
Application Security Lead
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in Indonesia.
• Define and spearhead Ajaib’s application-security program encompassing mobile, web, APIs, and backend services.
• Establish application-security standards, processes, and controls throughout the software development lifecycle.
• Collaborate with engineering and product teams to integrate security into product design and development.
• Facilitate threat modeling sessions for new products, features, architectures, and integrations.
• Perform security architecture reviews, code reviews, and application-security assessments.
• Own and enhance capabilities in SAST, DAST, software composition analysis, secrets detection, and dependency scanning.
• Embed application-security testing within CI/CD pipelines.
• Identify, prioritize, and monitor vulnerabilities through remediation and verification processes.
• Collaborate with engineering teams to provide actionable remediation guidance and secure coding practices.
• Coordinate penetration testing, security assessments, and responsible disclosure activities.
• Fortify security across mobile applications, APIs, authentication flows, customer accounts, and sensitive transactions.
• Assist in investigating application-related security incidents and support root cause analysis.
• Define application-security metrics, reporting, and risk indicators.
• Provide secure development training and cultivate security champions within engineering teams.
• Mentor application-security engineers and enhance the team’s technical expertise.
• Remain up-to-date with emerging vulnerabilities, attack techniques, and security risks impacting financial and investment platforms.
• Extensive experience in application security, product security, security engineering, or penetration testing.
• Proven track record in leading application-security initiatives or mentoring security engineers.
• Comprehensive knowledge of mobile, web, API, and backend application security.
• Experience in securing applications developed on modern cloud and distributed architectures.
• In-depth understanding of common application-security risks, including the OWASP Top 10 and OWASP API Security Top 10.
• Practical experience with threat modeling, secure code reviews, vulnerability assessments, and penetration testing.
• Familiarity with utilizing and implementing SAST, DAST, software composition analysis, and secrets detection tools.
• Knowledge of mobile application security for both Android and iOS platforms.
• Ability to comprehend code in one or more contemporary programming languages.
• Experience in integrating security checks into CI/CD and developer workflows.
• Strong grasp of authentication, authorization, session management, encryption, and secure API design.
• Proficient in communicating security risks clearly while offering practical, developer-friendly solutions.
• Excellent written and spoken English skills.
• High-impact ownership: influence application security across a rapidly growing financial platform.
• Hands-on influence: work closely with engineers to enhance how products are designed, built, tested, and released.
• Meaningful challenges: secure mobile applications, APIs, customer accounts, investment data, and financial transactions.
• Security at scale: assist in developing processes and automation that evolve with the business.
• Leadership opportunity: mentor engineers, foster a security-champion culture, and help define Ajaib’s application-security standards.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.