Application Security Engineer

3 days ago


Singapore SINGAPORE MARITIME INSTITUTE Full time
Roles & Responsibilities

You will be a key member of the R&D Digital Translation team established under the Singapore Maritime Institute. The R&D Digital Translation team develops and operates digital and cyber products and translates R&D projects to real world implementations for the maritime industry.


You will provide application security consultancy and support to the application teams in areas such as security assessments, DevSecOps, security training and awareness to raise the application security level of competency and standards of our people and organisation.


Key Responsibilities

1. Plan the application security roadmap to improve the way application security is practiced in the organisation.

2. Develop secure application development practices, standards, guidelines, and solutions to raise the application security practices of our application teams.

3. Maintain various application security processes and automated source code scanning platform in the organisation.

4. Perform secure code quality reviews and conduct application penetration testing/vulnerability assessment.

5. Support various types of application testing and delivery (e.g. CI/CD) within the organisation.

6. Train and up-skill developers in the area of secure coding in various programming platforms such as Java, C#, PHP etc. and to write security acceptance criteria in user stories.

7. Train the applications team to write security unit tests and perform secure coding assessments

8. Work with DevOps team to improve security in the CI/CD pipeline


Requirements:

1. At least 3-5 years combined work experience in software development, application security and cloud computing (e.g. Azure, AWS)

2. Background in Computer Science or related field required

3. Experience in conducting manual secure source code review in at least one of the following programming platforms in both waterfall and Agile approach: Java, PHP, Javascript, C#, Android, iOS

4. Experience in threat modelling and able to establish threat profiles for application projects to identify, quantify and remediate application security risks.

5. Experience working with mobile and web application programming interfaces (API) architecture (e.g. REST, SOAP, SSL/TLS)

6. Demonstrate knowledge in industry security best practices such as OWASP Top 10, OWASP application security verification standard

7. Experience on using SAST code scanning tools such as Checkmarx, Sonarqube, etc.

8. Familiar with Agile Development process, CI/CD, DevOps concepts, tools (Git, Gitlab, Github, Jenkins, Anslbe etc) and how automated security testing can be incorporated into CI/CI pipelines

9. Collaborate extensively with various teams (application, networking, infrastructure) to maintain, establish and deliver application security services for the organisation

10. Good verbal/written communications skills and experience interacting with various stakeholders

11. Strong interest and passion for the field of application security.

12. Strong problem-solving and troubleshooting skills.

13. Self-reliant with an analytical and creative mind.


Additional Preferences

1. Experience working with industry APIs such as Apigee or equivalent.

2. Certification in CISSP (Certified Information Systems Security Professional)

3. DevOps related certifications e.g. Azure DevOps Engineer Expert or AWS DevOps Engineer

4. Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OWSE)

5. Experience in working with Government Commercial Cloud (GCC)


Tell employers what skills you have

iOS
Troubleshooting
Application Security
Azure
Cloud Computing
Pipelines
SOAP
REST
User Stories
Agile
Application Development
Security Training
C#
Software Development
CISSP
Agile Development

  • Singapore SINGAPORE MARITIME INSTITUTE Full time

    You will be a key member of the R&D Digital Translation team established under the Singapore Maritime Institute. The R&D Digital Translation team develops and operates digital and cyber products and translates R&D projects to real world implementations for the maritime industry. You will provide application security consultancy and support to the...


  • Singapore Secur Solutions Group Full time

    You will be a key member of the R&D Digital Translation team established under the Singapore Maritime Institute. The R&D Digital Translation team develops and operates digital and cyber products and translates R&D projects to real-world implementations for the maritime industry. You will provide application security consultancy and support to the...


  • Singapore Cannon Security Products Full time

    OKX will be prioritising applicants who have a current right to work in Singapore, and do not require OKX's sponsorship of a visa Who We Are At OKX, we believe the future will be reshaped by technology. Founded in 2017, we are revolutionising world systems through our cutting-edge digital asset exchange, Web3 portal and blockchain ecosystems. We reshape...


  • Singapore KITEWORKS PTE. LTD. Full time

    Roles & ResponsibilitiesCompany OverviewKiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and save of sensitive content. To this end, we created a platform that delivers content governance, compliance, and protection to customers. The platform unifies, tracks, controls, and secures sensitive content...


  • Singapore KITEWORKS PTE. LTD. Full time

    Roles & ResponsibilitiesCompany OverviewKiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and save of sensitive content. To this end, we created a platform that delivers content governance, compliance, and protection to customers. The platform unifies, tracks, controls, and secures sensitive content...


