01
About This Role
We're hiring a Security Engineer to protect our products, infrastructure, and client data. You'll build security into the development lifecycle, harden our cloud platforms, and help every engineer make safer decisions by default.
02
What You'll Do
- Run threat modeling and security design reviews for new features and systems
- Build security checks into CI/CD: dependency scanning, SAST, secret detection, and container image scanning
- Harden cloud, Kubernetes, and network configurations using least-privilege principles
- Manage vulnerability intake, triage, and remediation tracking across teams
- Coordinate penetration tests and fix what they find
- Set up security monitoring, alerting, and incident response procedures
- Train engineers on secure coding practices and common vulnerabilities (OWASP Top 10)
- Support compliance work for PDPA and client security requirements
03
What We're Looking For
- 3+ years of experience in application security, cloud security, or a related field
- Solid understanding of web application vulnerabilities and how to prevent them
- Hands-on experience securing cloud environments and containerized workloads
- Scripting skills in Python, Go, or Bash for automation
- Familiarity with identity, authentication, and authorization standards (OAuth 2.0, OIDC)
- Clear, pragmatic communication, so you're seen as a partner to engineering rather than a blocker
04
Nice to Have
- Security certifications (OSCP, CISSP, CKS, or cloud security certifications)
- Experience with SIEM tools and incident response
- Knowledge of ISO 27001 or SOC 2 processes
- Bug bounty or CTF experience