Talent.com
Application Security Manager
Application Security ManagerGreat Eastern • Kuala Lumpur, Kuala Lumpur, Malaysia
Application Security Manager

Application Security Manager

Great Eastern • Kuala Lumpur, Kuala Lumpur, Malaysia
1 hari lalu
Penerangan pekerjaan

The Manager, Application Security is responsible for strengthening our enterprise application security posture. This is a hands‑on individual contributor role responsible for performing penetration testing, secure code review, software composition analysis, container image assurance, and vulnerability assessments, as well as managing findings and supporting compliance with financial industry regulations. The role requires strong technical expertise, practical testing skills, and familiarity with regulatory requirements such as MAS TRM Guidelines and BNM RMiT Policy Document.

Responsibilities

  • Conduct penetration testing for web, mobile, and API applications.
  • Perform secure code reviews, software composition analysis, and container image assurance to identify vulnerabilities early in the SDLC.
  • Perform vulnerability assessments for applications, middleware, and supporting systems.
  • Utilise industry-standard tools such as Burp Suite, OWASP ZAP, Fortify, Checkmarx, Black Duck, Nessus, Aqua and Qualys.
  • Triage, validate, and prioritise security findings from security assessments.
  • Work with development, DevOps, and infrastructure teams to ensure timely remediation.
  • Track and report remediation progress, ensuring closure within timelines required by regulatory instruments and Technology Security Standards.
  • Provide guidance to developers and project teams on secure coding practices.
  • Embed application security controls and tools (SAST, DAST, SCA, IAST) into CI / CD pipelines.
  • Maintain security documentation and provide evidence for audits and regulatory reviews.
  • Ensure compliance with internal policies, regulatory obligations, and industry best practices.
  • Support audits, risk assessments, and regulatory inspections involving application security.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related field.
  • Professional certifications such as CREST, OSCP+, OSEP, or GPEN.
  • 7+ years of IT security experience, with at least 4 years of direct experience in project‑based and annual penetration testing for web, mobile, and API applications.
  • Experienced in secure code reviews, software composition analysis, container image assurance, and vulnerability assessments.
  • Strong technical knowledge of web, mobile, and API security, including OWASP Top 10 and common attack vectors.
  • Hands‑on expertise with security testing tools mentioned above.
  • Working knowledge of MAS TRM, MAS Cyber Hygiene, and BNM RMiT requirements.
  • How you succeed

  • Champion and embody our Core Values in everyday tasks and interactions.
  • Demonstrate high level of integrity and accountability.
  • Take initiative to drive improvements and embrace change.
  • Take accountability of business and regulatory compliance risks, implementing measures to mitigate them effectively.
  • Keep abreast with industry trends, regulatory compliance, and emerging threats and technologies to understand and highlight potential concerns / risks to safeguard our company proactively.
  • Who we are

    Founded in 1908, Great Eastern is a well‑established market leader and trusted brand in Singapore and Malaysia. With over S$100 billion in assets and more than 16 million policyholders, including 12.5 million from government schemes, it provides insurance solutions to customers through three successful distribution channels – a tied agency force, bancassurance, and financial advisory firm Great Eastern Financial Advisers. The Group also operates in Indonesia and Brunei.

    The Great Eastern Life Assurance Company Limited and Great Eastern General Insurance Limited have been assigned the financial strength and counterparty credit ratings of “AA‑” by S&P Global Ratings since 2010, one of the highest among Asian life insurance companies. Great Eastern’s asset management subsidiary, Lion Global Investors Limited, is one of the leading asset management companies in Southeast Asia.

    Great Eastern is a subsidiary of OCBC, the longest established Singapore bank, formed in 1932. It is the second largest financial services group in Southeast Asia by assets and one of the world’s most highly‑rated banks, with an Aa1 rating from Moody’s and AA‑ by both Fitch and S&P. Recognised for its financial strength and stability, OCBC is consistently ranked among the World’s Top 50 Safest Banks by Global Finance and has been named Best Managed Bank in Singapore by The Asian Banker.

    Recruitment Agency Notice

    To all recruitment agencies : Great Eastern does not accept unsolicited agency resumes. Please do not forward resumes to our email or our employees. We will not be responsible for any fees related to unsolicited resumes.

