Application Security Manager

2 days ago


Kuala Lumpur, Kuala Lumpur, Malaysia Great Eastern Full time 120,000 - 200,000 per year

About the Job

The Manager, Application Security is responsible for strengthening our enterprise application security posture. This is a hands-on individual contributor role responsible for performing penetration testing, secure code review, software composition analysis, container image assurance, and vulnerability assessments, as well as managing findings and supporting compliance with financial industry regulations. The role requires strong technical expertise, practical testing skills, and familiarity with regulatory requirements such as MAS TRM Guidelines and BNM RMiT Policy Document.

  • Conduct penetration testing for web, mobile, and API applications.
  • Perform secure code reviews, software composition analysis, and container image assurance to identify vulnerabilities early in the SDLC.
  • Perform vulnerability assessments for applications, middleware, and supporting systems.
  • Utilise industry-standard tools such as Burp Suite, OWASP ZAP, Fortify, Checkmarx, Black Duck, Nessus, Aqua and Qualys.
  • Triage, validate, and prioritise security findings from security assessments.
  • Work with development, DevOps, and infrastructure teams to ensure timely remediation.
  • Track and report remediation progress, ensuring closure within timelines required by regulatory instruments and Technology Security Standards.
  • Provide guidance to developers and project teams on secure coding practices.
  • Embed application security controls and tools (SAST, DAST, SCA, IAST) into CI/CD pipelines.
  • Maintain security documentation and provide evidence for audits and regulatory reviews.
  • Ensure compliance with internal policies, regulatory obligations, and industry best practices.
  • Support audits, risk assessments, and regulatory inspections involving application security.

We are looking for people with

  • Bachelor's degree in Information Security, Computer Science, or related field.
  • Professional certifications such as CREST, OSCP+, OSEP, or GPEN.
  • 7+ years of IT security experience, with at least 4 years of direct experience in project-based and annual penetration testing for web, mobile, and API applications.
  • Experienced in secure code reviews, software composition analysis, container image assurance, and vulnerability assessments.
  • Strong technical knowledge of web, mobile, and API security, including OWASP Top 10 and common attack vectors.
  • Hands-on expertise with security testing tools mentioned above.
  • Working knowledge of MAS TRM, MAS Cyber Hygiene, and BNM RMiT requirements.

How you succeed

  • Champion and embody our Core Values in everyday tasks and interactions.
  • Demonstrate high level of integrity and accountability.
  • Take initiative to drive improvements and embrace change.
  • Take accountability of business and regulatory compliance risks, implementing measures to mitigate them effectively.
  • Keep abreast with industry trends, regulatory compliance, and emerging threats and technologies to understand and highlight potential concerns/ risks to safeguard our company proactively.

Who we are

Founded in 1908, Great Eastern is a well-established market leader and trusted brand in Singapore and Malaysia. With over S$100 billion in assets and more than 16 million policyholders, including 12.5 million from government schemes, it provides insurance solutions to customers through three successful distribution channels – a tied agency force, bancassurance, and financial advisory firm Great Eastern Financial Advisers. The Group also operates in Indonesia and Brunei.

The Great Eastern Life Assurance Company Limited and Great Eastern General Insurance Limited have been assigned the financial strength and counterparty credit ratings of "AA-" by S&P Global Ratings since 2010, one of the highest among Asian life insurance companies. Great Eastern's asset management subsidiary, Lion Global Investors Limited, is one of the leading asset management companies in Southeast Asia.

Great Eastern is a subsidiary of OCBC, the longest established Singapore bank, formed in 1932. It is the second largest financial services group in Southeast Asia by assets and one of the world's most highly-rated banks, with an Aa1 rating from Moody's and AA- by both Fitch and S&P. Recognised for its financial strength and stability, OCBC is consistently ranked among the World's Top 50 Safest Banks by Global Finance and has been named Best Managed Bank in Singapore by The Asian Banker.

