, as well as a continuous improvement process.
  • Support application security projects and vendor security activities to ensure third-party software and development meet Herbalife security standards.
  • Integrate threat modelling and Secure SDLC practices into the application development lifecycle.
  • Provide security requirements for test-driven application design.
  • Collaborate with other departments on their daily security requirements.
  • Work closely with Herbalife's Development teams to provide guidance on proper application security best practices and standards.
  • Support internal and external contractual, regulatory, and legal compliance relevant to application security.
  • Be available 24x7 for incident response and end-of-month support.

Qualifications Skills:

  • Knowledge of Secure SDLC best practices and familiar with implementation of application security controls.
  • Understanding of relevant application security vulnerabilities including OWASP Top 10, best practices, and testing methodologies.
  • Experience in penetration testing (Web, API, and Mobile Application) along with programming/scripting skills will be an advantage.
  • Familiarity with code review for Java, .Net and .Net Core, etc.
  • Ability to respond immediately to application security-related incidents and perform post-event analysis.
  • Adequate knowledge of web-related technologies (Web applications, Web Services, and Service-Oriented Architectures, API integration) and network/web-related protocols.
  • Adequate knowledge of OS, Networks, Cryptography, Databases, Web Technologies.
  • Knowledge of Application security tools such as Burp Suite, Kali Linux, Metasploit, etc.
  • General knowledge of build pipelines and CI/CD.
  • Ability and willingness to learn new skills quickly.
  • Flexibility to work in an agile and fluid environment.
  • Effective written and verbal communication skills.
  • Strong collaboration abilities and good communication skills.
  • Good oral and written communication skills in English.

Experience:

  • Related experience in the Application Cybersecurity, IT Security field, and application development operations.
  • Embedded Application information management systems into the application development lifecycle.
  • 3-5 years of penetration testing experience for web applications, mobile apps, etc.
  • Experience with Application security protection and testing tools such as DAST, IAST, SAST, MAST, RASP, WAF.
  • Familiarity with one of the programming languages and development tools in either of the following technology stacks: 1. JAVA-related development skills, framework, e.g., Java Spring MVC, Spring Cloud. 2. Windows Development APIs including C#, .NET framework, .NET Core.

Education:

  • Bachelor's degree in Computer Science, Information Technology, Business or equivalent discipline.
  • 3-5 years related experience and/or training; or equivalent combination of higher education and experience.
  • Technical Certifications such as OSCP, CISSP, CSWAE is preferred.
Seniority level
  • Not Applicable
Employment type
  • Full-time
Job function
  • Information Technology
Industries
  • Retail Health and Personal Care Products
#J-18808-Ljbffr

  • Kuala Lumpur, Kuala Lumpur, Malaysia Insider Security Pte Ltd Full time

    About the RoleAs a Cybersecurity Test Engineer at Insider Security Pte Ltd, you will be responsible for ensuring the quality and security of our software products through thorough testing and evaluation.ResponsibilitiesTest Planning and Execution: Develop and execute comprehensive test plans, including both manual and automated testing approaches, to...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    Crypto Cybersecurity TeamOverview of the RoleWe are seeking a highly skilled Cybersecurity Engineer Specialist to join our team at Crypto. As part of our Global Cybersecurity Services, the role will be engaged in enhancing our security technology stack, building AI-driven security automation workflows and contributing to security operations and threat...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Cisco Systems Full time

    What You'll DoThe Cybersecurity Solutions Engineer's prime responsibility is to provide technical sales support and recommendations to internal and external customers on the Cisco Security Solutions Portfolio. The successful candidate will have wide-ranging knowledge and experience across the information security domain. Through a consultative approach, the...

