Bjak
Application Security Engineer AppSec
About this role
Secure BJAK's web applications, APIs, and backend services by embedding security into development workflows and coordinating cross-platform risks. You'll perform code and security reviews, manage vulnerabilities, integrate security tools into CI/CD pipelines, and ensure compliance with financial regulations while guiding developers on secure coding practices.
What you'll do
- Conduct security reviews, code reviews, and penetration testing for web applications, APIs, and backend services
- Identify and help remediate injection, broken access control, authentication, and configuration vulnerabilities
- Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines
- Perform threat modeling and design reviews for features, APIs, third-party integrations, and major system changes
- Coordinate with mobile teams on cross-platform security findings and ensure backend controls protect iOS and Android clients
- Own application security compliance for SC TRM and BNM RMiT regulations, including secure SDLC evidence and audit remediation
What they're looking for
- Application security and secure software development
- OWASP Top 10 and OWASP API Security Top 10
- Burp Suite and OWASP ZAP
- SAST, DAST, and dependency scanning tools
- TypeScript/Node.js and Python code review
- Threat modeling and secure design
- AWS and GCP cloud security
- Secure SDLC and vulnerability management
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Bjak
Bjak is a Southeast Asian fintech super app offering insurance, payments, savings, wallets, and investment products through a unified platform. The company is hiring full stack engineers, backend engineers, iOS developers, and Android engineers to build scalable features and reliable systems across mobile and web products.
- Website
- bjak.com
Likely interview questions
- Describe your experience implementing SC TRM and BNM RMiT compliance requirements in a financial services environment.
- Walk us through how you've integrated SAST and DAST tools into a CI/CD pipeline and what challenges you encountered.