FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Manager
NexTbil Tech. Define, implement, and lead the application security program across products, platforms, and the software development lifecycle .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security program leadership, secure coding practices, and vulnerability management. Proficient in integrating security tools into CI/CD pipelines and conducting security training and consultations.
Highest-signal resume keywords
Application Security Program LeadershipSAST, DAST, SCA, IAST ToolingOWASP Top 10 KnowledgeSecure Coding Guidelines DevelopmentVulnerability Management Lifecycle
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecuritySecure Software EngineeringThreat ModelingSecure Code ReviewsExploitation TechniquesDefensive Coding PatternsProgramming in C#, C++, Java, Go, Python, JavaScript, TypeScriptCI/CD IntegrationVulnerability Remediation TrackingSecurity Architecture Reviews
Soft Skills
LeadershipCollaborationCommunication
Tools & Technologies
CheckmarxVeracodeSnykSemgrepBurp SuiteOWASP ZAP
Certifications & Qualifications
OSCPOSWEGWAPTGMOBCSSLPCISSPBurp Suite Certified Practitioner
Industry Keywords
Cloud-Native Application SecurityKubernetes SecurityServerless SecurityOWASP SAMMBSIMMNIST SSDFSecure SDLC GovernanceCompliance-Focused Environments
Tech Stack
Tools & technologiesCloudCyber SecurityJavaJavaScriptKubernetesPythonSDLCTypeScriptC++Go
About the role
Key responsibilities & impact- Define, implement, and lead the application security program across products, platforms, and the software development lifecycle
- Set application security strategy, standards, secure coding guidelines, and policies for web, mobile, API, and application security
- Drive threat modeling, architecture security reviews, and secure design consultations
- Own SAST, DAST, SCA, IAST, secrets scanning, and fuzz testing toolchains and integrate them into CI/CD pipelines
- Manage the application vulnerability lifecycle, including triage, prioritization, remediation tracking, SLA enforcement, and reporting
- Lead manual secure code reviews and coordinate penetration testing engagements
- Operate the bug bounty program and validate findings
- Build and deliver secure coding training, developer enablement programs, and security champion networks
- Partner with DevOps and platform teams to harden build pipelines, container images, cloud-native workloads, and backend services
- Monitor application security threats, trends, and relevant Southeast Asia regulatory expectations
Requirements
What you’ll need- Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or a related discipline
- 5+ years of experience in application security, product security, or secure software engineering
- At least 2 years in a lead or senior individual contributor capacity
- Strong understanding of OWASP Top 10, OWASP API Top 10, and OWASP Mobile Top 10
- Knowledge of exploitation techniques and defensive coding patterns
- Hands-on experience with SAST, DAST, SCA, and IAST tooling and CI/CD integration
- Experience with tools such as Checkmarx, Veracode, Snyk, Semgrep, Burp Suite, or OWASP ZAP
- Proficiency in at least one of C#, C++, Java, Go, Python, JavaScript, or TypeScript
- Ability to read and review code across multiple technology stacks
- Availability to work on-site in Kuala Lumpur
- Availability for occasional out-of-hours engagement with global engineering teams across time zones
- Preferred: OSCP, OSWE, GWAPT, GMOB, CSSLP, CISSP, Burp Suite Certified Practitioner, or equivalent credentials
- Preferred: Experience securing interactive digital products, cloud-native application security, Kubernetes, serverless and container security, threat modeling, security architecture reviews, OWASP SAMM, BSIMM, NIST SSDF, compliance-focused environments, secure SDLC governance, and audit support
Benefits
Comp & perks- Attractive salary package and performance-based bonuses
- Flexible working options and hybrid working models
- Comprehensive health insurance
- Wellness initiatives and physical and mental well-being resources
- Continuous learning through training programs
- Mentorship
- Clearly defined career development paths
- Diverse, inclusive, and team-oriented workplace
- Regular team-building activities and social events