Web Application Security Engineer

1 day ago


Malaysia CXM Direct LLC Full time 60,000 - 120,000 per year
Position Overview

We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.

This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.

Core ResponsibilitiesOffensive Security (Penetration Testing)

The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.

You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL/TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.

Defensive Security (Blue Team Operations)

On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.

You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.

Purple Team Collaboration

As a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.

You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.

Security Integration and Automation

You will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.

Required Qualifications
  • Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
  • ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
  • Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
  • Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
  • Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
  • Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
  • Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF/IPS
  • Hands-on experience configuring and tuning web application firewalls and deep packet inspections
Preferred Qualifications

Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.

Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.

Competitive Compensation

Medical

Gym Allowance

Company Events

Personal Growth


  • Security Engineer

    1 day ago


    Malaysia AceTeam Full time 60,000 - 80,000 per year

    AceTeam Networks is committed to take IT beyond with our customers and pledge to be the best, while strengthening the focus towards becoming a people centric company and not just limiting to technologies.We are looking for a Security Engineer who would like to grow with us, clearly defined by three things:CommITted · Connected · ConvergedAs a Security...


  • Malaysia 12u12 Full time

    Web Application Product Manager **Responsibilities**: - Conduct studies, analyze and consolidate consumer information/data - Provide insightful analysis on competitive product features, pricing, market trends, segmentation studies, consumer behavior, etc. and convert into strategy - Test product to ensure implementation meeting specifications - Provide...


  • Malaysia 12u12 Full time

    Web Application Market Research Executive **Responsibilities**: - Conduct studies, analyze and consolidate consumer information/data - Provide insightful analysis on competitive product features, pricing, market trends, segmentation studies, consumer behavior, etc. and convert into strategy - Assist superior in ad-hoc assignments and take lead role in...


  • Malaysia Payments Network Malaysia Full time 80,000 - 120,000 per year

    SUMMARY OF RESPONSIBILITIESPart of the Security Engineering team, responsible for co-developing solutions and automation workflows to improve the overall security posture of PayNet.Serve as a change agent in automation initiatives, building pipelines to enhance operational efficiency.Ensure that sound security controls are in place, commensurate with...

  • Web Developer

    1 day ago


    Petaling Jaya, Malaysia ARRK Engineering Full time 60,000 - 120,000 per year

    Web Developer (m/f/x)about the roleWe're looking for a creative and detail-oriented Web Developer to join our growing team. You'll be part of our international team and are responsible for building and maintaining high-quality web applications that deliver exceptional user experiences. If you're passionate about clean code, responsive design, and modern...


  • Malaysia IntersoftKK Full time

    Malaysia **Experience**: Backend and Web Developer **Skills**:Backend and Web Developer **Min Year or Exp** **Responsibilities **Mandatory Skills** **Optional Skills** 8 Years and min 1-year experience with IBM Watson Solutions Develop secure software components that can be reused for building multigrained services. Responsible to develop and...

  • Security Analyst

    1 day ago


    Malaysia AceTeam Full time 30,000 - 60,000 per year

    AceTeam is committed to take IT beyond with our customers and pledge to be the best, while strengthening the focus towards becoming a people centric company and not just limiting to technologies.We are looking for a Security Analyst who would like to grow with us, clearly defined by three things:CommITted · Connected · ConvergedAs a Security Analyst, you...


  • Malaysia Amazon Data Services Malaysia Sdn. Bhd. Full time

    Completion of tertiary level education - Proficiency with MS Office - Read, write, and speak business level English language - Good report writing skills Amazon Web Services (AWS) is looking to hire a highly motivated, customer-obsessed individual to provide hands-on support to our Data Center Infrastructure Operations across SIN Cluster. (Data Center...


  • Malaysia - KL Eco City FWD Group Full time 120,000 - 180,000 per year

    About FWD GroupFWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD's customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler insurance experience. Established in 2013, the...


  • Malaysia CompAsia Full time 60,000 - 120,000 per year

    Job DescriptionWe are looking for a detail-oriented and proactive Senior Application Support Engineer to join our IT support team. This role primarily involves ensuring the seamless operation of our applications by addressing and resolving application issues, monitoring application uptime, and tracking Service Level Agreements (SLA). The ideal candidate will...