Back to jobs Featured

Application Security Analyst

Job Responsibilities

  • Perform hands‑on application security testing (manual and automated) on web, API, mobile and cloud applications
  • Identify, analyze and validate security vulnerabilities using industry tools and frameworks
  • Conduct secure code reviews and provide practical remediation guidance to development teams
  • Work closely with developers to embed security best practices into the SDLC / DevSecOps pipelines
  • Act as a security advisor, translating technical risks into developer‑friendly recommendations
  • Track vulnerability remediation progress and ensure timely closure
  • Promote secure coding awareness through training, documentation and technical guidance

Job Requirements

  • Degree in Computer Science, IT or related discipline
  • 5+ years IT experience with strong exposure to application development and security testing
  • Solid knowledge of OWASP Top 10, CWE, CVSS and secure coding principles
  • Hands‑on experience with application security testing tools (e.g. Burp Suite, SAST/DAST tools)
  • Proficient in at least one programming language (Java, Python, C# or similar)
  • Experience working in Agile / DevSecOps environments
  • Strong analytical, problem‑solving and communication skills
  • Good command of spoken and written Cantonese and English; Mandarin is a plus
  • Relevant certifications (e.g. OSCP, CISSP, GIAC) are an advantage
  • Willingness to travel occasionally within China / Asia