  • Singapore ST ENGINEERING INFO-SECURITY PTE. LTD Full time

    Company description: Singapore Technologies Engineering Ltd Job description: We are seeking an experienced Penetration Tester (Cloud Applications)to join our team. The successful candidate will have expertise in cloud security, penetration testing, and vulnerability assessment. The role involves identifying and exploiting vulnerabilities in cloud-based...


  • Singapore Affinidi Full time

    Affinidi The concept of "Holistic Identity" houses the entire spectrum of discovering, collecting, sharing, storing, and even monetising personal data in the digital realm. Affinidi is a technology company dedicated to changing data ownership for good. We empower businesses and individuals with control and ownership of their data, with a comprehensive...


  • Singapore Abnormal Security Corporation Full time

    About the Role Abnormal Security is looking for a Staff Software Engineer to act as a technical lead for the APAC leg of the Multi-Product Platform division. We are responsible for demonstrating Abnormal’s value to our customers & providing them with a smooth journey, from demo to post-purchase. At Abnormal, we keep our customers—ranging from Global...


  • Singapore Abnormal Security Corporation Full time

    About the Role Abnormal Security is seeking an Enterprise Sales Engineer to join our growing Sales Engineering team. As an Enterprise Sales Engineer, you will be our customer’s technical contact, crafting strategic business cases to win customers over and help them conquer their most intractable email security challenges. In conjunction with Enterprise...


  • Singapore Cannon Security Products Full time

    OKX will be prioritising applicants who have a current right to work in Singapore, and do not require OKX's sponsorship of a visa Who We Are At OKX, we believe the future will be reshaped by technology. Founded in 2017, we are revolutionising world systems through our cutting-edge digital asset exchange, Web3 portal and blockchain ecosystems. We reshape...


  • Singapore Certis Security Full time

    Position Purpose The Responsibility of a Maritime Security Guard (MSG Level 4) working at a security-regulated port is to protect the integrity and safety of all established maritime zones where approved Maritime Security Plans are enforced. This must be done in compliance with MTOFSA rules and regulations, the approved maritime security plan, and the site...


  • Singapore ByteDance Full time

    Application Security Engineer Intern, Security Assurance - 2025 Start ByteDance is a technology company operating a range of content platforms that inform, educate, entertain, and inspire people across languages, cultures, and geographies. About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of...


  • Singapore Certis Security Full time

    Position Purpose To carry out guarding duties at guard sites in accordance with SNP Standing Orders and site instructions, in compliance with AS4421-1996 and all relevant State and/or Federal legislation. NOTE: This section is an overview of the position and role. It is the ‘big picture’ description. This may include employment tenure; Permanent or Part...


  • Singapore SYSCYBER SECURITY SOLUTIONS PTE. LTD. Full time

    Roles & Responsibilities Join our security team and help secure our organization through maintaining, engineering, and deploying security solutions. We use industry-standard security tools, in an automated fashion, to ensure our security teams can operate effectively and provide security to the company. Responsibilities: Troubleshooting security problems...


  • Singapore Area 1 Security Full time

    Available Location: Singapore What you’ll do You are the technical keystone through the entire sales cycle - pre and post sales. You will work closely with our Enterprise prospects and customers in Taiwan market to educate, empower, and ensure their success on the Cloudflare platform. You will leverage your technical expertise in Cloudflare’s global...

  • SECURITY EXECUTIVE

    3 days ago


    Singapore HENDERSON SECURITY SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description & Requirements· Responsible and accountable for effectively managing the day-to-day operations/allocated contract sites and staffs by providing highest quality to employees and Clients· Conduct security and safety risk assessment surveys of the assignments allocated· Conduct investigations and vet incident reports...

  • SECURITY EXECUTIVE

    2 days ago


    Singapore HENDERSON SECURITY SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description & Requirements· Responsible and accountable for effectively managing the day-to-day operations/allocated contract sites and staffs by providing highest quality to employees and Clients· Conduct security and safety risk assessment surveys of the assignments allocated· Conduct investigations and vet incident reports...


  • Singapore Cyber Crime Full time

    Application Security Engineer Intern, Security Assurance - 2025 Start ByteDance is a technology company operating a range of content platforms that inform, educate, entertain and inspire people across languages, cultures and geographies. About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more...


  • Singapore ST ENGINEERING INFO-SECURITY PTE. LTD Full time

    Company description: ST Engineering Info-Security Pte Ltd Job description: Responsibilities: Provide maintenance and support for Customers' Enterprise Cybersecurity Services Perform daily health check of cybersecurity applications and appliances Develop test cases and conduct proof of concept tests on new software and hardware prior to patching Work...


  • Singapore RN CARE PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description: In Charge of designing, deploying, and managing security solutions such as firewalls, IDS/IPS, and encryption technologies. Responsible for conducting security audits, compliance checks such as vulnerability assessments with risk analysis Taking charge of the development and enforcement of security policies,...