Responsibilities
- Manage software supply-chain security for Node.js environments, including dependency scanning, open-source license compliance, software composition analysis, and container image scanning using tools like Socket.dev, Dependabot, and AWS ECR, enforced in CI/CD with reachability-based prioritization.
- Oversee end-to-end application security testing, including threat modeling for new features and architecture changes, tuning AI-assisted static application security testing pipelines, and coordinating penetration tests from scoping through remediation and retest sign-off.
- Secure the GitHub organization and AWS infrastructure by implementing secret scanning, hardened CI/CD workflows, IAM least-privilege policies, malware and threat detection, and vulnerability management with AWS GuardDuty, Inspector, and Detective.
- Triage security alerts and enhance endpoint detection and response capabilities across all devices.
- Manage edge protection by tuning AWS WAF rules for rate limiting, bot control, and managed rule sets, and configuring Network Firewall policies to defend against DDoS, injection attacks, and malicious traffic.
- Serve as the primary technical responder for application security incidents, and continuously integrate advances in application security and AI-assisted security engineering into existing tooling.
Requirements
- At least 3 years of experience in an application security role with strong foundational knowledge, and the ability to read Node.js or JavaScript well enough to trace vulnerabilities to their root cause and validate fixes.
- Experience securing software supply chains using dependency, license, and container scanning tools such as Socket.dev, Dependabot, Trivy, or Semgrep, enforced as CI/CD policies with reachability-based prioritization.
- Proven ability to conduct threat modeling on new features and coordinate penetration tests from scoping through remediation.
- Experience hardening CI/CD pipelines and GitHub organizations with branch protection, secret scanning, and Actions security measures like OIDC, pinned actions, and scoped permissions.
- Hands-on experience with AWS security services including GuardDuty, Inspector, Detective, and CloudTrail for threat detection, as well as WAF and Network Firewall for edge protection.
- Ability to build security tools, scanners, or CI plugins using Python, TypeScript, or Bash.
Nice to Have
- Experience using AI for security automation is a plus.
Benefits
- Join a supportive culture with smart, collaborative teammates who genuinely care about each other's growth and success.
- Guaranteed professional growth exceeding that of other opportunities.
- Virtual events such as talent shows, Among Us nights, and online game sessions to maintain engagement regardless of location.
- Highly competitive compensation package.
- Mental health allowance to support health and wellness needs.
- Flexible working environment and hours that adapt to your lifestyle, regardless of your location.
Compensation
Highly competitive compensation package.
Work Arrangement
Remote (Worldwide) — Kuala Lumpur, Malaysia
Other
Flexible working environment and working hours that fit your lifestyle, wherever you're based.