Назад
Company hidden
9 дней назад

Application Security Engineer (DevSecOps)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Singapore
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (DevSecOps): Providing expert advice, conducting security assessments, and embedding application security across the software development lifecycle with an accent on threat modeling, secure coding, CI/CD security, and vulnerability assessment. Focus on integrating SAST, DAST, and VAPT tools, reviewing DevSecOps pipelines, and guiding development teams in remediating security issues.

Location: 138 Market St, Singapore 048946; hybrid working mode

Company

hirify.global is a listed European technology company providing consulting, digital services, software, and infrastructure, cloud, and cybersecurity services.

What you will do

  • Perform risk assessments of development environments, DevOps workflows, and CI/CD processes.
  • Conduct application security assessments, threat modelling, code reviews, and vulnerability assessments.
  • Review and improve IAM, network security, secure SDLC practices, source code management, cryptographic key handling, and data protection.
  • Guide development teams in adopting secure coding practices and integrating SAST, DAST, and VAPT into their workflows.
  • Review CI/CD pipelines against DevSecOps principles and develop secure coding guidelines and security standards.
  • Collaborate with development teams to remediate security issues and provide security advice across JavaScript, Node, Java, C#, Python, and other platforms.

Requirements

  • At least 3 years of experience in application security or software development with a security focus.
  • Strong DevSecOps experience with a foundation in cybersecurity and risk assessment.
  • Hands-on knowledge of secure software development lifecycle principles and tools.
  • Experience integrating security testing practices into CI/CD environments.
  • Experience with secure coding and vulnerability assessments across web and mobile technologies.
  • Ability to guide development teams and communicate complex security requirements as practical advice.

Culture & Benefits

  • Hybrid working mode with 18 days of annual leave.
  • Comprehensive medical and insurance coverage, including general practitioner, hospitalization, dental, and optical care.
  • Annual performance-based bonus.
  • Training programs, certification opportunities, and training incentives.
  • Regular team-building activities and social events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →