Talent.com
Web Application Security Engineer
Web Application Security EngineerCXM Direct LLC • MY
Web Application Security Engineer

Web Application Security Engineer

CXM Direct LLC • MY
5 hari lalu
Jenis pekerjaan
  • Quick Apply
Penerangan pekerjaan

Position Overview

We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.

This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.

Core Responsibilities

Offensive Security (Penetration Testing)

The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.

You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL / TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.

Defensive Security (Blue Team Operations)

On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.

You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.

Purple Team Collaboration

As a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.

You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.

Security Integration and Automation

You will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.

Requirements

Required Qualifications

  • Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
  • ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
  • Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
  • Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
  • Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
  • Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
  • Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF / IPS
  • Hands-on experience configuring and tuning web application firewalls and deep packet inspections

Preferred Qualifications

Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.

Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.

Benefits

Competitive Compensation

Medical

Gym Allowance

Company Events

Personal Growth

Buat amaran kerja untuk carian ini

Application Engineer • MY

Pekerjaan berkaitan
Security Analyst

Security Analyst

Rimini Street, Inc • Malaysia, Malaysia
Security Analyst page is loaded## Security Analystlocations : Remote Malaysiatime type : Full timeposted on : Posted Todayjob requisition id : R- • •About Rimini Street, Inc.Nasdaq : RMNI), a Rus...Tunjukkan lagi
Kemas kini terakhir: 7 hari yang lalu • Dinaikkan pangkat
Security Analyst

Security Analyst

Rimini Street • Malaysia, Malaysia
Security Analyst – Rimini Street.We are looking for a Security Analyst to join our team in Malaysia (Remote).This role is based in Malaysia (Remote). Nasdaq : RMNI), a Russell 2000® Company, is a glo...Tunjukkan lagi
Kemas kini terakhir: 7 hari yang lalu • Dinaikkan pangkat
Web3 Senior Security Engineer

Web3 Senior Security Engineer

Hyphen Connect • Malaysia, Malaysia
We are working with a decentralised exchange which looks to innovate on providing the best of CEXs and DEXs, focusing on building a safe, simple and scalable platform for trading.They differentiate...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Senior Analyst, Information Security Engineering

Senior Analyst, Information Security Engineering

FWD Group Management Holdings Limited • Malaysia, Malaysia
Senior Analyst, Information Security Engineering page is loaded## Senior Analyst, Information Security Engineeringlocations : Malaysia - KL Eco Citytime type : Full timeposted on : Posted Todayt...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Senior Process Safety Engineer

Senior Process Safety Engineer

FLEXSYS • PahangMalaysia, Pahang, Malaysia
The Process Safety Engineer will provide Process Safety services and support Southern Asia.Most of the support will be for the Flexsys Kuantan Malaysia site where the engineer’s office will be loca...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Software Engineer (Security Management Applications)

Software Engineer (Security Management Applications)

Shirlyn Technology • Malaysia, Malaysia
Global Security and Risk Management (GSRM).Our team of security professionals, innovators, and thought leaders leverage decades of expertise to drive large-scale transformations and ensure the secu...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Application Engineer

Application Engineer

EXFO • Malaysia, Malaysia
The Application Engineer is a seasoned technology sales / pre-sales professional with a techno-commercial mindset.This candidate should possess a strong knowledge of the end-to-end value chain from b...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
SOC Manager

SOC Manager

Confidential • Malaysia
We are seeking an experienced and highly capable Security Operations Center (SOC) Manager to lead our combined Information Technology (IT) and Operational Technology (OT) security monitoring and in...Tunjukkan lagi
Kemas kini terakhir: 13 hari yang lalu • Dinaikkan pangkat
Technical Lead (Web Based)

Technical Lead (Web Based)

Mpowerts • Malaysia, Malaysia
We are looking for a highly skilled technical personnel to lead a team of developers in implementing a new web based (and mobile) application from ground up. The technical lead is required to be tec...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
IT Security Lead

IT Security Lead

Monroe Consulting Group • Malaysia, Malaysia
Monroe Consulting Group is partnering with a highly established Government-Linked Company (GLC) with a robust footprint in the consumer, logistics, and technology sectors.Our client is recognized f...Tunjukkan lagi
Kemas kini terakhir: 9 hari yang lalu • Dinaikkan pangkat
Application Developer

Application Developer

Businessperformance • Malaysia, Malaysia
Primarily responsible in development of Business Intelligence Application, either in the area of database, web and business intelligence. Data Warehousing, Data Management, Business Intelligence or ...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Web Application Security Engineer

Web Application Security Engineer

CXM • Malaysia, Malaysia
We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity.This role represents a strategic blend of offensive penetration testing expertise a...Tunjukkan lagi
Kemas kini terakhir: 1 hari yang lalu • Dinaikkan pangkat
Security Architect

Security Architect

GraceMark Solutions • Malaysia, Malaysia
Be among the first 25 applicants.Malaysia (Flexible Work Options Available).Our client is a global leader in digital security and performance solutions, supporting billions of users worldwide.With ...Tunjukkan lagi
Kemas kini terakhir: 1 hari yang lalu • Dinaikkan pangkat
Security Engineer

Security Engineer

CDN5 • Malaysia, Malaysia
Implement and maintain website security measures to protect against cyber threats.Conduct penetration testing and vulnerability assessments to identify and mitigate security risks.Monitor and respo...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Cybersecurity Engineer

Cybersecurity Engineer

Mindvalley • Malaysia, Malaysia
Mindvalley is seeking a Cybersecurity Engineer to strengthen the overall security posture of our platforms, endpoints, cloud services, and applications. This role goes beyond traditional AppSec — yo...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
Software Application Engineer

Software Application Engineer

Applied Materials, Inc. • Malaysia, Malaysia
Key Responsibilities • • • Creates, plans, and performs a variety of software analysis, design, development, code, code review, documentation, integration, test and product assurance tasks.Contributes...Tunjukkan lagi
Kemas kini terakhir: 7 hari yang lalu • Dinaikkan pangkat
Utilities Engineer

Utilities Engineer

Lonza • Jerantut, Pahang, Malaysia
Today, Lonza is a global leader in life sciences operating across five continents.While we work in science, there’s no magic formula to how we do it. Our greatest scientific solution is dedicated in...Tunjukkan lagi
Kemas kini terakhir: 17 hari yang lalu • Dinaikkan pangkat
Senior Engineer, Product Security Engineering

Senior Engineer, Product Security Engineering

Dell Technologies • Malaysia, Malaysia
As a Security Review Consultant, you will be responsible for performing security reviews on firewall change requests, proxy change requests, third-party access requests. You will also review the cap...Tunjukkan lagi
Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat