Talent.com
Tawaran kerja ini tidak tersedia di negara anda.
Product Security Vulnerability Management Engineer

Product Security Vulnerability Management Engineer

The Access GroupKuala Lumpur, Kuala Lumpur, Malaysia
7 jam yang lalu
Penerangan pekerjaan

We’re looking for people to join the Access family, who share our passion for believing in better, and who will help us continue to grow.Love Work. Love Life. Be You. - is central to our success and how we give our customers the freedom to do more of what's important to them.We offer a blended approach to office working, encouraging you to collaborate and connect in one of our thriving offices. We deliver on what we say, taking the development of our people seriously. We’ll work with you to progress your success plan and provide opportunities to accelerate your career.On top of a competitive salary, our wellbeing days taking you to 25 days leave a year and a health contribution, you’ll also be able to choose from a range of benefits to suit you. We’re an organisation that likes to give back, so you’ll also have three charity days allocated to support a cause that matters to you.

  • Position Overview
  • We are seeking a motivated Product Security Vulnerability Management Engineer with 2-3 years of experience to support, manage, and contribute to our comprehensive product security program. This role will be instrumental in operating and enhancing our Application Security Testing Platform, supporting the Secure Software Development Lifecycle (SSDLC) Platform, and enabling DevSecOps integration across our development ecosystem.The position focuses on maintaining automated security testing across the entire product stack while learning to implement secure development practices throughout the organization and collaborating closely with development teams to embed security throughout the software development lifecycle.The ideal candidate will have hands-on experience with automated security testing tools, DevSecOps practices, a solid foundation in product security principles, and be ready to take on increased responsibilities in vulnerability management, developer engagement, and security program optimization while continuing to develop their expertise in secure SDLC implementation and NIST framework alignment.
  • Key Responsibilities
  • Application Security Testing & Analysis
  • Support the development and maintenance of testing orchestration processes to ensure seamless integration across multiple security tools
  • Assist in maintaining and optimizing the unified security testing platform integration with development workflows
  • DevSecOps Integration & Enablement
  • Partner with development teams to integrate security testing into CI / CD pipelines and help reduce friction in security adoption
  • Support DevSecOps integration and orchestration activities, including container security scanning and policy as code implementation
  • Assist in maintaining pipeline security coverage and security gate automation across development workflows
  • Contribute to container vulnerability metrics collection and policy compliance monitoring
  • Support Infrastructure as Code (IaC) security scanning and compliance checks
  • Create security-focused monitoring and logging solutions for production environments with senior team guidance
  • Secure SDLC Support & Implementation
  • Support threat modeling activities, security requirements generation, and secure architecture pattern implementation aligned with NIST Secure Software Development Framework
  • Contribute to the operation and maintenance of the Secure Software Development Lifecycle (SSDLC) Platform
  • Assist in ensuring security activities are integrated throughout the software development lifecycle
  • Support security gate implementation and help track security gate pass rates
  • Participate in architecture reviews and provide input on secure design patterns.
  • Contribute to security requirements coverage and documentation
  • Vulnerability Management & Reporting
  • Track and report on key security metrics including vulnerability detection rates, false positive rates, and developer adoption metrics
  • Maintain vulnerability findings database and ensure accurate tracking of remediation efforts
  • Support mean time to remediation (MTTR) tracking and vulnerability aging metrics
  • Generate unified security reports from multiple testing tools for stakeholders and management
  • Monitor application security coverage and identify gaps in testing coverage across the application portfolio
  • Work collaboratively with development teams to support remediation of high-priority vulnerabilities
  • Support compliance efforts by ensuring alignment with NIST Cybersecurity Framework 2.0 controls
  • Developer Collaboration & Security Enablement
  • Provide security guidance and training to developers on secure coding practices and vulnerability remediation
  • Support developer onboarding security tools and processes, contributing to improved adoption rates
  • Create and maintain developer-friendly documentation including integration playbooks and security guides
  • Contribute to developer security enablement programs and security champion initiatives
  • Support secure coding standards implementation and help track secure coding violations trends
  • Assist in security knowledge assessment activities and training satisfaction measurement
  • Process Improvement & Continuous Learning
  • Identify opportunities to enhance the application security testing platform and reduce false positives
  • Evaluate and assist in piloting new security tools and technologies to improve detection capabilities
  • Contribute to security policy development and help establish security standards for application development
  • Support incident response activities related to application security vulnerabilities
  • Stay current with emerging threats and application security best practices through continuous learning
  • Contribute to continuous improvement in security automation and tool efficiency
  • Required Qualifications
  • Education & Experience :
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
  • 2-3 years of hands-on experience in product security, application security, DevSecOps, or related security roles
  • Demonstrated experience with application security testing tools and methodologies
  • Experience supporting product security programs or secure development initiatives
  • Technical Skills :
  • Proficiency with SAST, DAST, and SCA tools
  • Understanding of secure coding practices and common vulnerability types (OWASP Top 10, CWE Top 25)
  • Experience with CI / CD integration and DevSecOps principles
  • Familiarity with programming languages commonly used in enterprise environments (Python, Java, JavaScript, C#, etc.)
  • Knowledge of web application security concepts and testing methodologies
  • Basic understanding of threat modeling methodologies (STRIDE, PASTA)
  • Familiarity with container security and cloud-native application security concepts
  • Understanding of NIST frameworks including Cybersecurity Framework 2.0 and Secure Software Development Framework
  • Experience with Infrastructure as Code (IaC) security scanning tools
  • Knowledge of vulnerability management principles and practices
  • Soft Skills :
  • Strong analytical and problem-solving abilities with attention to detail
  • Excellent communication skills for collaborating with technical and non-technical stakeholders
  • Ability to work in fast-paced, agile environments while maintaining security standards
  • Project management capabilities for coordinating security initiatives across multiple teams
  • Eagerness to learn and grow in product security expertise
  • Passion for continuous learning and staying current with security trends
  • Key Performance Indicators :
  • Support improvement in mean time to detection (MTTD) for application vulnerabilities and maintain mean time to remediation (MTTR) below organizational targets
  • Help maintain false positive rate below 5% across all testing types through tool tuning and process optimization
  • Support achieving 95%+ developer adoption rate of security tools and processes
  • Contribute to pipeline security coverage metrics

