About UrBox
UrBox is Vietnam’s leading digital gifting and loyalty platform, connecting businesses with a wide network of brands and merchants. Our platform operates across digital gifting, loyalty, rewards, vouchers, and stored-value products such as UrCard.
As our platform and ecosystem continue to scale, security is a critical part of protecting our customers, partners, transactions, and technology infrastructure.
About the Role
We are looking for a Security Engineer to strengthen the security of UrBox’s software applications and cloud infrastructure.
You will work across Application Security, AWS Cloud Security, Security Monitoring, Incident Response, and Vulnerability Management, partnering closely with Engineering and Infrastructure teams to identify risks, improve security controls, and drive remediation.
This is a hands-on role for someone who can understand technical risks, investigate security issues, and work directly with engineers to implement practical security improvements.
Key Responsibilities
1. Application Security (AppSec)
- Review security architecture and designs for new features, particularly authentication, OTP, KYC, and payment flows.
- Manage penetration testing activities and track vulnerability remediation with Engineering teams.
- Assess and control the API attack surface, including API inventory, endpoint classification, and identification of zombie/shadow APIs.
- Perform secure code reviews and provide secure coding guidance to developers.
- Identify application vulnerabilities and recommend practical remediation approaches.
- Apply security principles and industry standards such as OWASP Top 10 and OWASP ASVS.
2. AWS Cloud Security
- Monitor and improve AWS Cloud Security Posture through security assessments, configuration reviews, scanning, and hardening.
- Manage and review IAM configurations, permissions, and access controls.
- Secure AWS network environments, including Security Groups and EKS.
- Implement and review data protection and encryption controls across services such as EBS and S3.
- Manage secrets and sensitive credentials securely.
- Monitor and maintain audit trails and security logging, including AWS CloudTrail.
- Use tools such as Prowler or equivalent to identify and remediate cloud security risks.
3. Security Monitoring & Technical Incident Response
- Operate and improve SIEM and security log monitoring using Graylog, Wazuh, or equivalent solutions.
- Monitor security events and investigate suspicious or abnormal activities.
- Investigate and respond to technical security incidents.
- Develop and maintain detection rules for relevant security threats.
- Perform basic threat hunting and security investigations based on available logs and telemetry.
- Work with Engineering and Infrastructure teams to contain, investigate, and remediate security incidents.
4. Vulnerability Management
- Conduct regular vulnerability scanning across infrastructure, applications, dependencies, and containers.
- Analyze and prioritize vulnerabilities based on technical risk and business impact.
- Track remediation progress and work with relevant teams to ensure vulnerabilities are addressed within appropriate timelines.
- Maintain visibility of security risks across the technology environment.
Technical Skills — Must Have
- 3–5+ years of experience in cybersecurity, Security Engineering, Application Security, Cloud Security, or a related field.
- Strong understanding of AWS security, including: IAM, EKS / container security, Network security, Encryption, Security configuration and hardening
- Strong understanding of Application Security, including: OWASP Top 10, OWASP ASVS, SSRF, Injection vulnerabilities, IDOR, Authentication and authorization vulnerabilities, OTP / authentication flow security
- Hands-on experience with SIEM and security log analysis, such as Graylog, Wazuh, Splunk, ELK, or equivalent.
- Experience with vulnerability assessment and remediation.
- Ability to read and understand application code and work directly with developers to identify and remediate security vulnerabilities.
- Good understanding of API security and common attack surfaces.
Nice to Have
- Experience in fintech, payment, e-commerce, digital wallet, loyalty, or stored-value platforms.
- Understanding of payment security and payment-related security risks.
- Experience with container / Kubernetes security.
- Scripting experience with Python and/or Bash for security automation, scanning, and technical checks.
- Experience with tools such as Prowler, Burp Suite, Trivy, or equivalent security tools.
- Experience managing or coordinating penetration testing activities.
- Experience with AWS Security certifications, OSCP, or equivalent security certifications.
Soft Skills
- Strong first-principles thinking and the ability to independently analyze technical security risks.
- Strong analytical and problem-solving skills.
- Able to translate technical vulnerabilities into clear business and engineering priorities.
- Comfortable working directly with developers, DevOps, Infrastructure, and other technical teams.
- Proactive mindset with a strong sense of ownership.
- Able to balance security requirements with practical engineering and business needs.
What Success Looks Like
- Critical application and cloud security risks are identified and addressed proactively.
- Vulnerability remediation is tracked effectively and completed within agreed timelines.
- Security monitoring and detection capabilities continuously improve.
- Security incidents are investigated and handled effectively.
- Engineering teams increasingly adopt secure-by-design and secure coding practices.
- UrBox maintains a stronger and more resilient security posture across its applications and AWS infrastructure.
