HomeSearch › Job

Lead Analyst, Technology Centre

AIA

Kuala Lumpur, AIA Digital+ Malaysia · lead

Are you ready to shape a better tomorrow? AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives. If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you.

Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment. If you want to shape a brighter future at AIA Digital+, please read on. About the Role We are seeking an Application Security Analyst to support the organization’s Application Security capability, with primary focus on vulnerability analysis, validation, and remediation advisory for application security findings.

The role will be responsible for reviewing findings generated by application security tools, including Static Application Security Testing and Software Composition Analysis, and determining whether the reported issues are genuine vulnerabilities, false positives, informational findings, or tool-generated inaccuracies. The candidate should have sufficient application security and secure coding knowledge to assess exploitability, business impact, and remediation options.

The successful candidate will work closely with application development teams to validate findings, explain security risks, recommend practical remediation actions, and support secure software delivery. Roles and Responsibilities Analyze, triage, and validate application security findings generated by SAST, SCA, and other application security testing tools. Differentiate genuine vulnerabilities from false positives, informational findings, duplicate findings, and tool-generated inaccuracies.

Review application source code to understand vulnerability context and identify potential security weaknesses. Assess exploitability, attack surface, attack path, and potential business impact of reported vulnerabilities. Provide risk-based remediation guidance to application teams. Review code written in Java, Python, JavaScript, and other commonly used programming languages to support vulnerability validation.

Work with development teams to explain security findings, clarify remediation actions, and support closure of identified issues. Document vulnerability analysis, triage decisions, risk ratings, business impact, and remediation recommendations. Track application security findings, remediation progress, recurring issues, and key application security metrics. Support secure software development practices by providing application security advisory to project and development teams.

Stay updated on application security threats, common vulnerability patterns, secure coding practices, OWASP guidance, CWE weaknesses, and emerging attack techniques. Required Experience and Skills Minimum 3 years of experience in Application Security, Information Security, Secure Software Development, or related areas. Hands-on experience with application security testing, vulnerability validation, secure code review, or vulnerability assessment.

Experience working with SAST, SCA, or similar application security tools. Good understanding of OWASP Top 10, OWASP Web Security Testing Guide, CWE, and secure coding principles. Ability to analyze security findings and determine whether issues are exploitable, relevant, or false positives. Ability to understand source code and application logic in Java, Python, JavaScript, or similar programming languages.

Knowledge of common web application security issues such as injection, broken access control, insecure authentication, insecure deserialization, cryptographic weaknesses, and insecure configuration. Good understanding of authentication, authorization, access control, inpu

Search all live jobs — free, no account →