Application Security Risk Manager

Kerry Consulting

Singapore

On-site

SGD 120,000 - 170,000

Full time

24 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kerry Consulting seeks an experienced Application Security Risk Manager to provide risk oversight and challenge across application security and technology controls.

The role will partner with Technology, Cybersecurity and Engineering teams to identify security risks and ensure applications are designed, developed and operated securely. You will conduct risk assessments, review controls across the SDLC, and help shape security policies and metrics.

Qualifications

  • 8–15 years of experience across application security, cybersecurity, technology risk, security architecture or technology assurance.
  • Strong understanding of application security, SDLC and secure software development.
  • Knowledge of DevSecOps, CI/CD, APIs, IAM, vulnerability management and cloud security.
  • Experience assessing application security controls and technology risks.
  • Familiarity with SAST, DAST, penetration testing and frameworks such as OWASP, NIST and ISO 27001.
  • Financial services and regulatory experience would be advantageous.
  • Strong analytical, communication and stakeholder management skills.
  • Certifications such as CISSP, CISM, CRISC, CSSLP or CCSP would be advantageous

Responsibilities

  • Provide risk oversight and challenge across application security and software development activities.
  • Conduct security risk assessments for new applications, major technology changes and critical systems.
  • Assess security controls across the SDLC, including secure design, development, testing, deployment and production.
  • Review risks relating to application vulnerabilities, APIs, integrations, authentication, access management and data protection.
  • Assess DevSecOps and CI/CD controls, including SAST, DAST, penetration testing and vulnerability management.
  • Review security exceptions, risk assessments and remediation plans and provide independent challenge where required.
  • Assess application security across on-premise, cloud and hybrid environments.
  • Conduct thematic reviews to identify systemic risks and control weaknesses.
  • Oversee significant application security incidents and remediation.
  • Develop risk metrics and contribute to application security policies, standards and control frameworks.
  • Monitor emerging application security threats and advise stakeholders on relevant risks.

Skills

Application security
SDLC
DevSecOps
CI/CD
APIs
IAM
Vulnerability management
Cloud security
Security risk assessment

Job description

We are seeking an experienced Application Security Risk Manager to provide risk oversight and challenge across application security and technology controls.

The role will partner with Technology, Cybersecurity and Engineering teams to identify security risks and ensure applications are designed, developed and operated securely.

Key Responsibilities:
  • Provide risk oversight and challenge across application security and software development activities.
  • Conduct security risk assessments for new applications, major technology changes and critical systems.
  • Assess security controls across the SDLC, including secure design, development, testing, deployment and production.
  • Review risks relating to application vulnerabilities, APIs, integrations, authentication, access management and data protection.
  • Assess DevSecOps and CI/CD controls, including SAST, DAST, penetration testing and vulnerability management.
  • Review security exceptions, risk assessments and remediation plans and provide independent challenge where required.
  • Assess application security across on-premise, cloud and hybrid environments.
  • Conduct thematic reviews to identify systemic risks and control weaknesses.
  • Oversee significant application security incidents and remediation.
  • Develop risk metrics and contribute to application security policies, standards and control frameworks.
  • Monitor emerging application security threats and advise stakeholders on relevant risks.
Requirements:
  • 8-15 years of experience across application security, cybersecurity, technology risk, security architecture or technology assurance.
  • Strong understanding of application security, SDLC and secure software development.
  • Knowledge of DevSecOps, CI/CD, APIs, IAM, vulnerability management and cloud security.
  • Experience assessing application security controls and technology risks.
  • Familiarity with SAST, DAST, penetration testing and frameworks such as OWASP, NIST and ISO 27001.
  • Financial services and regulatory experience would be advantageous.
  • Strong analytical, communication and stakeholder management skills.
  • Certifications such as CISSP, CISM, CRISC, CSSLP or CCSP would be advantageous
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Risk Governance Lead (Banking)
Application Risk Governance Lead (Banking)

SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer (DevSecOps)
Application Security Engineer (DevSecOps)

Envoy Search Partners Pte Limited • Singapore

On-site
SGD 90,000 - 150,000
Application Development Security Senior Analyst
Application Development Security Senior Analyst

Success Human Resource Centre Pte Ltd • Singapore

On-site
1-month completion bonus
Application Security Engineer
Application Security Engineer

Liberty in Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer (CBD) (Contract)
Application Security Engineer (CBD) (Contract)

Monetary Authority of Singapore • Singapore

On-site
SGD 75,000 - 105,000
Head of Cybersecurity / Security Engineering Manager
Head of Cybersecurity / Security Engineering Manager

charterhouse pte. ltd. • Singapore

On-site
SGD 200,000 - 280,000
Application Security Engineer
Application Security Engineer

Liberty Specialty Markets • Singapore

On-site
SGD 120,000 - 180,000
Security Risk Assessment (Senior Consultant), Consulting Firm
Security Risk Assessment (Senior Consultant), Consulting Firm

Kerry Consulting • Singapore

On-site
SGD 120,000 - 180,000
Tech Risk or Assurance Analyst
Tech Risk or Assurance Analyst

FLINTEX CONSULTING PTE. LTD. • Singapore

On-site
SGD 100,000 - 180,000
Application & Technology Risk Specialist
Application & Technology Risk Specialist

Tek Systems • Singapore

On-site
SGD 90,000 - 150,000