Application Security Engineer

6 days ago


Jakarta, Jakarta, Indonesia Bibit Full time

At Stockbit & Bibit, we prioritize the security of our applications and the data of our users. As an
Application Security Engineer
, you'll play a key role in ensuring the security and integrity of our products from mobile apps to backend systems by working closely with our product and engineering tribes

You'll be directly involved in embedding security practices into our SDLC, partnering with each tribe to identify potential risks early, and helping teams design and build securely by default

Why Join Us?
You'll be part of a growing security culture that believes in collaboration over gatekeeping — working directly with engineers and product teams to make security a shared responsibility. You'll also have the opportunity to shape how AppSec operates across multiple tribes and influence security strategy at scale.

What You'll Do

  • Embed with Product Tribes: Collaborate closely with engineers, QA, and product managers to ensure security considerations are part of every development stage (SDLC).
  • Secure Code Review: Review application code (mainly Golang and JavaScript) to identify and mitigate vulnerabilities such as SQLi, XSS, CSRF, and IDOR.
  • Security Testing: Conduct penetration testing, vulnerability scanning, and static/dynamic analysis to proactively uncover weaknesses across web, mobile, and backend services.
  • Threat Modeling: Partner with teams to assess potential threats and design effective mitigations.
  • Bug Bounty Management: Triage, validate, and coordinate resolution for bug reports submitted by external researchers.
  • Security Architecture Guidance: Provide input on secure design patterns, ensuring security is built into architecture and deployments.
  • Incident Response: Support investigation and remediation of application-related security incidents, minimizing impact and improving detection/prevention mechanisms.
  • Security Awareness: Promote secure coding practices within the tribes through knowledge-sharing, internal training, and playbooks.
  • Stay Current: Keep up with the latest vulnerabilities, frameworks, and attack vectors to continuously strengthen our defenses.

What We're Looking For

  • Strong understanding of web and mobile security fundamentals.
  • Hands-on experience with penetration testing and secure code review.
  • Familiarity with Golang and JavaScript (Stockbit's main tech stack).
  • Experience with static/dynamic analysis tools (e.g., Burp Suite, OWASP ZAP, Snyk, etc.).
  • Ability to communicate complex security concepts in a clear, practical way to developers.
  • Bonus: Exposure to CI/CD pipeline security, cloud security (AWS/GCP), or DevSecOps practices.


  • Jakarta, Jakarta, Indonesia PT Adira Dinamika Multi Finance Tbk Full time

    Detail Pekerjaan:⁠Mengimplementasikan dan mengembangkan proses Secure SDLC serta memastikan keamanan terintegrasi di setiap tahap pengembangan aplikasi.⁠Mengoperasikan, mengelola, dan mengoptimalkan Application Security Tools seperti SAST, SCA, DAST, serta mengintegrasikannya ke dalam CI/CD pipelines.⁠Merancang, mengembangkan, dan memelihara automation...


  • Jakarta, Jakarta, Indonesia PT Pronata Data Insani Full time

    QualificationsBachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.Minimum 5 years of experience in application security, cybersecurity, or software development.Have Experience as IT Helpdesk/Support L2 minimum 1 yearsStrong understanding of OWASP Top 10 and common application vulnerabilities.Hands-on experience...


  • Jakarta, Jakarta, Indonesia Bumi Amartha Teknologi Mandiri Full time

    Company DescriptionPT. Bumi Amartha Teknologi Mandiri, widely known as Amartek, is a dynamic system integrator founded in 2018, committed to delivering high-value IT solutions globally. As a full-stack technology partner, Amartek specializes in domains such as data & analytics, integration & automation, outcome-based services, and talent augmentation. With...


  • Jakarta, Jakarta, Indonesia PT Bumi Amartha Teknologi Mandiri Full time

    Perform application security testing, including penetration testing, to identify vulnerabilities in applications and systems.Prepare and submit weekly progress reports on ongoing security testing activities.Create detailed penetration testing reports for each tested application or system, including findings, risk levels, and recommendations.Validate and...

  • Security Engineer

    2 weeks ago


    Jakarta, Jakarta, Indonesia PT. PELNI (Persero) Full time

    Company DescriptionPT PELNI (Persero) specializes in providing sea mass transportation for passenger and goods transport across Indonesian islands, operating over 24 passenger vessels, including Ro-Ro and high-speed ferries. The company also manages 10 cargo ships and 50 pioneer ships. With two subsidiaries—PT Sarana Bandar Nasional (SBN) and PT Pelita...


  • Jakarta, Jakarta, Indonesia PT. Central Proteina Prima, Tbk Full time

    Responsibilities :Assist with planning and implementing cybersecurity measures to protect networking, servers, applications, and computer systemsMonitor and analyse network traffic to detect and respond to security threats and vulnerabilitiesResponsible for operating, administrating and improving security technologies including DLP, Antivirus, IPS/IDS, End...


  • Jakarta, Jakarta, Indonesia PT STEAL ALIEN INDONESIA Full time

    Job SummaryWe are looking for a highly motivated Mobile Application Security Engineer (iOS) who has strong hands-on experience in Mobile RASP implementation. This role focuses on securing iOS applications against jailbreak, debugging, hooking, tampering, and reverse engineering.Even candidates with 1–2 years of experience are welcome, as long as they...


  • Jakarta, Jakarta, Indonesia PT Pronata Data Insani Full time

    Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.Minimum 3 years of experience in application security, cybersecurity, or software development.Has experience as an IT Helpdesk / IT Support Level 2 (L2).Strong understanding of OWASP Top 10 and common application vulnerabilities.Hands-on experience with security...

  • Security Engineer

    1 day ago


    Jakarta, Jakarta, Indonesia Skor Technologies Full time

    What You'll Do:Conduct manual penetration testing, primarily on mobile applications, based on product team needs.Review and assess application architecture (front-end and back-end) for potential vulnerabilities.Identify and remediate security issues following OWASP Top 10 and other standard frameworks.Collaborate with engineering and DevOps teams to resolve...

  • Security Engineer

    5 days ago


    Jakarta, Jakarta, Indonesia Yourpay Full time

    Company DescriptionYOUR (formerly Yourpay) is a neobank focused on empowering and transforming the lives of underbanked mothers and families in rural areas of Indonesia. Our goal is to provide secure, affordable, and user-friendly financial services to Indonesian migrant workers around the world. We offer a comprehensive platform for payments, transfers,...