To all recruitment agencies:
Great Eastern does not accept unsolicited agency resumes. Please do not forward resumes to our email or our employees. We will not be responsible for any fees related to unsolicited resumes.



  • Kuala Lumpur, Kuala Lumpur, Malaysia Great Eastern Full time 900,000 - 1,200,000 per year

    About the JobThe Manager, Application Security is responsible for strengthening our enterprise application security posture. This is a hands-on individual contributor role responsible for performing penetration testing, secure code review, software composition analysis, container image assurance, and vulnerability assessments, as well as managing findings...


  • Kuala Lumpur, Kuala Lumpur, Malaysia TechLab Security Sdn Bhd Full time 120,000 - 180,000 per year

    Job SummaryWe are seeking an experienced Senior Cybersecurity Engineer to lead and manage daily Security Operations (SecOps) activities. The role involves hands-on management of endpoint security, firewalls, email security, and WAF, as well as leading cybersecurity enhancement projects across the organization.The ideal candidate is a technically strong and...

  • security concierge

    2 days ago


    Kuala Lumpur, Kuala Lumpur, Malaysia COUNTERFORCE SECURITY SERVICES SDN BHD Full time 40,000 - 80,000 per year

    SITE LOCATION: PAVILION, DAMANSARAWe are looking a professional Security Concierge to provide a welcoming presence while keeping our client's site safe. You will manage access control, visitor services, and security systems, as well as support incident response and coordination with our client's Global Command Center and Facility teams. If you excel in both...


  • Kuala Lumpur, Kuala Lumpur, Malaysia BTI Executive Search Pte Ltd Full time $60,000 - $80,000 per year

    Responsibilities:Design security architectures for new product featuresIntegrate automated security testing into development pipelinesConduct security reviews of application code and infrastructureDevelop secure coding guidelines and provide technical mentorshipRequirements:5+ years in application security with software development experienceStrong...


  • Kuala Lumpur, Kuala Lumpur, Malaysia BTI Executive Search Pte Ltd Full time $70,000 - $130,000 per year

    Responsibilities:Design and validate security controls for application interfacesConduct security assessments and vulnerability researchBuild automation frameworks for security testingCollaborate with engineering teams on secure architecture patternsImplement authentication and authorization best practicesRequirements:5+ years in application security or...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Gentari Full time 120,000 - 180,000 per year

    Changing how we live todayto help secure our future.Join us at Gentari to be part of this exciting, purposeful journey towards a cleaner energy future.Gentarians are passionate about sustainability - our purpose is to solve the world's most pressing sustainable energy needs. Here at Gentari, we move differently. Teams seek out opportunities to work with one...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Bank Negara Malaysia Full time 100,000 - 120,000 per year

    ResponsibilitiesLead, plan, oversee and operationalize secure configuration management processes in terms development, enhancement, enforcement, and validation of secure configuration baselines and reporting its compliance to the management through collaboration with various team from security architecture, administration, and operation, technical...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Bank Negara Malaysia Full time 120,000 - 240,000 per year

    ResponsibilitiesResponsible for effective operations, maintenance, support, monitoring, and updates of the key security technologies i.e. privileged user access management, malware protection, compliance automation etc.. This includes anticipating growth to ensure scalability, assessing the value of enhancement emanating from benchmarks, observations or...


  • Kuala Lumpur, Kuala Lumpur, Malaysia DUG Full time 90,000 - 120,000 per year

    DUG is looking for an Information Security Manager to join our global team. In this role, you'll take ownership of our cybersecurity posture, shaping policies, monitoring for threats, and implementing best practices to protect our data, systems, and users.We operate primarily in a Linux-based environment, so a strong foundation in Linux security is...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Bank Negara Malaysia Full time 80,000 - 120,000 per year

    ResponsibilitiesExecute and operationalize secure configuration management processes in terms development, enhancement, enforcement, and validation of secure configuration baselines and reporting its compliance to the management, through collaboration with various team from security architecture, administration, and operation, technical infrastructure,...