Application Security Engineer

2 weeks ago


Jakarta, Jakarta, Indonesia Bibit Full time

At Stockbit & Bibit, we prioritize the security of our applications and the data of our users. As an
Application Security Engineer
, you'll play a key role in ensuring the security and integrity of our products from mobile apps to backend systems by working closely with our product and engineering tribes

You'll be directly involved in embedding security practices into our SDLC, partnering with each tribe to identify potential risks early, and helping teams design and build securely by default

Why Join Us?
You'll be part of a growing security culture that believes in collaboration over gatekeeping — working directly with engineers and product teams to make security a shared responsibility. You'll also have the opportunity to shape how AppSec operates across multiple tribes and influence security strategy at scale.

What You'll Do

  • Embed with Product Tribes: Collaborate closely with engineers, QA, and product managers to ensure security considerations are part of every development stage (SDLC).
  • Secure Code Review: Review application code (mainly Golang and JavaScript) to identify and mitigate vulnerabilities such as SQLi, XSS, CSRF, and IDOR.
  • Security Testing: Conduct penetration testing, vulnerability scanning, and static/dynamic analysis to proactively uncover weaknesses across web, mobile, and backend services.
  • Threat Modeling: Partner with teams to assess potential threats and design effective mitigations.
  • Bug Bounty Management: Triage, validate, and coordinate resolution for bug reports submitted by external researchers.
  • Security Architecture Guidance: Provide input on secure design patterns, ensuring security is built into architecture and deployments.
  • Incident Response: Support investigation and remediation of application-related security incidents, minimizing impact and improving detection/prevention mechanisms.
  • Security Awareness: Promote secure coding practices within the tribes through knowledge-sharing, internal training, and playbooks.
  • Stay Current: Keep up with the latest vulnerabilities, frameworks, and attack vectors to continuously strengthen our defenses.

What We're Looking For

  • Strong understanding of web and mobile security fundamentals.
  • Hands-on experience with penetration testing and secure code review.
  • Familiarity with Golang and JavaScript (Stockbit's main tech stack).
  • Experience with static/dynamic analysis tools (e.g., Burp Suite, OWASP ZAP, Snyk, etc.).
  • Ability to communicate complex security concepts in a clear, practical way to developers.
  • Bonus: Exposure to CI/CD pipeline security, cloud security (AWS/GCP), or DevSecOps practices.


  • Jakarta, Jakarta, Indonesia PHINCON Full time

    Requirements:Minimum Bachelor's degree in Informatics Engineering, Computer Science, Information Systems, Electrical Engineering, or other IT-related fields.Minimum 8 years of relevant experience.Familiarity with operating systems such as Windows and Linux; knowledge of cloud-based systems (AWS, Azure, GCP) is a plus.Understanding of network protocols and...


  • Jakarta, Jakarta, Indonesia PHINCON Full time

    Requirements:● Minimum Bachelor's degree in Informatics Engineering, Computer Science, Information Systems, Electrical Engineering, or other IT-related fields.● Minimum 8 years of relevant experience.● Familiarity with operating systems such as Windows and Linux; knowledge of cloud-based systems (AWS, Azure, GCP) is a plus.● Understanding of network...

  • Security Engineer

    2 weeks ago


    Jakarta, Jakarta, Indonesia PT Kalos Anthrope Solusi Full time

    Company DescriptionPT Kalos Anthrope Solusi specializes in providing Network and IT solutions, including implementing network security systems, outsourcing network engineers, and handling rollout projects for Network and Security. Known for delivering tailored and efficient services, the company is committed to helping clients achieve their operational...


  • Jakarta, Jakarta, Indonesia PT. Central Proteina Prima, Tbk Full time

    Responsibilities :Assist with planning and implementing cybersecurity measures to protect networking, servers, applications, and computer systemsMonitor and analyse network traffic to detect and respond to security threats and vulnerabilitiesResponsible for operating, administrating and improving security technologies including DLP, Antivirus, IPS/IDS, End...

  • Security Engineer

    2 weeks ago


    Jakarta, Jakarta, Indonesia Bukalapak Full time

    About BukalapakBukalapak is a leading Indonesian technology company dedicated to empowering small and medium-sized enterprises (SMEs). We are committed to creating a fair economy for all, driving innovation, and contributing to the growth of society. At Bukalapak, you'll be part of a dynamic and passionate team making a real impact.About the RoleWe're...

  • Security Engineer

    1 week ago


    Jakarta, Jakarta, Indonesia Skor Technologies Full time

    What You'll Do:Conduct manual penetration testing, primarily on mobile applications, based on product team needs.Review and assess application architecture (front-end and back-end) for potential vulnerabilities.Identify and remediate security issues following OWASP Top 10 and other standard frameworks.Collaborate with engineering and DevOps teams to resolve...

  • Security Engineer

    2 weeks ago


    Jakarta, Jakarta, Indonesia Yourpay Full time

    Company DescriptionYOUR (formerly Yourpay) is a neobank focused on empowering and transforming the lives of underbanked mothers and families in rural areas of Indonesia. Our goal is to provide secure, affordable, and user-friendly financial services to Indonesian migrant workers around the world. We offer a comprehensive platform for payments, transfers,...

  • Security Engineer

    2 weeks ago


    Jakarta, Jakarta, Indonesia Mirae Asset Sekuritas Indonesia Full time

    Company DescriptionMirae Asset Sekuritas Indonesia, as the most prominent global financial group, aims to provide clients with exceptional value and contribute to a vibrant society through investments.Role DescriptionThis is a full-time on-site role for a Security Engineer located in Jakarta Metropolitan Area. You will be responsible for application...


  • Jakarta, Jakarta, Indonesia Grab Full time

    Company Description About Grab and Our WorkplaceGrab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to...

  • Security Engineer

    2 weeks ago


    Jakarta, Jakarta, Indonesia Amartha Full time

    About the RoleThe Software Security Engineer plays an essential role in protecting Amartha from evolving cyber threats. You will be part of our dynamic security team, focusing on identifying and mitigating security risks across our technology stack.About the TeamOur Information Security team consists of dedicated security professionals who prioritize...