Lead Application Security Engineer
Core
Lead the design and implementation of application-level security controls, standards, and automated testing within a DevSecOps environment for Agoda's global travel platform.
Role type
Lead Application Security Engineer
Builds
Internal security tools, automated security testing pipelines, and secure microservice/web/mobile platforms
Domain
Travel technology, Application Security, DevSecOps
Required skills
Threat modeling, Secure coding, Identity management and authentication, Cryptography, System administration, Network security, OWASP MASVS/ASVS assessment, Web application vulnerability exploitation, Automated dynamic scanning and fuzzing
Preferred skills
Software Development Life Cycle (SDLC) integration, Cloud environment security (Openshift, Rancher, K8s, AWS, GCP, Azure), Code review and remediation
Technologies
Rust, Python, Go, Nodejs, Openshift, Rancher, K8s, AWS, GCP, Azure (via careerplan.io/jobs/8241915-lead-application-security-engineer-at-agoda)
Responsibilities
Develop and design application-level security controls and standards; Perform application security design reviews; Track and prioritize security issues; Build internal security tools; Enable automated security testing at scale; Execute security tests across on-premise and public cloud data centers
Seniority
Senior, hands-on IC