#J-18808-Ljbffr

Buat amaran kerja untuk carian ini

Product Engineer • Kuala Lumpur, Kuala Lumpur, Malaysia

Pekerjaan yang berkaitan
  • Dinaikkan pangkat
Technical Product Manager – Operational Excellence (Bangkok-based, relocation provided)

Technical Product Manager – Operational Excellence (Bangkok-based, relocation provided)

AgodaKlang Municipal Council, Klang Municipal Council, Malaysia
Technical Product Manager – Operational Excellence (Bangkok-based, relocation provided) at Agoda.This role focuses on enabling Agoda Tech to become more effective in non-coding activities such as i...Tunjukkan lagiKemas kini terakhir: 2 hari yang lalu
  • Dinaikkan pangkat
Engineer, Workplace IT Security

Engineer, Workplace IT Security

SingtelKuala Lumpur, Kuala Lumpur, Malaysia
Singtel Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia.Workplace IT Security Engineer.Workplace IT security solutions. The key focus is to develop security related workflows, process and ...Tunjukkan lagiKemas kini terakhir: 16 hari yang lalu
  • Dinaikkan pangkat
Site Reliability Engineer

Site Reliability Engineer

Avensys ConsultingKuala Lumpur, Kuala Lumpur, Malaysia
Our client’s project is a well-established brand in the IT industry who is now looking for a passionate and driven Site Reliability Engineer. This is an exciting opportunity to expand your skill set...Tunjukkan lagiKemas kini terakhir: 2 hari yang lalu
  • Dinaikkan pangkat
Senior Specialist, Security Engineer

Senior Specialist, Security Engineer

TNG DigitalKuala Lumpur, Kuala Lumpur, Malaysia
Senior Talent Acquisition Specialist @ TNG Digital - We're Hiring!.We fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion...Tunjukkan lagiKemas kini terakhir: 24 hari yang lalu
  • Dinaikkan pangkat
Site Reliability Engineer

Site Reliability Engineer

GlintsKuala Lumpur, Kuala Lumpur, Malaysia
Recruitment Consultant at Glints Singapore.Monitor and maintain system performance to ensure the stability and reliability of applications and infrastructure. Design and implement resilient system a...Tunjukkan lagiKemas kini terakhir: 24 hari yang lalu
  • Dinaikkan pangkat
Cybersecurity Support Engineer - Malaysia

Cybersecurity Support Engineer - Malaysia

FortinetKuala Lumpur, Kuala Lumpur, Malaysia
Location : Malaysia (Kuala Lumpur).Join Fortinet, a cybersecurity pioneer with over two decades of excellence, as we continue to shape the future of cybersecurity and redefine the intersection of ne...Tunjukkan lagiKemas kini terakhir: 30+ hari yang lalu
  • Dinaikkan pangkat
  • Baharu!
Site Reliability Engineer (L2 Support)

Site Reliability Engineer (L2 Support)

