Senior Security Engineer

Bangkok, Thailand

About the role

Why Coda Coda is a global growth engine for commerce, connecting people, digital products, and payments through trusted monetization and distribution solutions. With 600+ people from 57 nationalities across 23 locations, we’re a truly global team headquartered in Singapore, with offices in Amsterdam, Dubai, Bristol, Shanghai, Eindhoven, and across Southeast Asia. We power global commerce through a dual model. Our B2B solutions, Codapay , Coda Webstore, Coda Links, Coda Distribution, and Giftcloud , enable publishers and brands to monetize and distribute digital content globally. On the consumer side, we operate a portfolio of trusted storefronts including Codashop , Recharge.com , Startselect.com , and mobiletopup.co.uk , that give customers secure and easy access to game top-ups, digital credits, vouchers, gift cards and prepaid products in over 70 markets. Our culture is built on respect, ownership, and collaboration. We move fast, support each other, and celebrate wins together. If you’re looking to grow your career and make a real impact in a global team, Coda is the place for you. The Opportunity We are looking for an independent, passionate, and persuasive Senior Security Engineer to join our Security Engineering team. You will play a crucial role in driving vulnerability remediation and securing applications from the outset, utilizing cutting-edge solutions to effectively prevent attacks and safeguard the business. \n

What you'll do Work closely with the engineering team on all security initiatives, ensuring products are built securely by default and that audits and remediation efforts are managed to achieve smooth, timely resolution. Conduct risk assessments and vulnerability analyses to identify threats and security gaps in existing and new systems and architectures. Perform vulnerability scanning across networks, systems, middleware, and databases, then assess each finding by likelihood and potential impact to prioritize what matters. Manage the remediation lifecycle with a risk-based approach, ensuring vulnerabilities are resolved in line with accepted industry standards. Implement and manage static and dynamic code analysis (SAST/DAST) in CI/CD pipelines; perform source code security reviews and advise developers on remediation. Manage the end-to-end process for externally reported vulnerabilities and bug bounty submissions. Lead initiatives that measurably reduce risk across our application and infrastructure stack, including applying AI/ML tooling where it delivers real leverage. Use scripting and automation to remove manual toil and improve team workflows, rather than defaulting to manual processes out of habit What we expect Take strong ownership of outcomes beyond assigned tasks: proactively identify risks, surface them early to the right stakeholders, and drive resolution without waiting to be asked. Clarify vulnerabilities and risks directly with product and engineering stakeholders rather than assuming; communicate bad news, delays, scope changes, and newly discovered risks early, and always pair them with options, not just problems. Stay flexible and resourceful, taking on new challenges as the business evolves What you'll bring At least 5+ years in cybersecurity, of which 3+ years is focused on vulnerability management At least 3+ years in software development and scripting (Java, Node.js, Python) with continued hands-on use. Able to independently write scripts and simple web apps to solve day-to-day security needs Solid foundations in networking, operating systems, and applications Demonstrated track record of self-directed work rather than just completed assignments, with concrete examples of risks you identified, owned, and drove to resolution independently, including picking up new skills as needed Strong stakeholder management: able to clarify vulnerabilities and risks directly with product and engineering, and communicate effectively with both technical and non-technical audiences

Bonus if you have Experience building dedicated internal tools, dashboards, or CI/CD integrations beyond ad hoc scripting Experience in bug bounty, penetration testing, and vulnerability assessment Knowledge of cloud security Knowledge of container security Knowledge of AI security Knowledge of DevSecOps and security tools in CI/CD Hold OSCP, OSWE, AWS Certified Security - Specialty, Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate, GPEN, and/or CREST certification Experience with a tech or financial services company \n We are proud to be an equal opportunity employer, embracing the unique qualities of every individual, regardless of gender, race, age, religion, disability, or other local protected classes. Our goal is to foster an inclusive environment where everyone feels welcome and valued. Due to the large number of exceptional applications we receive, we can only reach out to shortlisted candidates. If you don't hear from us, rest assured there may be another opportunity at Coda that aligns better with your unique abilities. Remember to check our Careers Page for more exciting job openings!

About Coda

Coda is a leading content monetization partner that simplifies global payments for digital publishers. Operating as a Merchant of Record, Coda provides compliant, secure, and localized monetization solutions—no local entity required.

With deep expertise in high-growth markets, especially across Asia-Pacific, Coda supports 90% of the world’s preferred payment methods, including e-wallets, carrier billing, and bank transfers. This ensures publishers can offer frictionless user experiences while meeting local compliance standards.

Coda enables publishers to grow globally—reducing operational overhead, improving payment success rates, and accelerating time-to-market. Trusted by over 300 publishers, including top names in gaming and digital content, Coda helps businesses unlock growth beyond the app.

Other roles at Coda

Interested?

Let me introduce you to the founders.

Skip the process

Job details

Location

Bangkok, Thailand

Company

NameCoda
IndustryContent and Publishing
Team Size4

Funding

Total raised

$240M

Last stage

Series D

Investors

Kleiner Perkins
General Catalyst
Greylock
Khosla Ventures
New Enterprise Associates

Founders

Shishir Mehrotra

Shishir Mehrotra

Co-Founder & CEO

LinkedIn
AD

Alex DeNeui

Co-Founder & CTO

What happens next.

No applications, no recruiter spam. Just the intro.

01

Confirm the fit

A few questions to make sure this role is the right shape for you. Two minutes.

02

I pitch you to the company

I write the intro, send it to the founder, and handle the back-and-forth.

03

A meeting lands on your calendar

If they’re a yes, I book the chat. You show up — that’s the whole job-hunt.