  • Security Engineer

    7 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    We are seeking a seasoned Cybersecurity Specialist to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI-driven security automation workflows and contributing to security operations.Key Responsibilities:Threat Monitoring...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    Specialist, Security Engineering & OperationsCrypto.com Kuala Lumpur, Federal Territory of Kuala Lumpur, MalaysiaWe are looking for an intermediate level security specialist to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    Specialist, Security Engineering & Threat ManagementCrypto.com Kuala Lumpur, Federal Territory of Kuala Lumpur, MalaysiaWe are looking for an intermediate level security specialist to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Cultivar Staffing & Search Full time

    About Us:Cultivar Staffing & Search is a Digital Marketing and IT consultancy company based in Kuala Lumpur. We are seeking a Cybersecurity and Cloud Engineer to join our team.Job Description:The successful candidate will design, build, and maintain secure cloud infrastructure on Amazon Web Services (AWS). They will also analyze network performance, resolve...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Planex Technology Sdn Bhd Full time

    Job Description:We are seeking an experienced Application Security Expert to join our team at Planex Technology Sdn Bhd.About the Role:We will provide training and guidance to developers on secure coding practices, common vulnerabilities (such as those listed in the OWASP Top 10), and how to avoid them.The ideal candidate should have a strong understanding...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    About Crypto:We are a cutting-edge company at the forefront of innovation in cybersecurity. Our team is passionate about protecting our customers from cyber threats and ensuring the integrity of their digital assets. We believe in empowering our employees to grow and develop their skills, and we offer a dynamic work environment that fosters collaboration and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    We are looking for a highly skilled Security Operations Engineer to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI-driven security automation workflows and contributing to security operations.Our team is focused on building a...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tech Titan Group - Titan Guard and Tech Titan Distribution Full time

    About the JobWe are looking for a Cybersecurity Technical Support Specialist to join our team at Tech Titan Group - Titan Guard and Tech Titan Distribution. As a Cybersecurity Technical Support Specialist, you will be responsible for providing technical support to customers, troubleshooting system issues, and documenting all support issue details.The ideal...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Seargin Full time

    Seargin Federal Territory of Kuala Lumpur, MalaysiaCybersecurity EngineerGet AI-powered advice on this job and more exclusive features.As a dynamic multinational tech company operating in 50 countries, we drive innovation and create projects that shape the future and greatly enhance the quality of life. You will find our solutions in the space industry,...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    Crypto is looking for a seasoned Cybersecurity Specialist to join our Global Cybersecurity Services Team. The ideal candidate will have a strong background in threat monitoring investigations, security engineering, incident response, cloud & container security, and vulnerability management.You will be responsible for deep diving into Tier 1 & Tier 2 security...

  • Security Engineer

    4 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia Prometric Ireland Limited Full time

    Kuala Lumpur, Federal Territory of Kuala Lumpur, MalaysiaJob DescriptionCybersecurity Engineer Job Overview:As a Prometric Security Engineer, you will be a core player who participates in and leads multiple security efforts. You will work closely with development teams, product managers, and our enterprise teams to ensure that Prometric brands and products...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Offshore Wind Consultants Ltd Full time

    As a Cybersecurity Engineer at Offshore Wind Consultants Ltd, you will play a vital role in protecting our organization's assets and maintaining a robust security posture.The ideal candidate will possess in-depth experience in IT systems or networking, as well as demonstrated expertise in integrated services. Additionally, they should have a strong...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Seargin Full time

    About the RoleWe are searching for a seasoned Cybersecurity Engineer to support our growth and innovation efforts at Seargin. As a key member of our cybersecurity team, you will contribute to the development of comprehensive security policies and procedures, assess and address security risks, and collaborate with stakeholders to ensure alignment with...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Finexus Group Full time

    Finexus Group WP. Kuala Lumpur, Federal Territory of Kuala Lumpur, MalaysiaApplication Security EngineerJob Brief:We also provide SaaS (Software as a Service) services which include infrastructure, platform, business processing outsourcing for banking and financial industry.Job Responsibilities:Overseeing overall development, implementation and maintenance...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    We are seeking a highly skilled Cybersecurity Specialist to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI-driven security automation workflows and contributing to security operations.The successful candidate will have...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Crypto Full time

    We are looking for an intermediate level security specialist to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI driven security automation workflows and contributing to security operations and threat management.We are building a...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Cisco Systems Full time

    Cybersecurity Solutions OverviewThe position of Cybersecurity Solutions Engineer at Cisco Systems is a technical sales role that focuses on providing expert support and recommendations to internal and external customers on the Cisco Security Solutions Portfolio. This involves articulating the benefits of the Cisco Security Platform and integrated...