CareerPlanSign in

Application Security Engineer/Lead

Jakarta, Jakarta, Indonesia💼 Full-time🗓 2026-05-07 → 2026-09-25

Core

Primary authority for ensuring security, resilience, and integrity of digital financial services, mobile platforms, and crypto systems.

Role type

Senior IC Application Security Lead

Builds

Secure software development lifecycle (SSDLC) practices, threat modeling capabilities, and security testing programs

Domain

Fintech, digital banking, e-commerce

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Secure coding practices, threat modeling (STRIDE), vulnerability management, SAST/DAST/SCA/IAST tool implementation, CI/CD pipeline security, mobile app vulnerability analysis (reverse engineering, certificate pinning), OWASP standards application, CREST penetration testing management, secure code training design

Preferred skills

CREST certifications, OSCP, OSWE, CSSLP

Technologies

Java, Python, Go, Node.js, AWS, GCP, Kubernetes, Docker, GitHub, GitLab, Bitbucket, Checkmarx, Semgrep, Snyk, Burp Suite Professional, SonarQube

Responsibilities

Define and implement enterprise Application Security strategy, standardize application security testing and vulnerability management, oversee SAST/DAST/SCA/IAST tools in CI/CD pipelines, lead architecture review and conduct threat modeling exercises, manage external penetration tests per CREST standards, design and deliver secure code training programs

Seniority

Senior, hands-on IC

Sourced via workable · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.