DevSecOps Specialist, Technology Information Security Office

OCBC company

Singapore

On-site

SGD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive base salary
Holistic, flexible benefits
Industry-leading learning opportunities

Job summary

OCBC company in Singapore seeks a Cyber Engineering - Risk professional. This role requires a minimum of 5 years in cybersecurity, with strong technical skills in vulnerability scanning tools and DevSecOps processes. You will evaluate risks, collaborate with development teams, and improve security measures. The position offers a competitive salary, flexible benefits, and opportunities for personal and professional growth in a supportive environment.

Qualifications

  • Minimum 5 years of cyber security experience.
  • Sound technical background with various vulnerability scanning tools.
  • Deep knowledge in container security and related vulnerabilities.

Responsibilities

  • Evaluate and analyze threats and security issues from DevSecOps tools.
  • Advise and collaborate with teams on security issues.
  • Provide training on security tools.
  • Implement automated security checks in CI/CD pipelines.

Skills

Cyber security experience
Technical background with vulnerability scanning tools
Secure code reviews
DevSecOps pipeline understanding
Container security knowledge
Infrastructure as Code security
Scripting (Python, Bash, Javascript)
Communication skills

Education

University degree in Computer Science or related field
Certifications in cyber security (GWAPT, OSCP, CISSP)

Tools

SAST
SCA
DAST
IAST
Continuous Integration/Continuous Deployment tools

Job description

You may choose to display a cookie banner on the external site. You must specify the message in the cookie banner and may add a link to a relevant policy. If you are unfamiliar with these requirements, please seek the advice of legal counsel.You are about to enter websites controlled or offered by third parties. OCBC hereby disclaims liability for any information, materials, products or services posted or offered at any of these third party web-sites. By creating a link to these third party web-sites, OCBC does not endorse or recommend any products or services offered or information contained on those web-sites or information fed by these third parties nor is OCBC liable for any failure of products or services offered or advertised at any of these third party web-sites. OCBC Group shall in no event be liable for any damages, loss or expense including without limitation, direct, indirect, special, or consequential damage, or economic loss arising from or in connection with any use of or access to any other website linked to this website, any system, server or connection failure, error, omission, interruption, delay in transmission, or computer virus and any services, products, information, data, software or other material obtained from this website or from any other website linked to this website. Any hyperlinks to any other websites are not an endorsement or verification of such websites and such websites should only be accessed at the user’s own risks. This exclusion clause shall take effect to the fullest extent permitted by law.You further consent to Oversea-Chinese Banking Corporation Limited, its related corporations (collectively, the "OCBC Group"), and their respective business partners and agents (collectively, the “OCBC Representatives”) collecting, using and disclosing your personal data for purposes reasonably required by the OCBC Group and the OCBC Representatives to enable them to process your employment application and assess your suitability for the position which you are applying for. Such purposes are set out in a Data Protection Policy, which is accessible at www.ocbc.com/policies or available on request and which you confirm you have read and understood.# **WHO WE ARE:** Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future. We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.Your Opportunity Starts Here.# # **Who you are*** Minimum 5 years of cyber security experience.* Sound technical background of working with SAST, SCA, DAST, IAST and other vulnerability scanning tools.* Prior experience in performing secure code reviews, web and mobile application penetration tests.* Solid understanding of full DevSecOps pipeline, Agile methodology, cloud security, APIs and microservices.* Deep knowledge of container security(Docker image scanning) and related vulnerabilities.* Knowledge in IaC (Infrastructure as Code) security. Automate security validation in CI/CD pipeline for IaC deployments.* Capable of working with various CI/CD tools.* Analytical thinker with excellent communication skills.* A recognized university degree in Computer Science, Computer/Electrical Engineering, Information Technology or equivalent.* Familiarity of MAS TRMG, PCI-DSS and other regulatory/industries requirements.* Possesses certifications in cyber security field such as GWAPT, OSCP, CISSP etc.* Experience working in DevSecOps for Banks in Singapore will be highly preferred.* Good communication (spoken and written) skills, able to work independently and as a team.**Who we are** Today, we're on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia's leading financial services partner for a sustainable future. We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here. **What we offer** Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Equal opportunity. Fair employment. Selection based on ability and fit with our culture and values. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.# # **What we offer:**Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.**Why Join** Protecting our customers' assets and data is at the heart of everything we do at OCBC. As a Cyber Engineering - Risk professional, you'll play a critical role in safeguarding our systems and networks from cyber threats. You'll be part of a team that's shaping the future of cybersecurity in the financial industry. **How you succeed** To succeed in this role, you'll need to stay one step ahead of emerging threats. You'll work closely with our engineering teams to identify and mitigate risks, and develop strategies to protect our systems and data. You'll need to be proactive, collaborative, and always looking for ways to improve our cybersecurity posture. **What you do*** Evaluate and analyse threat, vulnerability, impact, and risk of security issues discovered from various DevSecOps tools such as Static Application Security Testing (SAST), Software Composition Analysis (SCA), Interactive Application Security Testing (IAST), Dynamic Application Security Testing (DAST)and Container Security platform.* Advise and collaborate with DevOps teams, developers, application, and project teams on the security issues, including explanation of the technical details and how they can remediate the vulnerabilities in their applications.* Develop and design DevSecOps metrics, policies, processes, and procedures.* Provide training to developers and other stakeholders on the usage of the tools.* Assist with implementing and designing automated security checks and additional security tools within the CI/CD pipelines.* Review and triage vulnerabilities discovered by automated security tools.* Proficient understanding of programming languages.* Proficiency in scripting (Python, Bash, Javascript or similar) to support the automation and continuous improvement of processes* Knowledge in build/release tools and methodologies in CI/CD pipelines.* Conduct POCs and work with vendors for DevSecOps tools to achieve security automation and efficiency.* Liaise with external vendors and oversee the resolution of incidents and technical issues related to the security tools.* Effectively communicate and manage expectations of various stakeholders.* Keep abreast of the latest industry trends in security and DevSecOps processes and make continuous recommendations for improvement.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Lead – Cybersecurity & Risk
Vulnerability Management Lead – Cybersecurity & Risk

