Skip to content

Open nowPosted 2 hours agoWe saw it 26 min after it went up

Application Security Engineer AppSec

bjakcareer3,082 open roles

Where
Global
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowApplication Security Engineer AppSecbjakcareer · Global
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on bjakcareer's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market. bjakcareer postings stay open a median of 1 days.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 2 hours ago

bjakcareer median: 1 days open

The posting

ABOUT BJAK

The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.

Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.

Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.

We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.

If you're this person, we'd love to talk to you.

THE ROLE

Secure BJAK's web applications, APIs, and backend services, coordinating with mobile stakeholders on cross-platform risks. Embed security into design, development, testing, and release workflows.

WHAT YOU WILL BUILD

- Perform security reviews, code reviews, and testing for web applications, APIs, and backend services.

- Identify, prioritize, and help remediate injection, broken access control, authentication, and configuration vulnerabilities.

- Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines.

- Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.

- Coordinate with mobile engineers on cross-platform findings and backend controls protecting native iOS and Android clients.

- Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation.

- Provide secure coding guidance, track remediation, retest fixes, and improve developer security awareness.

WHAT WE LOOK FOR

- Degree in Computer Science, Cybersecurity, or related discipline, or equivalent experience.

- 3+ years in application security, penetration testing, or secure software development.

- Experience implementing and owning SC TRM and BNM RMiT application security and secure SDLC requirements.

- Strong understanding of OWASP Top 10, OWASP API Security Top 10, web vulnerabilities, API security, and secure design.

- Hands-on experience with Burp Suite, OWASP ZAP, SAST, DAST, and dependency scanning tools.

- Experience reviewing TypeScript/Node.js and Python services; familiarity with Swift, Kotlin, AWS, and GCP.

- Able to work closely with developers, explain findings, and support remediation.

LANGUAGE

English is our main working language across global teams. Strong English communication is required.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against bjakcareer's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on bjakcareer's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    bjakcareer's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.