Application Security Engineer/Lead
LeadOn-site (Jakarta)Salary undisclosed
Required Skills
PythonNode.jsJavaAWSGCPKubernetesDockerCI/CD
Job Description
As the Application Security Engineer\Lead, you will serve as the primary authority for ensuring the security, resilience, and integrity of our digital financial services, mobile platforms, and crypto systems. Reporting directly to the Head of Security, you will champion secure software development lifecycle (SSDLC) practices, scale our threat modeling capabilities, and manage security testing programs. You will be responsible for aligning our application defense with the OWASP framework and managing external penetration testing in accordance with CREST standards.
Key Responsibilities
- AppSec Program Leadership: Define and implement the enterprise Application Security strategy, ensuring secure coding practices are embedded across all engineering teams.
- Standardize application security testing, code reviews, and vulnerability management around OWASP Top 10, OWASP ASVS (Application Security Verification Standard), and SAMM (Software Assurance Maturity Model).
- Vulnerability & DevSecOps Management: Oversee the implementation and optimization of SAST, DAST, SCA, and IAST tools within CI/CD pipelines, triaging findings and guiding engineers on remediation. Automate SAST/DAST/SCA testing directly in developer workflows.
- Threat Modeling: Lead architecture review and conduct threat modeling exercises during early product design phases using frameworks like STRIDE, and champion secure coding standards across the en
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.