At a Glance
- Tasks: Conduct application security reviews and enhance security measures through innovative projects.
- Company: Agoda, a global leader in travel technology with a diverse team.
- Benefits: Relocation package, hybrid work model, and generous remote working days.
- Why this job: Join a dynamic team and make a real impact on global travel security.
- Qualifications: 3+ years in application security, strong coding skills, and cloud experience.
- Other info: Inclusive culture with opportunities for professional growth and volunteering.
The predicted salary is between 36000 - 60000 £ per year.
At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world. Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide. No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us.
The Opportunity/Role Summary:
- Conduct application security reviews and perform penetration testing, ensuring alignment with compliance standards.
- Engage in projects, research, and security tool development to enhance security measures and meet compliance requirements.
- Scale security processes using automation.
- Provide training, outreach, and develop documentation to guide security practices among internal teams.
- Offer technical guidance, advocate for automation, evaluate designs, and lead our security teams to empower engineering partners with cutting‑edge tools, techniques, and methodologies to naturally build secure products.
What you’ll Need to Succeed/Role Requirements:
- Strong foundations in secure design reviews, threat modeling experience, code reviews, pen-testing.
- Minimum of 3 years of technical experience with any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security.
- Minimum 2 years experience with Software Development Life Cycle in one or more languages (Go, Python, Nodejs, Rust, etc.).
- Experience with public/private cloud environments (Openshift, Rancher, K8s, AWS, GCP, Azure, etc.).
- In-depth knowledge of security principles, compliance regulations, and change management.
- Experience in running assessments using OWASP MASVS and ASVS.
- Working knowledge on exploiting and fixing application vulnerabilities.
- Proven expertise in architectural threat modeling and conducting secure design reviews.
- In-depth knowledge of common web application vulnerabilities (i.e. OWASP Top 10 or SANS top 25).
- Familiarity with automated dynamic scanners, fuzzers, and proxy tools.
- An analytical mind for problem solving, abstract thought, and offensive security tactics.
- Highly effective communication skills, in both verbal and written forms, to effectively convey technical and non‑technical concepts to a wide variety of audiences.
- Exposure to advanced AI and Large Language Model (LLM) security.
Benefits:
- Relocation package is provided in case you prefer to relocate to Bangkok, Thailand.
- Hybrid Working Model.
- WFH Set Up Allowance.
- 30 Days of Remote Working from anywhere globally every year.
- Employee discount for accommodation globally.
- Global team of 90+ nationalities.
- 40+ offices and 25+ countries.
- Annual CSR / Volunteer Time off.
- Benevity Subscription for employee donations.
- Volunteering opportunities globally.
- Free Headspace subscription.
- Free Odilo & Udemy subscriptions.
- Access to Employee Assistance Program (third party for personal and workplace support).
- Enhanced Parental Leave.
- Life, TPD & Accident Insurance.
Equal Opportunity Employer: At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics.
Senior/Staff Application Security Engineer (Bangkok based, relocation provided) in Edinburgh employer: Agoda
Contact Detail:
Agoda Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior/Staff Application Security Engineer (Bangkok based, relocation provided) in Edinburgh
✨Tip Number 1
Network like a pro! Reach out to current or former employees at Agoda on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills. Make sure you can confidently discuss secure design reviews, threat modelling, and pen-testing. Practice explaining complex concepts in simple terms – it’ll impress the interviewers!
✨Tip Number 3
Show your passion for travel and technology! When you talk about your experience, link it back to how it can enhance security in travel tech. This will help you stand out as someone who truly gets Agoda's mission.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining the Agoda team and ready to embark on this exciting journey with us.
We think you need these skills to ace Senior/Staff Application Security Engineer (Bangkok based, relocation provided) in Edinburgh
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior/Staff Application Security Engineer role. Highlight your experience with secure design reviews, threat modelling, and any relevant coding languages. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about application security and how your background makes you a great fit for Agoda. Don’t forget to mention any specific projects or achievements that showcase your expertise.
Showcase Your Technical Skills: In your application, be sure to highlight your technical skills, especially in areas like pen-testing and compliance standards. We love seeing candidates who can demonstrate their knowledge of security principles and tools, so don’t hold back!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details about the role and our company culture there!
How to prepare for a job interview at Agoda
✨Know Your Stuff
Make sure you brush up on your application security knowledge, especially around secure design reviews and threat modelling. Be ready to discuss your experience with tools like OWASP MASVS and ASVS, as well as any pen-testing you've done. This will show that you're not just familiar with the concepts but have practical experience too.
✨Showcase Your Problem-Solving Skills
Prepare to share specific examples of how you've tackled security challenges in the past. Think about times when you identified vulnerabilities or improved security processes. This will demonstrate your analytical mind and ability to think critically under pressure.
✨Communicate Clearly
Since you'll need to convey technical concepts to various audiences, practice explaining complex ideas in simple terms. Use examples from your past work to illustrate your points. Good communication can set you apart, especially in a role that requires collaboration with engineering teams.
✨Be Ready for Technical Questions
Expect some deep dives into your technical expertise, particularly around secure coding and cloud environments. Brush up on languages like Go, Python, or Node.js, and be prepared to discuss your experience with public/private cloud platforms. This is your chance to shine, so don’t hold back!