Application Security Engineer

2 weeks ago


Singapore NodeFlair Full time

Job Summary:

Job Type

Seniority
Senior

Years of Experience
Information not provided

Tech Stacks
OpenID Strategy Container OAuth AWS Docker Jenkins SAML LDAP Google Cloud CI Microsoft Azure Java Kubernetes C#.NET PHP

Position Overview:

Essential Duties & Responsibilities:

  • Act as a primary technical resource in development of a comprehensive security program to support various Software Development Lifecycles (SDLCs) and ensure that software developed in this SDLC is free of security vulnerabilities.
  • Ensure cybersecurity requirements are met prior to production release.
  • Review and understand code from both business logic and technical standpoint.
  • Coordinate with developers to prioritize and remediate identified true positive vulnerabilities.
  • Collaborate with software development and quality assurance teams to ensure code is free from security defects.
  • Communicate cybersecurity standards applicable to technology and coding workflows.
  • Working with Application Security Engineers, optimize security with existing technologies and processes.
  • Provide technical guidance to developers and engineers on cybersecurity best practices.
  • Review performance of controls such as threat modeling, SCA, SAST, DAST, IAST, RASP, Secrets Scanning, Container Scanning, Misconfiguration Identification, Secure Code Review, CI/CD Pipeline Security, Deployment Environment Security.
  • Actively seek ways to improve secure software development processes.

Additional Responsibilities:

  • Develop and maintain security policies, standards, and guidelines.
  • Provide remediation guidance and recommendations to developers and administrators based on identified vulnerabilities and existing technology stack.
  • Work with software development teams to prioritize and validate the urgency of mitigation of identified product vulnerabilities and security feature enhancement requests.
  • Stay updated with the latest cybersecurity threats and trends and incorporate this knowledge into security architecture designs and practices.
  • Conduct training and awareness programs to enhance the security posture of the organization. Participate in security audits and assist in regulatory compliance efforts.
  • Work closely with IT operations and software development teams to ensure secure systems deployment and operations.
  • Actively contribute to the organization's cybersecurity strategy and roadmap.

Minimum Qualifications:

  • Outstanding collaboration and communication skills.
  • Any of the following combinations of education, professional experience, or both:
At least 2 years of experience in a relevant DevSecOps role and technical degree in computer / information science; or

At least 4 years of experience in a relevant DevSecOps role; or

At least 6 years of related field work experience, at least 1 year of which in a software development role, and at least 1 of which in a cyber security role and technical degree in computer / information science; or

  • At least 8 years of relevant field experience, at least 1 year of which in a software development role, and at least 1 year of which in a cyber security role.
  • Demonstrated experience working with technical and nontechnical staff.
  • Basic knowledge of a broad range of IT, Security, Controls and Service Delivery standards and frameworks for example, International Standards Organization (ISO) 27001, IT Infrastructure Library (ITIL), Control Objectives for IT (CoBIT), and Capability Maturity Model Integration (CMMI).
  • Experience with Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure or other cloud platforms, with experience in developing and implementing software.
  • Experience developing software in various coding languages such as Java, C#, PHP, etc.
  • Safety is an essential function of this job.
  • Consistent and regular attendance is an essential function of this job.
  • Ability to execute multiple projects and tasks under tight deadlines.
  • Provide offhours support on an infrequent, but as needed basis. (Potential shifts may run 24/7 due to the needs of the business).
  • Strong interpersonal skills with the ability to communicate effectively with guests and other Team Members of different backgrounds and levels of experience.
  • Must be able to work varied shifts, including nights, weekends, and holidays.

Additional Experience Recommended:

  • Professional certification in multiple programming languages (C#,.NET, Java, etc.) recommended.
  • Professional certifications in cyber security (CISSP, OSCP, etc.) recommended.
  • Experience with CI/CD and pipeline tools such as Jenkins, Docker, Kubernetes, and others.
  • Knowledge of cloud platforms and services, with experience in cloud security.
  • Experience with automated software and security testing tools and techniques.
  • Ability to stay updated with the latest industry trends and advancements in cybersecurity.
  • Understanding of enterprise software development practices.
  • Experience wo


  • Singapore TAUREN PTE. LTD. Full time

    **Responsibilities: - Work closely with product, engineering, and DevSecOps teams to deliver secure software across web, API, mobile, and other platforms. Enable secure software development and delivery by producing and delivering actionable security requirements, guidelines, and design patterns to engineering. Guide team and thirdparty vendors in performing...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore DSTA - Defence Science & Technology Agency Full time

    Job no:Work type: PermanentLocation: DSTA SingaporeCategories:NAThe Defence Science and Technology Agency (DSTA) brings you to the forefront of cybersecurity, digital transformation and engineering. From working on software development and systems integration to unmanned technologies and artificial intelligence, you can have an impact on Singapore's...


