- Location
- Kuala Lumpur, MY
- Type
- Full-time
- Department
- Engineering
- Source
- Breezy HR
Description
Location: Kuala Lumpur, Malaysia
Role: Application Security Engineer
Department: Backend
About Respond.io
Founded in Hong Kong in early 2017, respond.io is an AI-powered business messaging platform that helps companies manage customer conversations across chat, calls and email — all in one place.
Trusted by businesses in over 127 countries and recognized by G2 and SME100, respond.io enables fast-growing companies around the world to capture, convert, and retain customers at scale.
We operate as a globally distributed team with employees based around the world, contributing to a diverse and inclusive culture. Join us, and be part of a team that is shaping the future of customer conversation management!
Our Culture
At respond.io, we move fast, work smart, and always keep our customers at the heart of what we do. Here’s what we stand for:
- Solve Customer Problems: Every effort must solve real customer pain points. No guesswork—just real feedback and clear value!
- The 80/20 Rule: We focus on 20% of actions that create 80% of the value. Simple is powerful—it gets us moving fast.
- 100% Alignment, 80% Accuracy: We aim 100% team alignment and 80% accuracy. Perfect plans can wait—clear goals come first.
- Be Direct: We give honest feedback, and tackle problems head-on. Clarity moves us forward!
- Own It and Support Each Other: We step up, help out, and drive outcomes—together.
- Build Human Connections: Work is better when we trust, care, and celebrate wins together. We’re a team!
Role Description
At respond.io, security is a platform engineering discipline, not a gate. Our security team builds Secure SDLC capabilities (Software supply-chain security, AI-assisted SAST, Security automation and AppSec perimeter controls) so developers can ship secure software fast.
We're hiring an Application Security Engineer to own two problems that define modern product security: the security of the code we write, and the security of the code we depend on. That means threat modeling across application and infrastructure, running a SAST pipeline that surfaces real vulnerabilities instead of noise, and securing everything that enters our build, from dependencies to IDEs and container images to CI/CD pipelines, prioritized by what's actually exploitable.
This is a hands-on engineering role. You'll build the tooling and guardrails that prevent entire classes of vulnerabilities, own vulnerability management from detection through verified remediation and act as technical first responder when incidents happen.
Key Responsibilities
- Own software supply-chain security across our Node.js ecosystems i.e. dependency, OSS license, SCA and container image scanning (Socket.dev, Dependabot, AWS ECR) enforced in CI/CD with reachability-based prioritization.
- Run application security testing end to end: threat modeling for new features and architecture changes, AI-assisted SAST pipeline tuning, and the PenTest from scoping through remediation and retest sign-off.
- Secure our GitHub organization and AWS infrastructure: secret scanning, hardened CI/CD workflows, IAM least-privilege, Malware and threat detection and vulnerability management with AWS GuardDuty, Inspector, and Detective.
- Triage security signals and improve detection capability of EDR across all endpoints
- Own edge protection: AWS WAF rule tuning (rate limiting, bot control, managed rule sets) and Network Firewall policies to defend against DDoS, injection attacks, and malicious traffic.
- Act as primary technical responder for application security incidents and continuously fold advances in AppSec and AI-assisted security engineering back into our tooling
What We’re Looking For
- You have 3+ years in an application security role with strong AppSec fundamentals and can read Node.js/JavaScript well enough to trace a vulnerability to its root cause and validate the fix.
- You have secured software supply chains with dependency, license, and container scanning tools like Socket.dev, Dependabot, Trivy, or Semgrep, enforced as CI/CD policies with reachability-based prioritization.
- You have run threat modeling on new features and coordinated pentests from scoping through remediation.
- You have hardened CI/CD and GitHub organizations with branch protection, secret scanning, and Actions security such as OIDC, pinned actions, and scoped permissions.
- You have worked with AWS security services like GuardDuty, Inspector, Detective, and CloudTrail for threat detection, and WAF and Network Firewall for edge protection.
- You have built security tools, scanners, or CI plugins in Python, TypeScript, or Bash. Even better if you’ve used AI for your security automations!
- You can explain risks clearly to engineers and stakeholders in plain English.
What's in it for you
- You will become part of an amazing culture with smart, collaborative teammates who actually care about each other's growth and success.
- You will grow more here than you would anywhere else, that is a promise.
- Virtual events like talent shows, Among Us nights, and online game sessions to keep the fun going, no matter where you are!
- We offer a highly competitive compensation package.
- You'll receive a mental health allowance to support your health and wellness needs.
- Flexible working environment and working hours that fit your lifestyle, wherever you're based.