Principal Engineer(Application Security)

1 week ago


Singapore DSTA - Defence Science & Technology Agency Full time

Job no:

Work type:
Permanent

Location:
DSTA Singapore

Categories:

NA
The Defence Science and Technology Agency (DSTA) brings you to the forefront of cybersecurity, digital transformation and engineering.

From working on software development and systems integration to unmanned technologies and artificial intelligence, you can have an impact on Singapore's defence.

Achieve your fullest potential with opportunities to build your technical expertise and hone your competencies in diverse domains.

You can also expect an immersive learning experience, where you will work with bright minds and collaborate with global industry experts.


DSTA is recognised as one of the top 10 employers in the Engineering & IT sector, where our engineers and IT professionals work alongside procurement specialists to deliver state-of-the-art capabilities for Singapore's peace and security.

Internship opportunities and a meaningful career await you.

Opportunity
DSTA's DevSecOps group is looking for experienced Principal Application Security Engineer to scale our DevSecOps capability to enable greater speed and agility in software development across DSTA, MINDEF and SAF

_ What can the team offer you?_


You can look forward to joining a newly formed term with a mission to provide centralised DevSecOps services across DSTA, MINDEF and SAF.

You will be responsibly to design, develop and deliver DevSecOps capabilities with the aim to substantially reduce the software delivery lead-time enterprise-wide.

To achieve this, we will need you to introduce technologies to push the automation boundary, streamline work processes and embed advanced software engineering practices into the Continuous Integration / Continuous Delivery (CI/CD) pipeline to create the shift-left effects in software development.


You can be expected to work alongside passionate DevSecOps professional who is excited in our DevSecOps journey to provide developers with a user-friendly development platform, and a secure CI/CD pipeline.


We encourage our community to bring their whole selves to work, respect the need for work-life balance and allow for autonomy in the design process and your career.


In this role, you will:

  • Design, develop and implement security standards and controls in software development lifecycle and CI/CD pipelines.
  • Develop security tools and scripts to improve security processes.
  • Drive automated security testing and validation, and the security shiftleft culture.
  • Recommend, trial and implement automated security test and monitoring tools.
  • Perform threat risk assessment and/or vulnerability assessment of the DevSecOps platforms.
  • Staying uptodate with security trends and technologies

Minimum qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering or related fields.

_Relevant experience and mindset_

  • Strong knowledge of cybersecurity principles and practices especially in DevSecOps context.
  • Good understanding in DevSecOps principles.
  • Experience with security automation tools and technologies for CI/CD pipelines such as Software Composite Analysis (SCA), Statics Application Security Test (SAST), Dynamic Application Security Test(DAST), vulnerability scanning tools, and etc.
  • Excellent analytical skills including the ability to deliver technical concepts clearly across different audiences.
  • Have a passion for innovation in delivering solutions/services.

_It would be a bonus if you have_

  • Familiarity with the security considerations for cloudnative software architecture.
  • Experienced in developing security sidecar for Kubernetes.
  • Familiarity with using automated deployment tools such Terraform and Ansible to strengthen security
  • Working experience with cloud computing providers (e.g. Amazon AWS, Microsoft Azure etc.).
  • Familiarity with software development methodologies and practices such as Scrum or Extreme Programming.

Application Instructions
As DSTA is an agency under Ministry of Defence, only Singapore Citizens will be considered.

Advertised: 30 Jun 2023 Singapore Standard Time

Applications close: 30 Jul 2023 Singapore Standard Time
  • Principal Engineer

    1 week ago


    Singapore EMA Energy Market Authority Full time

    Principal Engineer / Senior Principal EngineerAssist DD/Specialist to: Review and enforce legislation and codes of practice- evelop performance standards and technical regulatory frameworks for electricity licensees' compliance Investigate power failure, voltage dip and electrical incidents, and breaches of legislation, performance standards and codes of...


