Deskripsi Pekerjaan
Join Quess as an Application Security Engineer and become a guardian of digital innovation! We're seeking a dedicated professional to spearhead our web application security initiatives in Makati City. In this critical role, you'll leverage your expertise in SAST/DAST tools and threat modeling to identify vulnerabilities before they impact business operations. You'll conduct rigorous penetration testing, collaborate with development teams to implement secure coding practices, and drive continuous improvement of our security posture. This is your opportunity to work in a dynamic environment where your skills directly protect sensitive data and ensure regulatory compliance. Quess offers competitive compensation, professional growth opportunities, and a culture that values security excellence.
As part of our cybersecurity team, you'll stay ahead of emerging threats through ongoing research and tool optimization. You'll translate complex security findings into actionable recommendations for engineering teams, bridging technical knowledge with business impact. If you're passionate about building secure software and thrive in collaborative settings, we invite you to apply your 4-7 years of application security experience to make a tangible difference at Quess.
Tanggung Jawab
- Conduct comprehensive web application penetration testing using manual techniques and automated tools
- Implement and optimize SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) solutions
- Lead threat modeling sessions for new and existing applications
- Document security findings and provide actionable remediation guidance to development teams
- Collaborate with DevOps to integrate security practices into CI/CD pipelines
- Develop security standards, policies, and best practices for application development
- Stay current with emerging security threats, vulnerabilities, and mitigation techniques
Kualifikasi
- Bachelor's degree in Computer Science, Information Security, or related field
- 4-7 years of hands-on experience in application security engineering
- Proficiency with SAST/DAST tools (SonarQube, Checkmarx, Burp Suite, OWASP ZAP)
- Strong understanding of threat modeling methodologies (STRIDE, PASTA)
- Experience with OWASP Top 10 vulnerabilities and secure coding standards
- Ability to translate technical security concepts for non-technical stakeholders
- Relevant certifications (CISSP, OSCP, CEH) preferred
- Excellent problem-solving and communication skills