Назад
Company hidden
5 дней назад

Lead Information Security Specialist (Cybersecurity)

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Singapore
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Information Security Specialist (Cybersecurity): Building and embedding security automation across software delivery lifecycles with an accent on shift-left security, application security, and secure CI/CD integration. Focus on conducting penetration testing and code reviews, designing security strategies, and reducing risks across code, architecture, cloud, and infrastructure.

Location: Singapore, Singapore. Successful candidates must be Singapore citizens due to client security clearance requirements.

Company

hirify.global is a global technology consultancy integrating strategy, design, and engineering to build digital solutions for clients.

What you will do

  • Implement and refine security automation, security-by-design, and shift-left practices across engineering squads.
  • Integrate SAST, DAST, dependency checking, and container vulnerability assessment into CI/CD pipelines.
  • Conduct manual and automated security code reviews and penetration testing with delivery teams.
  • Define security strategies aligned with delivery methodologies and client requirements.
  • Advise delivery teams and clients on security best practices, Singapore public sector compliance, regulatory expectations, and risk mitigation.
  • Collaborate with delivery, DevOps, and Cloud teams to reduce risks in code, architecture, and infrastructure.

Requirements

  • Singapore citizenship is required for client security clearance.
  • 7+ years of experience as a security engineer working with delivery teams on code and architecture vulnerabilities.
  • Experience implementing security automation and working with agile development methodologies.
  • Applied knowledge of security architecture, OWASP/SANS standards, code reviews, penetration testing, and security testing plans.
  • Experience with tools and techniques including Checkmarx, Burp, ZAP, Fortify, Trivy, SAST, DAST, dependency checking, and container vulnerability assessment.
  • Knowledge of cloud security, AWS, Azure, GCP, password and secret management, networking, firewalls, virtualization, containers, and operating system security.

Culture & Benefits

  • Career development is supported through interactive tools and development programs.
  • Autonomy is balanced with a cultivation culture and peer support.
  • Employees are encouraged to support one another and develop their careers.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →