{"id":1239429,"url":"https://alion.io/job/dksh-senior-specialist-application-security-engineer","title":"Senior Specialist Application Security Engineer","company":{"id":20289,"name":"DKSH","domain":"dksh.com","url":"https://alion.io/company/dksh","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Kuala Lumpur, Malaysia"],"countries":["MY"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":19500,"max_usd":44000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1261},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Burp Suite","optional":false},{"name":"Invicti","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"SQL","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-09-25T02:00:00Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-28T23:07:45Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"About the Role\nAs an Application Security Engineer, you play a critical role in safeguarding DKSH's digital landscape by driving application security assurance across the full software development lifecycle. Your expertise in penetration testing, vulnerability management, and Application Security (AppSec) governance ensures that internal, third-party, and internet-facing applications are protected, resilient, and aligned with DKSH's security standards.\nWhat You Will Deliver\nCoordinate and manage application penetration testing activities including scoping, scheduling, evidence collection, vendor coordination, report review, retest tracking, and closure validation to ensure testing outcomes are thorough and actionable.\nConduct or support technical security assessments for web, Application Programming Interface (API), mobile, cloud-hosted, and enterprise applications using manual testing and automated tools, delivering findings that drive meaningful risk reduction.\nOwn application vulnerability tracking from discovery through to remediation, ensuring findings are categorized by severity, affected application, owner, risk, due date, and closure status to maintain full visibility and accountability.\nProvide clear and practical remediation guidance for vulnerabilities including SQL injection, Cross-Site Scripting (XSS), authentication flaws, insecure direct object references, weak encryption, insecure configuration, vulnerable components, and missing logging.\nSupport secure Software Development Lifecycle (SDLC) activities including security requirements, threat modeling inputs, secure coding guidance, release checks, and security sign-off criteria to embed security throughout application delivery.\nPrepare executive and technical reports summarizing critical and high findings, remediation status, risk themes, aging, recurring weaknesses, and business impact to support informed decision-making.\nDrive remediation coordination across application owners, developers, Quality Assurance (QA) teams, vendors, infrastructure, and security operations to ensure vulnerabilities are resolved effectively and on time.\nInfluence application teams to validate closure based on evidence, ensuring remediation outcomes are substantive rather than administrative.\nCollaborate with Security Operations Center (SOC) and infrastructure teams to strengthen prevention and detection capabilities against application attacks, webshell risk, credential abuse, and exploitation attempts.\nChampion secure-by-design and risk-based application delivery practices across the organization.\nWhat You Bring\nBachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or equivalent practical experience. Preferred certifications include GWAPT, GWEB, Offensive Security Certified Professional (OSCP), Practical Network Penetration Tester (PNPT), Certified Secure Software Lifecycle Professional (CSSLP), Certified Ethical Hacker (CEH), Security+, or equivalent.\n5 or more years of cybersecurity experience with a focus on application security, penetration testing, vulnerability management, secure SDLC, or security assurance.\nProven capability in application penetration testing coordination, report review, vulnerability validation, and remediation tracking.\nStrong knowledge of OWASP Top 10, API security, authentication and session management, secure coding, web server hardening, Web Application Firewall (WAF) concepts, and risk-based remediation.\nExperience with tools such as Burp Suite, Invicti, OWASP ZAP, Qualys, Microsoft Defender, and Static Application Security Testing/Dynamic Application Security Testing/Software Composition Analysis (SAST/DAST/SCA) tooling, ticketing systems, and reporting dashboards is preferred.\nAbility to translate technical vulnerabilities into practical, actionable remediation guidance for developers, vendors, system teams, and management.\nSkilled in maintaining penetration test trackers, vulnerability aging reports, remediation dashboards, and risk acceptance documentation.\nWhy Join DKSH\nAt DKSH, we help companies grow in Asia and enable people to perform at their best. You will be part of an organization that values accountability, collaboration, and long-term partnerships. We offer a dynamic environment where your contributions are visible and where you can build a meaningful career in Application Security.","description_format":"text","description_chars":4397,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Wholesale","Pharmaceutical Distribution","Medical Equipment Distribution"],"lifecycle":[{"event":"open","at":"2026-09-25T16:35:49Z"}],"liveness":{"score":81,"band":"hot","label":"Hiring now","p_open":0.9,"p_active":0.903,"p_room":1,"age_days":3,"expected_fill_days":31,"reasons":["conf:58","velocity","win:early","comp:brand"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/dksh-senior-specialist-application-security-engineer","json_url":"https://alion.io/job/dksh-senior-specialist-application-security-engineer.json","meta":{"generated_at":"2026-09-29T02:02:12Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1664,"day_limit":5000,"remaining_today":3336,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}