  • Singapore TAUREN PTE. LTD. Full time

    **Responsibilities: - Work closely with product, engineering, and DevSecOps teams to deliver secure software across web, API, mobile, and other platforms. Enable secure software development and delivery by producing and delivering actionable security requirements, guidelines, and design patterns to engineering. Guide team and thirdparty vendors in performing...


  • Singapore Palo Alto Networks, Inc. Full time

    Our Mission At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we're...


  • Singapore Affinidi Full time

    Affinidi focuses on changing data ownership for good, empowering communities with control and ownership of their data. We do that through enabling the creation, sharing and verification of Verifiable Credentials - a secure and cryptographically verifiable way of sharing sensitive data.Headquartered in Singapore, with offices in India, Germany and Ukraine,...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore NEW FUTURE HOLDINGS PTE. LTD. Full time

    JOB SUMMARYAs the Principal Software Engineer (Applications) , you will provide influential best practices and technical leadership in the planning, architecture, design, implementation and lead a development team to deploy our yet to be announced next generation integrated best-of-suite enterprise solutions. The role of the Principal Software Engineer...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore FNZ Full time

    Role Description At FNZ we take security seriously, our growing of the security organisation reflects this. We are developing a class leading security function and are looking for passionate people to join our team. We are looking for someone to help build our application security function. Reporting directly to the Application Security Lead, this exciting...


  • Singapore IKIGAI ENABLERS PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description: At least 2 years of experience in a relevant DevSecOps role and technical degree in computer / information science; or At least 4 years of experience in a relevant DevSecOps role; or At least 6 years of related field work experience, at least 1 year of which in a software development role, and at least 1 of which...


  • Jurong East, Singapore ST Engineering Full time

    ST Engineering is a global technology, defence and engineering group with offices across Asia, Europe, the Middle East and the U.S., serving customers in more than 100 countries. The Group uses technology and innovation to solve real-world problems and improve lives. Our dedication to excellence and our strong track record have earned us a distinctive...


  • Jurong East, Singapore ST Engineering Full time

    ST Engineering is a global technology, defence and engineering group with offices across Asia, Europe, the Middle East and the U.S., serving customers in more than 100 countries. The Group uses technology and innovation to solve real-world problems and improve lives. Our dedication to excellence and our strong track record have earned us a distinctive...


  • Jurong East, Singapore ST Engineering Full time

    ST Engineering is a leading global technology, defence, and engineering group with a strong presence in Asia, Europe, the Middle East, and the U.S., serving customers in over 100 countries. We are dedicated to using technology and innovation to solve real-world problems and enhance lives. Our commitment to excellence and our proven track record have...


  • Jurong East, Singapore ST Engineering Full time

    ST Engineering is a leading global technology, defence, and engineering group with a strong presence in Asia, Europe, the Middle East, and the U.S., serving customers in over 100 countries. We are dedicated to using technology and innovation to solve real-world problems and enhance lives. Our commitment to excellence and our proven track record have...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media’s application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers  (2) Software...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media’s application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers  (2) Software...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media's application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers (2) Software Composition...


  • Singapore SPH Media Limited Full time

    As an Intern Application Security Engineer, you will be responsible for application security activities, working closely with SPH Media's application development teams. This includes tools and practices on: (1) Static Application Security Testing (SAST), which focuses on web and mobile application source codes written by developers (2) Software Composition...


  • Singapore Crypto Full time

    Responsibilities Manage and oversee the company's bug bounty program on platforms like HackerOne, HackenProof, and Bugcrowd. Triage and validate bug reports submitted by external researchers. Prioritize and categorize bugs based on severity and potential impact. Collaborate with the engineering and security teams to understand, track, and remediate...


  • Singapore JAC Recruitment Singapore Full time

    Location:SingaporeSpecialisation:Information TechnologySalary:SGD 80, ,000 (Annual)Reference:PR/093311Contact details:Sarah ChinJob published:March 02, :45Our client is a premier tech firm in the finance industry, renowned for delivering revolutionary financial products to a global user base. This company excels in utilizing state-of-the-art technology to...