  • Singapore IKIGAI ENABLERS PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description: At least 2 years of experience in a relevant DevSecOps role and technical degree in computer / information science; or At least 4 years of experience in a relevant DevSecOps role; or At least 6 years of related field work experience, at least 1 year of which in a software development role, and at least 1 of which...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media’s application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers  (2) Software...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media’s application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers  (2) Software...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media's application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers (2) Software Composition...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media's application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers (2) Software Composition...


  • Singapore Crypto Full time

    Responsibilities Manage and oversee the company's bug bounty program on platforms like HackerOne, HackenProof, and Bugcrowd. Triage and validate bug reports submitted by external researchers. Prioritize and categorize bugs based on severity and potential impact. Collaborate with the engineering and security teams to understand, track, and remediate...


  • Singapore JAC Recruitment Singapore Full time

    Location:SingaporeSpecialisation:Information TechnologySalary:SGD 80, ,000 (Annual)Reference:PR/093311Contact details:Sarah ChinJob published:March 02, :45Our client is a premier tech firm in the finance industry, renowned for delivering revolutionary financial products to a global user base. This company excels in utilizing state-of-the-art technology to...

  • Security Engineer

    2 weeks ago


    Singapore LZ Security & Service GmbH Full time

    The role will focus on project delivery and implementation for security-related products across infrastructure and systems.Will also perform configuration, testing, and maintenance support for the security devices.Experience in Information Security Risk Management, Vulnerability Management, and Assessments.Serve as the Technical Support expert and capable of...


  • Singapore NIBAARA TECHNOLOGIES PTE. LTD. Full time

    6-8 years of IT experience with minimum 4 years of experience in Application Security including Code Security Review Proven track record of delivering multiple Application Security engagements Demonstrable ability in DevOps/CI/CD and automation practices Ability to comprehend complex architecture and recommend suitable Application Security controls Good...


  • Singapore NodeFlair Full time

    Job Summary:Job TypePermanentSeniorityMid JuniorYears of ExperienceAt least 2 yearsTech StacksHTTP TCP Websockets AWS Go Checkmarx CI gRPC Shell Azure Java Linux JavaScript SQL Python If you're looking for a fastpaced, missiondriven organization where opportunities to learn and excel are endless, then Binance is the place for youResponsibilities: Configure,...


  • Singapore PIXIEPOINT SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesWe are seeking talented and passionate individuals to join our Offensive Security team! This position has a strong focus on discovering unknown vulnerabilities in systems and devices.This position will be based in Singapore, but remote work is possible for the right candidate.We regret to inform that only shortlisted candidates will...

  • Security Engineer

    2 weeks ago


    Singapore Security Bank & Trust Co. Full time

    Formulation and implementation of security response plan and security assurance for the whole life cycle of the system.Handle 7 × 24 hour security incident response.Vulnerability management; anti-phishing tasks.Requirements:5 years+ security experience.Experienced in intrusion detection, event tracing and log analysis. Familiar with common attack and...


  • Singapore INNOEDGE LABS PTE. LTD. Full time

    Roles & ResponsibilitiesAt InnoEdge, we work with organisations to protect them from cyber threats. We help detect new unknown cyber threats through research, fortify networks, and defend critical information infrastructures. Based in Singapore, our team consists of cybersecurity experts who use the advanced techniques and technologies to deliver...


  • Singapore Crypto Full time

    The team comprises of multiple functions from Blockchain Security, Operational Security, Security Governance and Compliance and more. We drive a culture of having a growth mindset and being humble to help everyone achieve their potential. Security and Data Privacy Compliance first strategy which has been at the core of our company.The security team helped to...