Senior / Staff Application Security Engineer (Bangkok based, relocation provided)
Agoda is seeking a Senior / Staff Application Security Engineer to join our Security Department. This role is Bangkok-based with relocation provided. You will collaborate with engineering partners to build secure products and scale security processes through automation.
Responsibilities
- Conduct application security reviews and perform penetration testing, ensuring alignment with compliance standards.
- Engage in projects, research, and security tool development to enhance security measures and meet compliance requirements.
- Scale security processes using automation.
- Provide training, outreach, and develop documentation to guide security practices among internal teams.
- Offer technical guidance, advocate for automation, evaluate designs, and lead security teams to empower engineering partners with cutting-edge tools, techniques, and methodologies to naturally build secure products.
What you\'ll Need to Succeed / Role Requirements
Strong foundations in secure design reviews, threat modeling experience, code reviews, and pen-testing.Minimum of 3 years of technical experience with threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security.Minimum 2 years of experience with Software Development Life Cycle in languages such as Go, Python, Node.js, Rust, etc.Experience with public / private cloud environments (OpenShift, Rancher, Kubernetes, AWS, GCP, Azure, etc.).In-depth knowledge of security principles, compliance regulations, and change management.Experience in running assessments using OWASP MASVS and ASVS.Working knowledge of exploiting and fixing application vulnerabilities.Proven expertise in architectural threat modeling and secure design reviews.In-depth knowledge of common web application vulnerabilities (OWASP Top 10, SANS Top 25).Familiarity with automated dynamic scanners, fuzzers, and proxy tools.Analytical problem-solving mindset and offensive security mindset.Strong verbal and written communication skills to convey technical concepts to varied audiences.Exposure to advanced AI and Large Language Model (LLM) security.Relocation package provided for moving to Bangkok, Thailand. Hybrid working model with WFH setup allowance and remote-working benefits are available.Benefits
Hybrid working modelWFH setup allowance30 days of remote working from anywhere globally each yearEmployee discount for accommodation globallyGlobal team of 90+ nationalities40+ offices and 25+ countriesAnnual CSR / Volunteer Time OffBenevity subscription for employee donationsVolunteering opportunities globallyFree Headspace subscriptionFree Odilo & Udemy subscriptionsEmployee Assistance Program (EAP)Enhanced Parental LeaveLife, TPD & Accident InsuranceEqual Opportunity
At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We provide equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics. We will keep your application on file and you can request removal at any time. For details please read our privacy policy.
Disclaimer
We do not accept unsolicited third-party or agency submissions. If we receive such CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.
#J-18808-Ljbffr