Application Security Engineer

JOB DESCRIPTION

Job purpose:
We are seeking an experienced Application Security Engineer to join our team. This role will collaborate with other IT professionals as part of our security engineering team to anticipate and correct vulnerabilities in both client-facing and internal applications. The ideal candidate will not just be an expert in application security but have the expertise and capability to provide technical leadership and guidance on security best practices to the entire development team.
Key responsibilities:
Perform proof of concept testing for new security products
Evaluate new technologies and tools that will impact organization security.
Analyze proprietary and third-party software to identify and address security concerns.
Assess the organization’s security architecture and scan code to identify vulnerabilities.
Guide development teams on defensive coding and remediation techniques
Provide security training and guidance for developer teams
Review existing applications and software to identify security improvements
Install, configure, and use new security tools implemented by the organization
Develop and refine app and product security best practices
Maintain documentation of application security controls
Conduct penetration testing and provide retesting support
Serve as a subject matter expert on common attack vectors and application security for developer teams and organization leadership

JOB REQUIREMENT

4+ years of experience in an IT role, preferably in a security team
Experience assessing vulnerabilities in business software and systems.
Experience establishing software development policies.
Experience with application design, risk assessment, and penetration testing
Experience performing blackbox, greybox, and whitebox security assessments of applications using HTTP and/or proprietary protocols
Container DevSecOps experience
Proficient in at least one programming language such as Java, .NET, or Python
Deep knowledge of common security vulnerabilities
Knowledge of application architectural patterns (MVC, Microservices, etc.)
Knowledge of secure development lifecycle principles
Strong problem-solving and analytical skills
Education and Experience required: Bachelor’s degree in engineering, computer science, information security, or a related field
Prefer Qualifications
Experience with iOS or Android security
Certification in information security (CISSP, CISM, CEH, etc.)

WHAT'S ON OFFER

Competitive salary
13th salary and performance bonus
15 days Annual Leave and 5 days Sick Leave
Healthcare Insurance for employee
Laptop Provided
Career path, training courses
Other benefits of Company will be share details in the offer stage

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product

Technical Skills:

Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Job ID:

J01301

Status:

Close

Related Job:

Software Engineer (Node.js) - Database

Ho Chi Minh - Viet Nam


Product

  • NodeJS

Design system architectures, establish coding standards, and construct cohesive, cloud-native solutions. Develop high-quality Node.js code, optimize system performance, and tackle complex software integration challenges. Oversee the testing, deployment, and comprehensive documentation of integrated systems. Mentor less-experienced engineers, engage in cross-functional teamwork, and ensure solutions meet business requirements and international standards. Participate actively in all Agile software development phases, including creating user stories and executing sprint planning Engage with multinational companies, demonstrating flexibility to occasionally adapt to US and EU time zones.

Negotiation

View details

Software Engineer (Node.js) - Platform Security

Ho Chi Minh - Viet Nam


Product

  • NodeJS

Design system architectures, establish coding standards, and construct cohesive, cloud-native solutions. Develop high-quality Node.js code, strengthen system security and reliability, and tackle complex software integration challenges. Design and implement platform security controls across web applications, APIs, and cloud services, including authentication, authorization, session management, secrets management, encryption, and audit logging. Identify and remediate security risks through threat modeling, secure code reviews, automated security testing, dependency scanning, and investigation of security-related issues. Oversee the testing, deployment, and comprehensive documentation of integrated systems. Mentor less-experienced engineers, engage in cross-functional teamwork, and ensure solutions meet business requirements and international standards. Participate actively in all Agile software development phases, including creating user stories and executing sprint planning Engage with multinational companies, demonstrating flexibility to occasionally adapt to US and EU time zones.

Negotiation

View details

AI Agent Ops Engineer

Ho Chi Minh - Viet Nam


Product

  • AI

#Agent Engineering & operation Design, build, and maintain production-grade AI agent systems, including: context engineering and instruction architecture, prompt hardening and safe execution boundaries, tool integrations and multi-step orchestration, memory strategies and reliability patterns. Own the full agent lifecycle: prototype → evaluate → deploy → monitor → iterate. Build and maintain an evaluation pipeline to measure agent quality, catch regressions, and enforce deployment gates (golden datasets, scenario suites, automated checks). Instrument agents and agent platforms for production observability: structured logging, tracing, and metrics; latency and cost monitoring; tool-call success rates and failure analysis. Define operational readiness standards including: rollback criteria, incident response playbooks, recovery paths for common failure modes.#Team Enablement & Coaching Embed with product engineering teams to identify high-value use cases ready for agent automation. We will be operating in a Central Agent Ops role enabling Ai product builders through AI enablers. Translate business workflows into agent-executable tasks with clear: contact boundaries/interfaces, assumptions and inputs/outputs, failure modes and safe fallbacks. Deliver targeted coaching to engineers on: context engineering best practices, harness design and regression testing patterns, agent skill design and tool-contract discipline. Reduce onboarding time for teams adopting AI capabilities-from first conversation to a production-ready agent. Train product engineers to extend and maintain agent skills independently.#Standards & Knowledge operations Author and maintain org-level standards for agents, including: naming conventions, context file structures and ownership rules, skill interface contracts (inputs/outputs, invariants, error handling), evaluation criteria and release quality bars. Establish and enforce "repo-as-discipline" practices so agent knowledge is: versioned, reviewable, discoverable, reusable; not trapped in prompt snippets or individual heads. Build and grow a shared agent skills library that teams can reuse and extend. Track and aggregate AI tooling/framework updates and external best practices, serving as a central intake so product teams don't each have to follow the entire AI landscape. Run internal knowledge-sharing sessions, showcases, and retrospectives to propagate learnings efficiently.

Negotiation

View details