Mintel

Security Engineer (App Sec)

Mintel Kuala Lumpur, Kuala Lumpur, Malaysia

Market Research · 1,001-5,000 employees

Sep 11
security Senior (5-10 yrs) Full-time Malaysia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The role involves managing the end-to-end security triage workflow and responding to security incidents across endpoint, identity, and email platforms. You will also contribute to security improvement projects and maintain security configuration hygiene within the Microsoft ecosystem.

What they look for

Security operations Microsoft Defender Microsoft Intune Identity and access management Conditional access Incident response Security triage Endpoint security KQL PowerShell Python Cloud security Risk management Security configuration Automation

Requirements

Candidates should have at least 5 years of practical experience in security operations and hands-on knowledge of the Microsoft 365 security stack. Strong communication skills and the ability to work independently within defined operational guardrails are essential.

Benefits

Hybrid working Learning and development opportunities Knowledge sharing culture

Full description

We’re looking for an Application Security Engineer to join our Information Security team, working closely with Engineering, Infrastructure and Architecture to help us build and maintain secure applications at scale.

This is a hands-on role focused on improving the security of our software development lifecycle. You’ll work collaboratively with engineering teams across multiple products, helping to identify and reduce risk while enabling teams to deliver at pace. As a member of a globally distributed team, you’ll be comfortable working independently, taking ownership of your work, and proactively engaging with colleagues across regions.

What you will do

  • Partner with engineering teams to review application designs and implementations, identifying security risks and working collaboratively to address them
  • Contribute to and evolve our Secure SDLC processes, ensuring security is embedded into how we build and deliver software
  • Perform application security reviews across a range of technologies and services
  • Support vulnerability management activities, including triage, prioritisation and remediation guidance
  • Manage and triage CVEs impacting our environments, working with teams to drive timely resolution
  • Contribute to the security of our CI/CD pipelines, helping to ensure controls are effective and practical
  • Build, maintain and improve secure base Docker images for use across engineering teams
  • Manage and improve dependency update processes and tools, helping teams stay up to date securely
  • Work with engineers to investigate and remediate security issues, providing clear and actionable guidance
  • Advocate for security improvements, helping teams understand risk and make informed decisions
  • Contribute to and improve our security documentation, ensuring guidance is clear, accurate and accessible for engineering teams
  • Contribute to continuous improvement of our tools, processes and ways of working

What are we looking for?

  • 2+ years experience working in application security or a software engineering role with a strong security focus
  • Strong understanding of common application security risks and how they apply in real-world systems
  • Experience reviewing application code, architecture or designs from a security perspective
  • Hands-on experience working with Linux-based systems and Docker
  • Experience supporting or integrating security into CI/CD pipelines
  • Familiarity with vulnerability management processes, including CVE triage and remediation workflows
  • Ability to work independently and manage your own priorities in a distributed team environment
  • Strong communication skills, with the ability to work effectively with engineers and non-security stakeholders
  • A collaborative mindset, with a focus on enabling teams rather than acting as a gatekeeper

Nice to have:

  • Experience with Python and related frameworks (e.g. Django, FastAPI)
  • Experience with modern frontend technologies (e.g. JavaScript, TypeScript, React)
  • Familiarity with dependency management tooling (e.g. Renovate)
  • Experience securing containerised or cloud-based applications

How We Work

  • We work as partners to engineering teams, embedding security into everyday development rather than adding it at the end
  • We focus on pragmatic, risk-based decisions that balance security with delivery needs

Similar roles