Encora10
Senior API Security Engineer
Kuala Lumpur
Apply through hirly
hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Senior
- Work mode
- On-site / unstated
- First seen by hirly
- 4 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
- Key Responsibilities:
- ● API Logic Security: Hunt for Business Logic vulnerabilities (BOLA/IDOR, Mass
- Assignment) that traditional firewalls miss.
- ● Authentication & Authorization: Design and validate OAuth2, OIDC, and JWT
- implementations to ensure users can only access their own data.
- ● Attack Simulation: Script automated attacks against the API Gateway to test rate limiting
- and fraud detection rules.
- ● Gateway Hardening: Work with the Platform team to configure the API Gateway (Kong,
- or Azure API Gateway) for maximum security.
- ● Auth & Partner Integration: Deliver new security design patterns and components for
- authentication, authorization, SSO, MFA, and Partner security. Standardize how we
- consume external APIs (Open Banking) and how we secure our own exposed endpoints.
- Technical Requirements:
- ● Strong scripting skills (Python) to automate API attacks.
- ● Expertise in REST and GraphQL security.
- ● Deep knowledge of OAuth 2.0 and OpenID Connect (OIDC) flows.
- ● Experience with API Security tools (Postman, Burp Suite, 42Crunch).
Is this role actually a fit for you?
hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.
Score it against my resume