🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Job Purpose: This role will manage and coordinate application security vulnerabilities, security testing results, and remediation activities to reduce technology risk. Collaborate with stakeholders to embed security practices into development processes and support effective risk management and compliance. Responsibilities : Perform application security vulnerability management activities, including tracking, validation, prioritization, and remediation follow-up across enterprise applications. Support DevSecOps processes by integrating security requirements into the software development lifecycle (SDLC) and coordinating security testing activities. Manage and monitor security findings from SAST, DAST, SCA, penetration testing, and vulnerability assessments, ensuring timely remediation by development teams. Coordinate with application owners, developers, vendors, and technology teams to address application security risks and compliance requirements. Administer and maintain Jira workflows, dashboards, and reporting for security vulnerability tracking, remediation progress, and risk management Support cybersecurity incident investigation and resolution activities related to application security events and vulnerabilities. Qualifications : Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Software Engineering, or a related field. 2–5 years of experience in Application Security, DevSecOps, Software Development, Cybersecurity, or IT Security Operations. Good understanding of secure software development practices, OWASP Top 10, secure coding principles, and common application vulnerabilities. Experience with DevSecOps tools and security testing solutions such as SAST, DAST, SCA, container security, or CI/CD security controls. Hands-on experience using Jira for vulnerability management, issue tracking, workflow management, and reporting. Ability to work effectively with developers, architects, infrastructure teams, and business stakeholders to drive risk remediation. Relevant certifications such as Security+, CEH, CSSLP, GWEB, GWAPT, Azure Security Engineer, or equivalent security certifications are an advantage. เพื่อให้เป็นไปตามมาตรฐานและนโยบายการคัดสรรบุคลากรของบริษัท เอไอเอ (ประเทศไทย) หลังผ่านการคัดเลือกแล้ว ผู้สมัครต้องได้รับการตรวจประวัติอาชญกรรมก่อนเริ่มงาน ทั้งนี้ บริษัทจะเก็บประวัติอาชญากรรมของท่านตามนโยบายข้อมูลส่วนบุคคลของบริษัท รายละเอียดตามลิงค์แนบ [https://www.aia.co.th/th/about-aia/privacy/candidate] In accordance with recruitment policy and hiring standard of AIA (Thailand) Company Limited, after completing the selection process, you are required for criminal background check before joining the company. Your criminal record information will be retained according to the PDPA policy of the company. As per attached link [https://www.aia.co.th/th/about-aia/privacy/candidate]