- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 4 hours ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
About the Role
At Bibit.id and Stockbit, safeguarding our applications and user data is a top priority. As an Application Security Engineer, you will be instrumental in maintaining the security and integrity of our products which cover mobile applications and backend systems. You'll collaborate closely with our product and engineering teams to embed security throughout the development lifecycle.
Key Responsibilities
- Work alongside product tribes including engineers, QA, and product managers to integrate security considerations at every phase of the Software Development Life Cycle (SDLC).
- Perform secure code reviews primarily on Golang and JavaScript applications to detect and mitigate vulnerabilities such as SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and Insecure Direct Object References (IDOR).
- Lead security testing efforts including penetration testing, vulnerability scans, and both static and dynamic analyses across web, mobile, and backend services to proactively identify weaknesses.
- Engage in threat modeling with product teams to evaluate potential security risks and design mitigation strategies.
- Manage bug bounty programs by triaging, validating, and coordinating fixes for bug reports from external security researchers.
- Advise on security architecture to incorporate secure design patterns in system design and deployment processes.
- Participate in incident response activities by assisting in investigations and remediation of application security incidents, aiming to reduce impacts and enhance detection/prevention.
- Increase security awareness by promoting best practices in secure coding through knowledge sharing, internal trainings, and developing security playbooks.
- Keep abreast of the latest security threats, vulnerabilities, frameworks, and attack vectors, continuously enhancing our defense mechanisms.
Candidate Profile
- Deep knowledge of web and mobile security principles and fundamentals.
- Proven hands-on experience in penetration testing and conducting secure code reviews.
- Proficiency with Golang and JavaScript aligning with Stockbit’s technology stack.
- Experienced with security analysis tools like Burp Suite, OWASP ZAP, Snyk, or similar.
- Effective communication skills for explaining complex security issues to technical development teams in an accessible manner.
- Additional advantage for candidates familiar with CI/CD pipeline security, cloud security frameworks (AWS/GCP), or DevSecOps methodologies.
Skills
Work styles they’re looking for
Communication
Collaboration