CareCone GroupKuala Lumpur, Kuala Lumpur, Malaysia
Site Reliability Engineer (L2 Support) role at CareCone Group in Kuala Lumpur, Malaysia.Responsible for end-to-end application support, production incident handling, platform monitoring, and coordi...Tunjukkan lagiKemas kini terakhir: 7 jam yang lalu
  • Dinaikkan pangkat
Software Engineer, Security Engineering

Software Engineer, Security Engineering

GrabPetaling Jaya, Selangor, Malaysia
Grab is Southeast Asia's leading superapp.From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything.In...Tunjukkan lagiKemas kini terakhir: 30+ hari yang lalu
  • Dinaikkan pangkat
Reliability Engineer (R&D)

Reliability Engineer (R&D)

Daikin Malaysia Sdn BhdSungai Buloh, Selangor, Malaysia
Oversee daily test operations, including equipment setup, maintenance, and facility upgrades.Collaborate with designers to conduct tests and ensure compliance with specifications and standards.Mana...Tunjukkan lagiKemas kini terakhir: 16 hari yang lalu
  • Dinaikkan pangkat
Senior IGA Consultant

Senior IGA Consultant

Kloudynet TechnologiesKlang Municipal Council, Klang Municipal Council, Malaysia
Kloudynet is a leading cybersecurity company with a strong partnership with Microsoft.As a Microsoft Solutions Partner in Modern Work and Security, we hold advanced specializations across key areas...Tunjukkan lagiKemas kini terakhir: 23 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Division CFO, Trilogy (Remote) - $400,000 / year USD

Division CFO, Trilogy (Remote) - $400,000 / year USD

TrilogyKlang City, Selangor, Malaysia
Division CFO, Trilogy (Remote) - $400,000 / year USD.Trilogy Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia.Get AI-powered advice on this job and more exclusive features.This range is prov...Tunjukkan lagiKemas kini terakhir: 7 jam yang lalu
  • Dinaikkan pangkat
  • Baharu!
Senior Product Manager - AI AdOps Copilot (REMOTE)

Senior Product Manager - AI AdOps Copilot (REMOTE)

MonetizeMoreKuala Selangor, Kuala Selangor, Malaysia
MonetizeMore is a global leader in ad tech, providing solutions that help publishers maximize their ad revenue while maintaining transparency, user trust, and brand safety.We are committed to shapi...Tunjukkan lagiKemas kini terakhir: 7 jam yang lalu
  • Dinaikkan pangkat
Technical Marketing Engineer

Technical Marketing Engineer

Infotree Global SolutionsKuala Selangor, Kuala Selangor, Malaysia
Job title : Developer : Technical Marketing - III.Max salary budget : RM8,000 / month.Experience : 5+ years in technical roles, 2+ years with developers, coding skills, and hands-on AI / edge / IoT experienc...Tunjukkan lagiKemas kini terakhir: 17 hari yang lalu
  • Dinaikkan pangkat
Lead, Security Operations Center

Lead, Security Operations Center

GREAT EASTERNKuala Lumpur, Kuala Lumpur, Malaysia
This role will report to the Head of IT Security, Malaysia.The SOC Lead will primarily be responsible for leading Great Eastern Next Generation Security Operations Centre (NGSOC) Team and act as a ...Tunjukkan lagiKemas kini terakhir: 24 hari yang lalu
  • Dinaikkan pangkat
Manager, Ground Operations Training

Manager, Ground Operations Training

Malaysia AirlinesSepang, Selangor, Malaysia
Manager, Ground Operations Training.The Manager, Ground Operations Training is expected to ensure organizational compliance with relevant regulations through effective training and risk management....Tunjukkan lagiKemas kini terakhir: 2 hari yang lalu
  • Dinaikkan pangkat
Compliance Engineer (Quality, Environment, Safety & Health)

Compliance Engineer (Quality, Environment, Safety & Health)

Neways Electronics International NVKlang City, Selangor, Malaysia
You champion quality and safety by ensuring our products meet the highest standards, while building a safe and sustainable workplace for everyone. You drive audits, compliance, and continuous improv...Tunjukkan lagiKemas kini terakhir: 30+ hari yang lalu
  • Dinaikkan pangkat
  • Baharu!
Security Operation Analyst

Security Operation Analyst

NTT DataSepang, Selangor, Malaysia
As part of the global NTT DATA Group, one of the top 5 IT service providers worldwide, we specialize in value-added SAP solutions. At NTT DATA Business Solutions, our focus is SAP Consulting, SAP De...Tunjukkan lagiKemas kini terakhir: 7 jam yang lalu
  • Dinaikkan pangkat
Security Engineer (Flexible Solution)

Security Engineer (Flexible Solution)

UNAVAILABLEKuala Lumpur, Kuala Lumpur, Malaysia
Orange Business is a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their busine...Tunjukkan lagiKemas kini terakhir: 23 jam yang lalu