Application Security Engineer

Liberty Specialty Markets

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Liberty Specialty Markets is seeking an Application Security Engineer with a DevSecOps mindset to embed security across the software development lifecycle in our APAC insurance markets. You will automate security controls, perform secure code reviews, and partner with engineering teams to design threat models for new features.

This hands-on role requires writing code, breaking things responsibly, and empowering developers to ship secure software swiftly while meeting regulators' cyber and

Qualifications

  • 5+ years in application security or related field.
  • Deep knowledge of OWASP Top 10 and CWE/SANS Top 25.
  • Experience integrating security tooling into CI/CD pipelines.
  • Cloud security experience in AWS/Azure including IAM and network controls.
  • Threat modeling experience (STRIDE).
  • Familiarity with SBOM, SLSA, sigstore, or supply chain security initiatives.
  • Relevant certifications (OSCP, OSWE, AWS Security Specialty).
  • Background in regulated environments — insurance, banking, or financial services preferred.

Responsibilities

  • Design, implement, and maintain security automation across CI/CD pipelines, including SAST, DAST, and secret detection.
  • Conduct secure code reviews for deployments and new designs; provide actionable, context-rich feedback.
  • Partner with engineering teams to perform threat modeling, secure code reviews, and architecture risk assessments.
  • Triage, prioritize, and remediate vulnerabilities discovered through automated tooling and tests.
  • Build and maintain secure-by-default frameworks, libraries, and templates for developers.
  • Develop, maintain, and improve SOPs and guidelines for DevSecOps with regulatory alignment.
  • Ensure AppSec controls support regulatory obligations in APAC markets.
  • Develop and deliver security training and documentation for engineers.
  • Respond to security incidents and perform root-cause analysis.
  • Contribute to vulnerability management metrics and reporting to leadership and GRC teams.
  • Escalate unresolved security issues to the CISO and preserve risks beyond SLAs.
  • Champion a healthy security culture through collaboration.

Skills

AppSec
Web API security
CI/CD Security
Cloud Security
Threat Modeling
APAC Reg Awareness
Communication
Bug Bounty
Open Source
SBOM
OWASP Top10
Secure Code Review

Tools

GitHub Actions
CodeQL
Jenkins
Contrast
Rapid7

Job description

We're looking for an Application Security Engineer with a DevSecOps mindset to help us build security into every stage of our software development lifecycle across our APAC insurance markets. You'll partner with engineering teams to shift security left, automate security controls, and ensure our applications and infrastructure remain resilient against evolving threats — while meeting the cyber and technology risk expectations of insurance regulators across the region. This is a hands‑on role for someone who enjoys writing code, breaking things (responsibly), and empowering developers to ship secure software at speed.

Your work will support compliance with cyber and technology risk requirements issued by insurance regulators in our APAC markets, including:

