Senior Security Engineer
Why Coda
Coda is a global growth engine for commerce, connecting people, digital products, and payments through trusted monetization and distribution solutions.
With 600+ people from 57 nationalities across 23 locations, we’re a truly global team headquartered in Singapore, with offices in Amsterdam, Dubai, Bristol, Shanghai, Eindhoven, and across Southeast Asia.
We power global commerce through a dual model. Our B2B solutions, Codapay, Coda Webstore, Coda Links, Coda Distribution, and Giftcloud, enable publishers and brands to monetize and distribute digital content globally. On the consumer side, we operate a portfolio of trusted storefronts including Codashop, Recharge.com, Startselect.com, and mobiletopup.co.uk, that give customers secure and easy access to game top-ups, digital credits, vouchers, gift cards and prepaid products in over 70 markets.
Our culture is built on respect, ownership, and collaboration. We move fast, support each other, and celebrate wins together.
If you’re looking to grow your career and make a real impact in a global team, Coda is the place for you.
The Opportunity
We are looking for an independent, passionate, and persuasive Senior Security Engineer to join our Security Engineering team. You will play a crucial role in driving vulnerability remediation and securing applications from the outset, utilizing cutting-edge solutions to effectively prevent attacks and safeguard the business.
What you'll do
- Work closely with the engineering team on all security initiatives, ensuring products are built securely by default and that audits and remediation efforts are managed to achieve smooth, timely resolution.
- Conduct risk assessments and vulnerability analyses to identify threats and security gaps in existing and new systems and architectures.
- Perform vulnerability scanning across networks, systems, middleware, and databases, then assess each finding by likelihood and potential impact to prioritize what matters.
- Manage the remediation lifecycle with a risk-based approach, ensuring vulnerabilities are resolved in line with accepted industry standards.
- Implement and manage static and dynamic code analysis (SAST/DAST) in CI/CD pipelines; perform source code security reviews and advise developers on remediation.
- Manage the end-to-end process for externally reported vulnerabilities and bug bounty submissions.
- Lead initiatives that measurably reduce risk across our application and infrastructure stack, including applying AI/ML tooling where it delivers real leverage.
- Use scripting and automation to remove manual toil and improve team workflows, rather than defaulting to manual processes out of habit
What we expect
- Take strong ownership of outcomes beyond assigned tasks: proactively identify risks, surface them early to the right stakeholders, and drive resolution without waiting to be asked.
- Clarify vulnerabilities and risks directly with product and engineering stakeholders rather than assuming; communicate bad news, delays, scope changes, and newly discovered risks early, and always pair them with options, not just problems.
- Stay flexible and resourceful, taking on new challenges as the business evolves
What you'll bring
- At least 5+ years in cybersecurity, of which 3+ years is focused on vulnerability management
- At least 3+ years in software development and scripting (Java, Node.js, Python) with continued hands-on use. Able to independently write scripts and simple web apps to solve day-to-day security needs
- Solid foundations in networking, operating systems, and applications
- Demonstrated track record of self-directed work rather than just completed assignments, with concrete examples of risks you identified, owned, and drove to resolution independently, including picking up new skills as needed
- Strong stakeholder management: able to clarify vulnerabilities and risks directly with product and engineering, and communicate effectively with both technical and non-technical audiences
Bonus if you have
- Experience building dedicated internal tools, dashboards, or CI/CD integrations beyond ad hoc scripting
- Experience in bug bounty, penetration testing, and vulnerability assessment
- Knowledge of cloud security
- Knowledge of container security
- Knowledge of AI security
- Knowledge of DevSecOps and security tools in CI/CD
- Hold OSCP, OSWE, AWS Certified Security - Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GPEN, and/or CREST certification
- Experience with a tech or financial services company
We are proud to be an equal opportunity employer, embracing the unique qualities of every individual, regardless of gender, race, age, religion, disability, or other local protected classes. Our goal is to foster an inclusive environment where everyone feels welcome and valued.
Due to the large number of exceptional applications we receive, we can only reach out to shortlisted candidates. If you don't hear from us, rest assured there may be another opportunity at Coda that aligns better with your unique abilities. Remember to check our Careers Page for more exciting job openings!
Job Details
Experience
Senior · 5+ yrs