Web Application Security Engineer
1 day ago
We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.
This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.
Core ResponsibilitiesOffensive Security (Penetration Testing)The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.
You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL/TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.
Defensive Security (Blue Team Operations)On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.
You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.
Purple Team CollaborationAs a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.
You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.
Security Integration and AutomationYou will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.
Required Qualifications- Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
- ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
- Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
- Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
- Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
- Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
- Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF/IPS
- Hands-on experience configuring and tuning web application firewalls and deep packet inspections
Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.
Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.
Competitive Compensation
Medical
Gym Allowance
Company Events
Personal Growth
-
Security Engineer
1 day ago
Malaysia AceTeam Full time 60,000 - 80,000 per yearAceTeam Networks is committed to take IT beyond with our customers and pledge to be the best, while strengthening the focus towards becoming a people centric company and not just limiting to technologies.We are looking for a Security Engineer who would like to grow with us, clearly defined by three things:CommITted · Connected · ConvergedAs a Security...
-
Web Application Product Manager
2 weeks ago
Malaysia 12u12 Full timeWeb Application Product Manager **Responsibilities**: - Conduct studies, analyze and consolidate consumer information/data - Provide insightful analysis on competitive product features, pricing, market trends, segmentation studies, consumer behavior, etc. and convert into strategy - Test product to ensure implementation meeting specifications - Provide...
-
Web Application Market Research Executive
2 weeks ago
Malaysia 12u12 Full timeWeb Application Market Research Executive **Responsibilities**: - Conduct studies, analyze and consolidate consumer information/data - Provide insightful analysis on competitive product features, pricing, market trends, segmentation studies, consumer behavior, etc. and convert into strategy - Assist superior in ad-hoc assignments and take lead role in...
-
Security Development Engineer
1 day ago
Malaysia Payments Network Malaysia Full time 80,000 - 120,000 per yearSUMMARY OF RESPONSIBILITIESPart of the Security Engineering team, responsible for co-developing solutions and automation workflows to improve the overall security posture of PayNet.Serve as a change agent in automation initiatives, building pipelines to enhance operational efficiency.Ensure that sound security controls are in place, commensurate with...
-
Web Developer
1 day ago
Petaling Jaya, Malaysia ARRK Engineering Full time 60,000 - 120,000 per yearWeb Developer (m/f/x)about the roleWe're looking for a creative and detail-oriented Web Developer to join our growing team. You'll be part of our international team and are responsible for building and maintaining high-quality web applications that deliver exceptional user experiences. If you're passionate about clean code, responsive design, and modern...
-
Back End Web Developer
7 days ago
Malaysia IntersoftKK Full timeMalaysia **Experience**: Backend and Web Developer **Skills**:Backend and Web Developer **Min Year or Exp** **Responsibilities **Mandatory Skills** **Optional Skills** 8 Years and min 1-year experience with IBM Watson Solutions Develop secure software components that can be reused for building multigrained services. Responsible to develop and...
-
Security Analyst
1 day ago
Malaysia AceTeam Full time 30,000 - 60,000 per yearAceTeam is committed to take IT beyond with our customers and pledge to be the best, while strengthening the focus towards becoming a people centric company and not just limiting to technologies.We are looking for a Security Analyst who would like to grow with us, clearly defined by three things:CommITted · Connected · ConvergedAs a Security Analyst, you...
-
Data Center Security Specialist, Dc Security
1 week ago
Malaysia Amazon Data Services Malaysia Sdn. Bhd. Full timeCompletion of tertiary level education - Proficiency with MS Office - Read, write, and speak business level English language - Good report writing skills Amazon Web Services (AWS) is looking to hire a highly motivated, customer-obsessed individual to provide hands-on support to our Data Center Infrastructure Operations across SIN Cluster. (Data Center...
-
Malaysia - KL Eco City FWD Group Full time 120,000 - 180,000 per yearAbout FWD GroupFWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD's customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler insurance experience. Established in 2013, the...
-
Senior Application Support Engineer
1 day ago
Malaysia CompAsia Full time 60,000 - 120,000 per yearJob DescriptionWe are looking for a detail-oriented and proactive Senior Application Support Engineer to join our IT support team. This role primarily involves ensuring the seamless operation of our applications by addressing and resolving application issues, monitoring application uptime, and tracking Service Level Agreements (SLA). The ideal candidate will...