  • Singapore – Monetary Authority of Singapore (MAS): Notice 127 on Cyber Hygiene, TRM Guidelines
  • Hong Kong – Hong Kong Insurance Authority (HKIA): GL20 on Cybersecurity
  • Australia – Australian Prudential Regulation Authority (APRA): CPS 234 (Information Security), CPS 230 (Operational Risk Management)
  • Malaysia – Bank Negara Malaysia (BNM): Risk Management in Technology (RMiT)
  • China – National Financial Regulatory Administration (NFRA)
  • India – Insurance Regulatory and Development Authority of India (IRDAI): Information and Cyber Security Guidelines
Responsibilities:
  • Design, implement, and maintain security automation across CI/CD pipelines, including SAST, DAST, and secret detection
  • Conduct secure code reviews for change deployments and new designs — review pull requests, release candidates, and infrastructure changes to identify security defects before they reach production; provide actionable, context-rich feedback that helps developers ship securely and on time
  • Partner with engineering teams to perform threat modeling, secure code reviews, and architecture risk assessments for new features, services, and system designs — ensuring security is embedded from the earliest design stages through implementation
  • Triage, prioritize, and remediate vulnerabilities discovered through automated tooling, bug bounty programs, and penetration tests
  • Build and maintain secure‑by‑default frameworks, libraries, and paved‑road templates that make the secure path the easy path for developers
  • Develop, maintain, and continuously improve SOPs and guidelines for DevSecOps — define standardised operating procedures covering secure development lifecycle, pipeline security gates, vulnerability handling workflows, secure release processes, and incident response playbooks; ensure guidelines are practical, adopted by engineering teams, and aligned with regulatory expectations
  • Ensure AppSec controls and evidence support the regulatory obligations of our APAC markets (e.g., APRA CPS 234 information security capability, MAS TRM secure development, BNM RMiT software lifecycle controls)
  • Develop and deliver security training and documentation to raise the security baseline across engineering
  • Respond to security incidents, conduct root cause analysis, and drive systemic improvements
  • Contribute to our vulnerability management program, including SLAs, metrics, and reporting to engineering leadership and to GRC teams supporting regulatory submissions
  • Escalate unresolved security issues and non‑compliances to the CISO — identify and formally preserve risks that remain unresolved beyond defined SLAs, regulatory non‑compliances, or exceptions that exceed accepted risk appetite, ensuring executive visibility and timely decision‑making
  • Champion a healthy security culture through collaboration rather than gatekeeping
Experience & Qualification Requirements:
  • 5+ years of experience in application security, software engineering, or a closely related field
  • Strong understanding of OWASP Top 10, CWE/SANS Top 25, and common web/API attack patterns
  • Hands‑on experience integrating security tooling into CI/CD pipelines (GitHub Actions, Contrast, Rapid7, Tenable, Wiz, Codacy, CodeQL, Jenkins, etc.)
  • Working knowledge of cloud security in AWS, Azure, including IAM, network controls, and container security
  • Experience performing threat modeling using frameworks like STRIDE.
  • Awareness of cyber and technology risk regulations applicable to insurers in APAC (MAS, HKIA, APRA, BNM, NFRA, IRDAI)
  • Strong written and verbal communication skills, especially when explaining security concepts to non‑security audiences
  • Experience with bug bounty programs, red team engagements, or offensive security
  • Contributions to open‑source security tools or published security research
  • Familiarity with SBOM, SLSA, sigstore, or other supply chain security initiatives
  • Relevant certifications (OSCP, OSWE, AWS Security Specialty, or equivalent)
  • Background in regulated environments — insurance, banking, or other financial services preferred
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Liberty in Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
Security Full Stack Engineer
Security Full Stack Engineer

R Systems Singapore Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
APAC AppSec Engineer — Secure DevOps & Compliance
APAC AppSec Engineer — Secure DevOps & Compliance

Liberty Specialty Markets • Singapore

On-site
SGD 120,000 - 180,000
Application Development Security Senior Analyst
Application Development Security Senior Analyst

Success Human Resource Centre Pte Ltd • Singapore

On-site
1-month completion bonus
Security Analyst
Security Analyst

RAPSYS TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 70,000 - 90,000
Cybersecurity Engineer | Hybrid (Singapore)
Cybersecurity Engineer | Hybrid (Singapore)

MRL Consulting Group Ltd. • Singapore

Hybrid
SGD 70,000 - 90,000
Security Engineer
Security Engineer

Simular Inc. • Singapore

On-site
SGD 80,000 - 120,000
Security Engineer
Security Engineer

Simular • Singapore

On-site
SGD 80,000 - 120,000
Application Security Engineer (DevSecOps)
Application Security Engineer (DevSecOps)

Envoy Search Partners Pte Limited • Singapore

On-site
SGD 90,000 - 150,000
Senior Executive, IT Security Operations
Senior Executive, IT Security Operations

auto & general (sea) services pte. limited • Singapore

On-site
SGD 120,000 - 180,000