About BJAK
At BJAK, we believe everyone deserves smarter ways to manage their money. Our journey began in 2019 with a simple yet powerful vision: to make insurance accessible to millions across Southeast Asia. We built the region's first mobile-first insurance platform, rapidly becoming the market leader.
Today, our mission has expanded. We're building a comprehensive financial ecosystem that empowers people to get more from their money every day — whether it's through spending, saving, investing, exchanging, or even traveling. We're breaking boundaries and redefining what's possible in fintech.
We are a global team of over 20 nationalities, working remotely and from our offices, united by a shared passion for innovation. We're not just building products; we're crafting next-generation financial applications that serve everyone, not just a select few. If you are driven by passion, thrive on building groundbreaking solutions, and are ready to challenge the status quo, you belong with us.
Application Security Engineer
Are you a passionate Application Security Engineer ready to safeguard a rapidly expanding fintech ecosystem? BJAK is seeking a proactive and skilled professional to champion application security across our innovative web applications, APIs, and backend services. In this critical role, you will be instrumental in embedding security practices throughout our entire software development lifecycle, from initial design to deployment, and collaborating closely with our mobile teams to address cross-platform risks.
What You'll Do
Lead comprehensive security reviews, code reviews, and robust testing across our web applications, APIs, and critical backend services.
Proactively identify, prioritize, and drive the remediation of critical vulnerabilities including injection flaws, broken access controls, authentication issues, and misconfigurations.
Design and implement advanced security tooling by integrating SAST, DAST, software composition analysis, and secrets scanning directly into our CI/CD pipelines.
Conduct thorough threat modeling and design reviews for new features, APIs, third-party integrations, and significant architectural changes.
Collaborate seamlessly with mobile engineering teams to address cross-platform security findings and fortify backend controls protecting our native iOS and Android clients.
Take ownership of application security compliance for SC TRM and BNM RMiT, ensuring robust secure SDLC evidence, meticulous vulnerability management, comprehensive testing, and effective audit remediation.
Champion secure coding practices by providing expert guidance, tracking remediation efforts, retesting fixes, and significantly elevating developer security awareness across the organization.
What You'll Bring
A degree in Computer Science, Cybersecurity, or a related technical discipline, or equivalent practical experience demonstrating strong foundational knowledge.
Minimum of 3+ years of dedicated experience in application security, penetration testing, or secure software development roles.
Proven track record of implementing and owning application security and secure SDLC requirements for regulatory frameworks such as SC TRM and BNM RMiT.
Deep expertise in the OWASP Top 10, OWASP API Security Top 10, common web vulnerabilities, API security best practices, and secure design principles.
Extensive hands-on experience with industry-standard security tools including Burp Suite, OWASP ZAP, SAST, DAST, and software composition analysis/dependency scanning tools.
Proficiency in reviewing and securing services built with TypeScript/Node.js and Python; familiarity with Swift, Kotlin, AWS, and GCP environments is highly valued.
Exceptional communication skills in English, both written and verbal, with the ability to articulate complex security findings to developers and actively support remediation efforts.