Skip to main content
Techy Recruiter

Application Security Lead

RemoteIndonesia only
Published
Role
Security
Experience
Lead
Employment
Full-time
Salary not disclosed
Check eligibility

Open to ID only. Set where you work from to check your eligibility.

No BS summary

Application security lead for Ajaib, focused on mobile apps, APIs, backend services, and SDLC security. Needs strong appsec/product security/security engineering or pentesting experience, leadership or mentoring experience, and Indonesia eligibility. Strong written and spoken English required.

Core skills

SASTDASTApplication Security

Required skills

OWASP Top 10OWASP API Security Top 10Software Composition AnalysisSecrets DetectionAndroidiOSCI/CD

Optional skills

Android application security testingiOS application security testingOWASP Mobile Application Security Verification StandardOWASP Application Security Verification StandardKubernetesCloud-native application securityOSCPOSWE

Required languages

English Strong written and spoken English required

What you'll do

  • Define and lead Ajaib’s application-security programme across mobile, web, APIs, and backend services
  • Build application-security standards, processes, and controls across the software-development lifecycle
  • Partner with engineering and product teams to embed security into product design and development
  • Lead threat-modelling sessions for new products, features, architectures, and integrations
  • Conduct security architecture reviews, code reviews, and application-security assessments
  • Own and improve SAST, DAST, software-composition analysis, secrets detection, and dependency-scanning capabilities
  • Integrate application-security testing into CI/CD pipelines
  • Identify, prioritise, and track vulnerabilities through remediation and verification
  • Work with engineering teams to provide practical remediation guidance and secure coding recommendations
  • Coordinate penetration testing, security assessments, and responsible-disclosure activities
  • Strengthen security across mobile applications, APIs, authentication flows, customer accounts, and sensitive transactions
  • Help investigate application-related security incidents and support root-cause analysis
  • Define application-security metrics, reporting, and risk indicators
  • Deliver secure-development training and build security champions within engineering teams
  • Mentor application-security engineers and help grow the team’s technical capabilities
  • Stay current with emerging vulnerabilities, attack techniques, and security risks affecting financial and investment platforms

What they require

  • Strong experience in application security, product security, security engineering, or penetration testing
  • Experience leading application-security initiatives or mentoring security engineers
  • Strong knowledge of mobile, web, API, and backend application security
  • Experience securing applications built on modern cloud and distributed architectures
  • Deep understanding of common application-security risks, including the OWASP Top 10 and OWASP API Security Top 10
  • Hands-on experience with threat modelling, secure code review, vulnerability assessment, and penetration testing
  • Experience using and implementing SAST, DAST, software-composition analysis, and secrets-detection tools
  • Familiarity with mobile application security across Android and iOS
  • Ability to understand code in one or more modern programming languages
  • Experience integrating security checks into CI/CD and developer workflows
  • Strong understanding of authentication, authorisation, session management, encryption, and secure API design
  • Ability to communicate security risks clearly and provide practical, developer-friendly solutions
  • Strong written and spoken English
  • Interviews may include technical, leadership, and application-security scenario discussions
  • You may be asked to review an architecture, assess a vulnerability, explain a threat model, or discuss how you have helped engineering teams resolve security risks
  • Do not include confidential information, customer data, source code, security findings, or proprietary details from current or previous employers during the interview process

Benefits

  • High-impact ownership: shape application security across a growing financial platform
  • Hands-on influence: work directly with engineers and improve how products are designed, built, tested, and released
  • Meaningful challenges: secure mobile applications, APIs, customer accounts, investment data, and financial transactions
  • Security at scale: help build processes and automation that grow with the business
  • Leadership opportunity: mentor engineers, build a security-champion culture, and help define Ajaib’s application-security standards
  • Accommodations available at any stage of the recruitment process if needed

Techy Recruiter is a boutique hiring partner for startups and scaleups across Europe and the Gulf. They run searches end to end and manage the hiring communication for this role.

Recruiting

Details

Apply routeDom
Salary not disclosed