Senior Application Security Engineer

4 days ago


Singapur, Singapore Ascenda Full time

Join to apply for the Senior Application Security Engineer role at Ascenda Great to Meet You We are Ascenda. Ascenda powers the growth of leading financial services brands worldwide with premium rewards programs that differentiate their products, drive profitable customer behaviors, and create sustained engagement. We are behind the world-class rewards propositions of major banks and fintechs around the globe, including brands like American Express, Capital One, Brex, Robinhood, Ramp, HSBC, Virgin Money (Australia), SMBC (Japan), ICBC (China), Bradesco (Brazil), ANZ (Australia), HDFC (India) and many others. We are a thriving global Loyalty as a Service company and experiencing rapid expansion. Join our dynamic finance team as one of its earliest leaders, contributing to the development of our financial planning strategies as we strive for hypergrowth. Our team spans 20 cities worldwide, with dual headquarters in Singapore and New York, totaling 250 team members. Join us as a Senior Application Security Engineer in Singapore The Role We are looking for a passionate Application Security Engineer who is keen to learn, grow and bring his/her experience in a fast-paced environment. We promote and do security through (we think) fun and cool stuff. At Ascenda, our Security Engineers work closely with other engineers like the developers and devops teams, with the common goal of continually improving the security posture of our applications. On some days, we would be conducting pentests on our applications, other days we would be writing, implementing, and working on security engineering projects to suit our security needs. We have achieved compliance with the most stringent security standards (PCI-DSS, SOC2, ISO27001). Our partners are financial institutions and airlines, and they expect a very high level of availability, reliability and security. Your Impact Scope out and conduct penetration testing on our various applications, and work together with developers to propose and implement a fix for the findings. Propose and implement projects (SAST/DAST, phishing exercises for example) that ultimately improve the security of our applications and the company as a whole. Suggestions are more than welcome Research, analyse, and evaluate the risks of introducing new technologies and tools to our current architecture from a security perspective. Help Ascenda scale out security tasks and processes using automation. Conceptualise and comprehend various security requirements, applying them to the company's context, and identifying any gaps. Propose and implement solutions to address these gaps. Investigate and analyse the occasional security logs and take the necessary actions. Occasionally provide technical and non-technical security advice to employees. This could range from questions related to “Is this a phishing email?” to “If we design our application in this way, what are the security concerns?”. Constantly be up to date with security trends, news and understanding of their relevance to our security posture. Work together with the security team on creating security awareness training materials, targeted at both technical developers as well as non-technical people. Be overall an independent and committed person with a strong tenacity to look into issues deeply. We Expect You To Have Experience in scoping and conducting penetration testing on web applications. Experience in conducting source code reviews across various applications running on microservices architecture. Knowledge of web application and API security vulnerabilities and how they can be exploited. Knowledge in scripting (Bash, Python, Javascript, etc). Knowledge in Linux, AWS, Kubernetes, Terraform, and the Software Development Lifecycle (SDLC). Familiarity with the concepts of Industrial Security Certifications such as PCI-DSS, SOC2, ISO27001. Technical Security Certifications such as CREST, OSCP, OSWE (or any of the other Offensive Security Certifications). Independence and good communication skills, able to interact and work effectively with both technical and non-technical people. It Will Be a Bonus If You Have Deep knowledge of Cloud and Container vulnerabilities and exploiting them. Deep knowledge in exploiting web applications running on ruby frameworks. Bug Bounty findings and CVEs to your name. Experience with playing CTFs (Share your writeups). Why Join Ascenda? Ascenda offers the unique opportunity to lead in the loyalty ecosystem space, shaping the future of rewards programs. We are passionate, we keep things simple, we focus on results, we work together & we innovate Benefits High growth environment & exponential career development Mobile & flexible work environment WFH office equipment allowance Medical insurance coverage Employee recognition programs Competitive compensation Travel perks & Employee rewards Ascenda is dedicated to diversity and inclusion, welcoming candidates from all backgrounds. Ready to power growth for the financial services industry? Apply now Together, we’ll redefine what’s possible. #J-18808-Ljbffr



  • Singapur, Singapore Marina Bay Sands Full time

    Senior Engineer, Application Security (IT) LOVE WHAT YOU DO? THERE IS A PLACE FOR YOU HERE! Be part of our diverse and inclusive team. Job Summary DevOps is responsible for integrating developer experience, infrastructure, and technology operations support to enhance software development and deliver comprehensive solutions, including gaming-related systems,...


  • Singapur, Singapore Income Insurance Limited Full time

    Join to apply for the Senior/Security Engineer role at Income Insurance Limited 2 days ago Be among the first 25 applicants Join to apply for the Senior/Security Engineer role at Income Insurance Limited Get AI-powered advice on this job and more exclusive features. Deploy automation to improve cyber efficiencies and streamline the cyber security processes...


  • Singapur, Singapore Binance Full time

    Join to apply for the Senior Application Security Architect role at Binance Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by over 280 million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed,...


  • Singapur, Singapore Hyphen Connect Full time

    Join to apply for the Web3 Senior Security Engineer role at Hyphen Connect . We are working with a decentralised exchange which looks to innovate on providing the best of CEXs and DEXs, focusing on building a safe, simple and scalable platform for trading. They differentiate themselves by offering institutional level systems and support whilst remaining...


  • Singapur, Singapore Selby Jennings Full time

    Our client is a globally recognised technology company and they are looking for an Infrastructure Security Engineer (Senior Hire) with deep expertise in cybersecurity and large scale infra systems, for their Singapore office. Responsibilities of a Senior Infrastructure Security Engineer: Design and secure global game publishing infrastructure using best...


  • Singapur, Singapore EOS Full time

    Join to apply for the Senior Field Application Engineer role at EOS 3 days ago Be among the first 25 applicants Join to apply for the Senior Field Application Engineer role at EOS Job Title: Senior Field Application Engineer (m/f/d)Location: SingaporeWHAT YOU’LL BE DOING:Process Development & OptimizationAdapt and optimize process products for laser...


  • Singapur, Singapore Peoplebank Full time

    Senior DevOps Engineer (Applications) (24-Month Contract) Location: Central, Singapore Salary: Up to SGD 7,000/month About the Role We’re seeking a hands‑on Senior DevOps Engineer (Applications) to own the reliability, patching, security posture, and run operations of one or two mission‑critical enterprise applications. You’ll stand up and operate HA...


  • Singapur, Singapore BluOcean Security Full time

    As a System & Service Engineer, your primary responsibility will be to provide exceptional maintenance and troubleshooting services to our customers in the region. You will oversee a comprehensive range of after-sales services, including managing service cases, performing routine maintenance, handling power shut-down services, and addressing any other...


  • Singapur, Singapore Centre for Strategic Infocomm Technologies (CSIT) Full time

    Cyber Security Vulnerability Researcher (Web Applications) Join to apply for the Cyber Security Vulnerability Researcher (Web Applications) role at Centre for Strategic Infocomm Technologies (CSIT) . Get AI-powered advice on this job and more exclusive features. Conduct research and analysis to understand web application architectures, discovering...


  • Singapur, Singapore Shopee Full time

    Senior Security Governance Engineer - Infrastructure Security About The Team We are looking for a senior security engineer to support security governance projects and optimise security tool operations. This role requires a strong technical foundation in security engineering, risk management, and automation, along with the ability to drive security...