Bjak logo

Application Security Engineer

Bjak

Remote
Full-time
Mid Level
3+ yrs
Salary not listedPosted 2d ago

Real job — pulled straight from Bjak’s careers page · Verified September 29, 2026 · No reposts.

Job description

Bjak is hiring a Application Security Engineer — a full-time, remote role. Apply directly on Bjak's careers page below.

Application Security Engineer AppSec

Department: Engineering

Location: Global

Employment Type: FullTime

About BJAK

The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.

Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.

Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.

We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.

If you're this person, we'd love to talk to you.

The Role

Secure BJAK's web applications, APIs, and backend services, coordinating with mobile stakeholders on cross-platform risks. Embed security into design, development, testing, and release workflows.

What You Will Build

  • Perform security reviews, code reviews, and testing for web applications, APIs, and backend services.

  • Identify, prioritize, and help remediate injection, broken access control, authentication, and configuration vulnerabilities.

  • Integrate SAST, DAST, software composition analysis, and secrets scanning into CI/CD pipelines.

  • Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.

  • Coordinate with mobile engineers on cross-platform findings and backend controls protecting native iOS and Android clients.

  • Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation.

  • Provide secure coding guidance, track remediation, retest fixes, and improve developer security awareness.

What We Look For

  • Degree in Computer Science, Cybersecurity, or related discipline, or equivalent experience.

  • 3+ years in application security, penetration testing, or secure software development.

  • Experience implementing and owning SC TRM and BNM RMiT application security and secure SDLC requirements.

  • Strong understanding of OWASP Top 10, OWASP API Security Top 10, web vulnerabilities, API security, and secure design.

  • Hands-on experience with Burp Suite, OWASP ZAP, SAST, DAST, and dependency scanning tools.

  • Experience reviewing TypeScript/Node.js and Python services; familiarity with Swift, Kotlin, AWS, and GCP.

  • Able to work closely with developers, explain findings, and support remediation.

Language

English is our main working language across global teams. Strong English communication is required.

Get Security Engineer jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Emerson logo

Cloud Platform Infrastructure Engineer

Austin, TX
✓ From careers page· 11h ago
Contentful logo

Software Engineer, Applied AI Solutions

$117k–$161kDenver, CO
✓ From careers page· 11h ago
Waymo logo

Software Engineering Intern, Labeling

$125k–$125kMountain View, CA
✓ From careers page· 11h ago
Atlassian logo

Principal Software Engineer

Remote · US-eligible
✓ From careers page· 11h ago

Frequently asked questions

Is Application Security Engineer at Bjak a remote job?

Yes, Application Security Engineer at Bjak is a remote position. This role is open to remote candidates.

What skills are required for Application Security Engineer at Bjak?

The required skills for Application Security Engineer at Bjak include: TypeScript, Node.js, Python, Swift, Kotlin, AWS, GCP.

What is the seniority level for Application Security Engineer at Bjak?

Application Security Engineer at Bjak is a Mid Level level position.

How do I apply for Application Security Engineer at Bjak?

You can view the full description and apply for Application Security Engineer at Bjak on EchoJobs: https://echojobs.io/job/bjak-application-security-engineer-appsec-s33h3.