Location: Kuala Lumpur, MY
Department: Backend
Role: DevSecOps Engineer (Application & Endpoint)
Mode: Full-time role
About Aelyst
Aelyst is an AI-powered omnichannel CRM and messaging automation platform built for SMBs in Indonesia and Malaysia. We help businesses capture, convert, and retain customers across WhatsApp, Instagram, and every channel their customers already use — all from one inbox, powered by AI agents that actually close deals.
We are a lean, fast-moving team building for the fastest-growing SMB market in Southeast Asia. Join us and help shape how millions of businesses talk to their customers.
Our Culture
- Solve Real Problems: Every feature must solve a real customer pain point. No guesswork — just feedback and shipped value.
- The 80/20 Rule: We focus on the 20% of work that creates 80% of the value. Simple is powerful.
- Be Direct: Honest feedback, problems tackled head-on. Clarity moves us forward.
- Own It: We step up, help out, and drive outcomes — together.
- Speed Is a Feature: We ship fast, learn fast, and fix fast.
Role Description
Security at Aelyst is a platform engineering discipline, not a gate. You will own the technical security layer around our code, delivery pipelines, cloud telemetry, and developer endpoints — turning policy into enforced, automated configuration without slowing the team down. This is a hands-on role: you will write code, tune tooling, build detections, and respond to incidents. A separate DevSecOps (GRC) role owns compliance audits and policy governance — you partner with them, not duplicate them.
Responsibilities
- Own dependency and container security across our PHP/Composer and Node.js ecosystems, enforcing vulnerability and license policies directly in CI/CD
- Deploy and tune SAST and secret-scanning tooling (e.g. Semgrep, Trivy, TruffleHog) with reachability-based prioritization to keep false positives low
- Harden our GitHub organization: branch protection, secret scanning with push protection, Actions security (OIDC, pinned actions, scoped permissions)
- Build and operate centralized logging/SIEM: ingest and correlate telemetry from cloud audit logs, servers, and GitHub events, and author high-signal detection rules
- Manage endpoint security across team devices: MDM configuration, EDR tuning, and alert triage
- Act as primary technical responder for security incidents: containment, forensics, and hotfix coordination
- Run the annual third-party pentest end to end: scoping, vendor management, findings triage, and remediation tracking
Qualifications
- 3+ years in Application Security, DevSecOps, or Security Engineering with strong AppSec fundamentals (OWASP Top 10, secure code review, threat modeling)
- Working proficiency in PHP and/or JavaScript: able to read production code, trace a vulnerability to root cause, and validate a fix
- Hands-on SCA/SAST experience deploying and tuning tools, including validating AI-generated findings before acting on them
- CI/CD and GitHub hardening experience at the organization level
- Cloud security telemetry experience: audit logs, detection rules, and standing up a SIEM or equivalent log pipeline
- Security automation experience: you have built scanners, CI plugins, or internal tooling; scripting in Python, Bash, or PHP
- Clear written and spoken English: able to explain risk and remediation directly to engineers
What's In It For You
- You will be part of a small team with real ownership — your work ships to customers, fast.
- You will grow more here than you would anywhere else. That is a promise.
- A highly competitive compensation package.
- Flexible working environment and working hours that fit your lifestyle.
Apply To Position