9 дней назад
Application Security Engineer (DevSecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (DevSecOps): Providing expert advice, conducting security assessments, and embedding application security across the software development lifecycle with an accent on threat modeling, secure coding, CI/CD security, and vulnerability assessment. Focus on integrating SAST, DAST, and VAPT tools, reviewing DevSecOps pipelines, and guiding development teams in remediating security issues.
Location: 138 Market St, Singapore 048946; hybrid working mode
Company
is a listed European technology company providing consulting, digital services, software, and infrastructure, cloud, and cybersecurity services.
What you will do
- Perform risk assessments of development environments, DevOps workflows, and CI/CD processes.
- Conduct application security assessments, threat modelling, code reviews, and vulnerability assessments.
- Review and improve IAM, network security, secure SDLC practices, source code management, cryptographic key handling, and data protection.
- Guide development teams in adopting secure coding practices and integrating SAST, DAST, and VAPT into their workflows.
- Review CI/CD pipelines against DevSecOps principles and develop secure coding guidelines and security standards.
- Collaborate with development teams to remediate security issues and provide security advice across JavaScript, Node, Java, C#, Python, and other platforms.
Requirements
- At least 3 years of experience in application security or software development with a security focus.
- Strong DevSecOps experience with a foundation in cybersecurity and risk assessment.
- Hands-on knowledge of secure software development lifecycle principles and tools.
- Experience integrating security testing practices into CI/CD environments.
- Experience with secure coding and vulnerability assessments across web and mobile technologies.
- Ability to guide development teams and communicate complex security requirements as practical advice.
Culture & Benefits
- Hybrid working mode with 18 days of annual leave.
- Comprehensive medical and insurance coverage, including general practitioner, hospitalization, dental, and optical care.
- Annual performance-based bonus.
- Training programs, certification opportunities, and training incentives.
- Regular team-building activities and social events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →