Application Security Engineer (Pentester/ Code Reviewer)

  • Jakarta
  • Crypto.com
The Cybersecurity and Data Privacy team reports directly under the office of the CISO headed by Chief Information Security Officer (CISO) Jason Lau () who has over 23+ years of experience in the cybersecurity space, awarded Global Top 100 CISO, and also serves on the World Economic Forum, International Association of Privacy Professionals and more. The team comprises of multiple functions from Blockchain Security, Operational Security, Security Governance and Compliance and more. We drive a culture of having a growth mindset and being humble to help everyone achieve their potential. Security and Data Privacy Compliance first strategy which has been at the core of our company. The security team helped to drive us to be the first Crypto company worldwide to achieve ISO27001, ISO27701, ISO22301 and PCI:DSS (Level 1) certifications. Extremely detailed third party attested by international audit firm SGS and achieved "Adaptive (Tier 4)” – the highest level possible for the US National Institute of Standards and Technology (NIST) Cybersecurity Framework and the latest NIST Privacy Framework as well as SOC2 and many other regional certifications like the Data Protection Trust Mark.ResponsibilitiesDiscover security vulnerabilities through design review, manual source code review, and follow up on the remediation processUse automated tools to find security vulnerabilities in source code and/or systemParticipant in relevant agile scrum meetings and provide professional recommendations on the design of security controls, libraries, and/or protocolsConduct secure coding training sessionsImplement various security control verification and risk detection by developing our own automation systemImplement security related libraries for internal useProvide support on application level security monitoring, intrusion detection, and incident responseRequirementsEither 1-4 years of software development experience focusing on Server Side development, OR 1-4 years of experience in web-api and mobile app penetration.A deep understanding of OWASP Top 10 and the ability to spot and address logic flawsGood understanding of the whole software development lifecycle, CI/CD tools, cloud, Kubernetes, and various and technology stacksSecurity-related certificates such as OSCP, CREST, CISSP, and CLSSP are definitely an advantageProficiency in both spoken and written English. Being able to speak Mandarin will be an advantage#Hybrid#LI-MK1