OCBC company • Singapore

On-site
Cyber Security Architect (Application/Infrastructure/Cloud)
Cyber Security Architect (Application/Infrastructure/Cloud)

OCBC company • Singapore

On-site
SGD 80,000 - 120,000
Competitive base salary
Holistic flexible benefits
Professional development opportunities
Vulnerability Management Specialist
Vulnerability Management Specialist

OCBC company • Singapore

On-site
AVP, Data Engineering Lead (Information Security & Digital Risk Management)
AVP, Data Engineering Lead (Information Security & Digital Risk Management)

OCBC company • Singapore

On-site
SGD 90,000 - 120,000
Competitive base salary
Flexible benefits
Learning and professional development opportunities
Privilege Identity Administrator
Privilege Identity Administrator

OCBC company • Singapore

On-site
SGD 75,000 - 95,000
Competitive base salary
Flexible benefits
Learning and professional development opportunities
Senior SOC Engineer (GTS - Command Centre)
Senior SOC Engineer (GTS - Command Centre)

OCBC company • Singapore

On-site
SGD 80,000 - 120,000
Competitive base salary
Holistic flexible benefits
Professional development opportunities
Cyber Threat Analyst
Cyber Threat Analyst

OCBC company • Singapore

On-site
SGD 60,000 - 80,000
Competitive base salary
Holistic, flexible benefits
Industry-leading learning and professional development opportunities
SOC Tier 3 Analyst (GTS - Command Centre)
SOC Tier 3 Analyst (GTS - Command Centre)

OCBC company • Singapore

On-site
SGD 80,000 - 120,000
Competitive base salary
Flexible benefits
Professional development opportunities
AVP, Security Lead, Property Management
AVP, Security Lead, Property Management

OCBC company • Singapore

On-site
SGD 70,000 - 100,000
Technology Risk Manager, Risk & Prevention, Group Operations & Technology (AVP/VP)
Technology Risk Manager, Risk & Prevention, Group Operations & Technology (AVP/VP)

OCBC company • Singapore

On-site
SGD 90,000 - 120,000
Holistic flexible benefits
Community initiatives
Professional development opportunities