Application Security Risk Manager

Kerry Consulting

Singapore

On-site

SGD 120,000 - 190,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kerry Consulting is seeking an experienced Application Security Risk Manager to provide risk oversight across application security and technology controls. You will partner with Technology, Cybersecurity and Engineering teams to identify risks and ensure secure design, development, and operation of applications.

Responsibilities include risk assessments for new apps, reviewing security controls across the SDLC, evaluating vulnerabilities and access management, and overseeing incidents and

Qualifications

  • 8-15 years of experience across application security, cybersecurity, technology risk, security architecture or technology assurance.
  • Strong understanding of application security, SDLC and secure software development.
  • Familiarity with SAST, DAST, penetration testing and frameworks such as OWASP, NIST and ISO 27001.
  • Knowledge of DevSecOps, CI/CD, APIs, IAM, vulnerability management and cloud security.
  • Financial services and regulatory experience would be advantageous.

Responsibilities

  • Provide risk oversight and challenge across application security and software development activities.
  • Conduct security risk assessments for new applications, major technology changes and critical systems.
  • Assess security controls across the SDLC, including secure design, development, testing, deployment and production.
  • Review risks relating to application vulnerabilities, APIs, integrations, authentication, access management and data protection.
  • Assess DevSecOps and CI/CD controls, including SAST, DAST, penetration testing and vulnerability management.
  • Review security exceptions, risk assessments and remediation plans and provide independent challenge where required.
  • Assess application security across on-premise, cloud and hybrid environments.
  • Conduct thematic reviews to identify systemic risks and control weaknesses.
  • Oversee significant application security incidents and remediation.
  • Develop risk metrics and contribute to application security policies, standards and control frameworks.
  • Monitor emerging application security threats and advise stakeholders on relevant risks.

Skills

Application security
Cybersecurity
Technology risk
Security architecture
SDLC security
DevSecOps
CI/CD
APIs
IAM
Vulnerability management
Communication
Stakeholder management
Analytical skills
Security certifications awareness

Tools

SAST tools
DAST tools
Penetration testing
OWASP
NIST
ISO 27001

Job description

We are seeking an experienced Application Security Risk Manager to provide risk oversight and challenge across application security and technology controls.

The role will partner with Technology, Cybersecurity and Engineering teams to identify security risks and ensure applications are designed, developed and operated securely.

Key Responsibilities:
  • Provide risk oversight and challenge across application security and software development activities.
  • Conduct security risk assessments for new applications, major technology changes and critical systems.
  • Assess security controls across the SDLC, including secure design, development, testing, deployment and production.
  • Review risks relating to application vulnerabilities, APIs, integrations, authentication, access management and data protection.
  • Assess DevSecOps and CI/CD controls, including SAST, DAST, penetration testing and vulnerability management.
  • Review security exceptions, risk assessments and remediation plans and provide independent challenge where required.
  • Assess application security across on-premise, cloud and hybrid environments.
  • Conduct thematic reviews to identify systemic risks and control weaknesses.
  • Oversee significant application security incidents and remediation.
  • Develop risk metrics and contribute to application security policies, standards and control frameworks.
  • Monitor emerging application security threats and advise stakeholders on relevant risks.
Requirements:
  • 8-15 years of experience across application security, cybersecurity, technology risk, security architecture or technology assurance.
  • Strong understanding of application security, SDLC and secure software development.
  • Knowledge of DevSecOps, CI/CD, APIs, IAM, vulnerability management and cloud security.
  • Experience assessing application security controls and technology risks.
  • Familiarity with SAST, DAST, penetration testing and frameworks such as OWASP, NIST and ISO 27001.
  • Financial services and regulatory experience would be advantageous.
  • Strong analytical, communication and stakeholder management skills.
  • Certifications such as CISSP, CISM, CRISC, CSSLP or CCSP would be advantageous
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

TECHCOM SOLUTIONS (SINGAPORE) PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer (DevSecOps)
Application Security Engineer (DevSecOps)

Envoy Search Partners Pte Limited • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity and Technology Risk Manager, Global MNC
Cybersecurity and Technology Risk Manager, Global MNC

Kerry Consulting • Singapore

On-site
SGD 150,000 - 220,000
Application Security Engineer
Application Security Engineer

Liberty in Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
Senior Security Analyst (Governance, Risk and Compliance)
Senior Security Analyst (Governance, Risk and Compliance)

ENERGY MARKET COMPANY PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Liberty Specialty Markets • Singapore

On-site
SGD 120,000 - 180,000
Application Risk Governance Lead (Banking)
Application Risk Governance Lead (Banking)

SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 180,000
IT Security Consultant
IT Security Consultant

K2 PARTNERING SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Application Security Consultant
Application Security Consultant

IBM • Singapore

On-site
SGD 90,000 - 140,000
Tech Risk or Assurance Analyst
Tech Risk or Assurance Analyst

FLINTEX CONSULTING PTE. LTD. • Singapore

On-site
SGD 100,000 - 180,000