    Seniority level : Mid‑Senior level

    Employment type : Full‑time

    Job function : Information Technology

    Industries : Banking and Financial Services

    #J-18808-Ljbffr

    Buat amaran kerja untuk carian ini

    Security Manager • Kuala Lumpur, Kuala Lumpur, Malaysia

    Pekerjaan berkaitan
    Technical Project Manager - Security Services

    Technical Project Manager - Security Services

    Arbitrum • Kajang Municipal Council, Selangor, Malaysia
    Founded in 2015 with the mission to protect the open economy, OpenZeppelin is the world leader in securing blockchain applications and smart contracts. Our Open-Source Contract Libraries are a publi...Tunjukkan lagi
    Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
    M / AD - Enterprise Security Architect - TRC (Petaling Jaya)

    M / AD - Enterprise Security Architect - TRC (Petaling Jaya)

    KPMG Malaysia • Petaling Jaya, Selangor, Malaysia
    M / AD - Enterprise Security Architect - TRC (Petaling Jaya).Join KPMG Malaysia as an Enterprise Security Architect in Petaling Jaya. You will design, implement and maintain enterprise security archit...Tunjukkan lagi
    Kemas kini terakhir: 30+ hari yang lalu • Dinaikkan pangkat
    Lead Engineer

    Lead Engineer

    Soft Space Sdn Bhd • Seremban, Negeri Sembilan, Malaysia
    We are seeking a technically strong leader based in Malaysia to head our North America region projects.The Lead Engineer will take ownership of regional delivery, technical solutioning, and team le...Tunjukkan lagi
    Kemas kini terakhir: 27 hari yang lalu • Dinaikkan pangkat
    Premier Centre Manager

    Premier Centre Manager

    OCBC company • Klang City, Selangor, Malaysia
    You may choose to display a cookie banner on the external site.You must specify the message in the cookie banner and may add a link to a relevant policy. If you are unfamiliar with these requirement...Tunjukkan lagi
    Kemas kini terakhir: 7 hari yang lalu • Dinaikkan pangkat
    Information Security Manager

    Information Security Manager

    senangPay—A DOKU Company • Kuala Lumpur, Kuala Lumpur, Malaysia
    To manage, develop, and maintain the organization's IT security framework, ensuring the integrity, confidentiality, and availability of information assets while meeting regulatory compliance requir...Tunjukkan lagi
    Kemas kini terakhir: 2 hari yang lalu • Dinaikkan pangkat
    Security Engineer

    Security Engineer

    PayNet (Payments Network Malaysia) • Kuala Lumpur, Kuala Lumpur, Malaysia
    Lead security solution initiatives, from architecture, design, deployment to operationalizing and other technical security assessment and implementation (at various layers).Ensure sound security pr...Tunjukkan lagi
    Kemas kini terakhir: 4 hari yang lalu • Dinaikkan pangkat
    Regional Engagement Lead — Global Cybersecurity (Remote)

    Regional Engagement Lead — Global Cybersecurity (Remote)

    Positka • Nilai, Negeri Sembilan, Malaysia
    A boutique consulting firm is seeking a Regional Engagement Manager in Kuala Lumpur.This role requires 7+ years of experience in Project Management and fluency in Mandarin for client communication ...Tunjukkan lagi
    Kemas kini terakhir: 4 hari yang lalu • Dinaikkan pangkat
    Regional Head, Malaysia & KLIA Hub

    Regional Head, Malaysia & KLIA Hub

    Malaysia Aviation Group • Sepang, Selangor, Malaysia
    Add expected salary to your profile for insights.Oversee ground handler performance at all domestic stations and KLIA, ensuring full compliance with Service Level Agreements (SLAs).Implement and ma...Tunjukkan lagi
    Kemas kini terakhir: 4 hari yang lalu • Dinaikkan pangkat
    Intune & Endpoint Management Architect - Autopilot Security

