Lead Application Security Engineer

Kuala Lumpur Until 8/22/2026 5+ years exp First posted June 23, 2026 Last posted June 23, 2026
Job description

Key Responsibilities: 
● Threat Modeling: Lead design reviews for new banking features (Payments, Transfers, 
KYC). Identify logic flaws before code is written. 
● Pipeline Automation: Architect and maintain the SAST/DAST/SCA tooling in the CI/CD 
pipeline (e.g., SonarQube, Snyk, GitLab CI) to block vulnerabilities automatically. 
● Code Review: Perform manual code audits on high-risk components (Authentication, 
Ledger logic) in Java, Kotlin, or Swift. 
● Cloud & AI Patterns: Deliver API, container, cloud, and AI security design patterns. 
Ensure that developers have "paved roads" (secure templates) for deploying 
microservices and AI models. 
● Culture: Act as a mentor to the development team, running secure coding workshops and 
championing a "Security Champion" program. 

Technical Requirements: 
● 5+ years in Application Security with a background in Software Development. 
● Proficiency in at least one core language: Java (Spring Boot), Node.js, or Go. 
● Deep understanding of OWASP Top 10 and SANS Top 25. 
● Experience with CI/CD integration (Jenkins, GitHub Actions). 
● Bonus: Experience in Fintech or Banking.

About this role

Summary

Lead application security, perform code audits, design secure microservices, mentor team.

Job title

Lead Application Security Engineer

Experience level

5+ years

Minimum experience

5+ years exp

Industry

financial technology

Location requirements

Kuala Lumpur, remote not specified

Salary

Not specified

Management role

No

Skills & keywords

Required skills

application securitythreat modelingci/cdjavakotlinswiftowaspsansjenkinsgithub actions

Preferred skills

fintechbanking

Specializations

threat modelingci/cdcode reviewcloud securityai security
Locations

Structured locations inferred from the posting.

Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia

Work arrangement unknown City