hirly

Encora10

Senior API Security Engineer

Kuala Lumpur

Apply through hirly

hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.

hirly's read of this role

Role family
Engineering
Seniority
Senior
Work mode
On-site / unstated
First seen by hirly
4 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

  • Key Responsibilities:
  • ● API Logic Security: Hunt for Business Logic vulnerabilities (BOLA/IDOR, Mass
  • Assignment) that traditional firewalls miss.
  • ● Authentication & Authorization: Design and validate OAuth2, OIDC, and JWT
  • implementations to ensure users can only access their own data.
  • ● Attack Simulation: Script automated attacks against the API Gateway to test rate limiting
  • and fraud detection rules.
  • ● Gateway Hardening: Work with the Platform team to configure the API Gateway (Kong,
  • or Azure API Gateway) for maximum security.
  • ● Auth & Partner Integration: Deliver new security design patterns and components for
  • authentication, authorization, SSO, MFA, and Partner security. Standardize how we
  • consume external APIs (Open Banking) and how we secure our own exposed endpoints.
  • Technical Requirements:
  • ● Strong scripting skills (Python) to automate API attacks.
  • ● Expertise in REST and GraphQL security.
  • ● Deep knowledge of OAuth 2.0 and OpenID Connect (OIDC) flows.
  • ● Experience with API Security tools (Postman, Burp Suite, 42Crunch).

Is this role actually a fit for you?

hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.

Score it against my resume
Senior API Security Engineer at Encora10 — hirly