    Intune & Endpoint Management Architect - Autopilot Security

    MRP Group • Kuala Lumpur, Kuala Lumpur, Malaysia
    A leading IT consulting firm in Kuala Lumpur is seeking an experienced Intune Specialist to design and implement a secure and scalable endpoint management environment across multiple platforms.The ...Tunjukkan lagi
    Kemas kini terakhir: 1 hari yang lalu • Dinaikkan pangkat
    Pre-Opening Safety & Security Director

    Pre-Opening Safety & Security Director

    Hilton • Kuala Lumpur, Kuala Lumpur, Malaysia
    A leading global hospitality company is seeking a Director of Safety & Security in Kuala Lumpur to oversee safety operations and ensure compliance with safety regulations.This role involves managin...Tunjukkan lagi
    Kemas kini terakhir: 1 hari yang lalu • Dinaikkan pangkat
    Senior SAP Basis + AWS Security Architect

    Senior SAP Basis + AWS Security Architect

    PEOPLE PROFILERS • Kuala Lumpur, Kuala Lumpur, Malaysia
    A leading recruitment company is seeking a Senior SAP BASIS and AWS specialist in Kuala Lumpur.The role involves managing SAP landscapes, optimizing AWS cloud infrastructures, and ensuring security...Tunjukkan lagi
    Kemas kini terakhir: 5 hari yang lalu • Dinaikkan pangkat
    Senior Security Engineer

    Senior Security Engineer

    CARSOME • Kuala Lumpur, Kuala Lumpur, Malaysia
    Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia.Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia.Be among the first 25 applicants. Get AI-powered advice on this job and more exclu...Tunjukkan lagi
    Kemas kini terakhir: 18 hari yang lalu • Dinaikkan pangkat
    Information Security Engineer

    Information Security Engineer

    R Systems • Kuala Lumpur, Kuala Lumpur, Malaysia
    R Systems WP, Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia.Information Security Engineering Lead.Acts as a team leader providing guidance to the Security Engineering team, sets goals a...Tunjukkan lagi
    Kemas kini terakhir: 7 hari yang lalu • Dinaikkan pangkat
    Security Engineer

    Security Engineer

    Ensign InfoSecurity • Kuala Lumpur, Kuala Lumpur, Malaysia
    Manage the ticketing system and ensure all tickets are up to date with the latest information / updates.Handles customers’ calls / escalation and performs 1st & 2nd level troubleshooting and resolution...Tunjukkan lagi
    Kemas kini terakhir: 7 hari yang lalu • Dinaikkan pangkat
    Azure Architect (AI Adoption / Security)

    Azure Architect (AI Adoption / Security)

    Softenger (Malaysia) Sdn Bhd • Selayang Municipal Council, Selayang Municipal Council, Malaysia
    Job Title : AI Architect (Adoption / Security).We are hiring for key roles to support a major enterprise‑scale AI transformation program. Candidates will work closely with business and IT teams to driv...Tunjukkan lagi
    Kemas kini terakhir: 5 hari yang lalu • Dinaikkan pangkat
    Centre Manager

    Centre Manager

    Knight Frank Property Management • Sepang, Selangor, Malaysia
    As a Centre Manager, your responsibilities include but are not limited to : .Plan, manage, and supervise day-to-day operations of the industrial / site, including building maintenance, housekeeping, se...Tunjukkan lagi
    Kemas kini terakhir: 5 hari yang lalu • Dinaikkan pangkat
    Senior E&C Risk Governance Lead - Remote

    Senior E&C Risk Governance Lead - Remote

    Oman Shell • Port Klang, Port Klang, Malaysia
    A leading energy company located in Cyberjaya is seeking an E&C Risk Governance Lead to manage E&C risk management processes, improving frameworks and reporting for stakeholder engagement.The ideal...Tunjukkan lagi
    Kemas kini terakhir: 6 hari yang lalu • Dinaikkan pangkat
    Remote Technical Project Manager - Blockchain Security

    Remote Technical Project Manager - Blockchain Security

    Placeholder • Nilai, Negeri Sembilan, Malaysia
    A leading technology firm is seeking an experienced Technical Project Manager in Shah Alam, Malaysia.You will manage client relationships, ensure project delivery, and work with cutting-edge blockc...Tunjukkan lagi
    Kemas kini terakhir: 5 hari yang lalu • Dinaikkan pangkat