Job Title: Engineer (Application Security)
Location: Kent Ridge Campus
What You Do
As an Application Security Engineer, you will support NUS IT’s efforts to build secure, reliable, and user‑centric digital services for the University community. This role strengthens application security across the software delivery lifecycle, focusing on mobile security, DevSecOps, and secure platform engineering. You will develop the CyberN’US mini‑app within the uNivUS superapp, embed secure coding practices, automate security controls, and harden platforms. You will collaborate with cross‑functional teams to ensure security is built into applications and platforms from design through deployment and operations.
Mobile Application Development and Enhancement
- Develop, test, maintain, and enhance the CyberN’US mini‑app as part of the uNivUS superapp.
- Support secure, intuitive, and reliable mobile application features for iOS and Android.
- Write clean, maintainable, and efficient code following development standards and secure coding practices.
- Participate in code reviews, testing, debugging, and issue resolution to ensure quality, performance, and security.
- Collaborate with UX/UI designers, backend developers, product owners, and stakeholders for a seamless user experience.
Application Security and Secure Software Delivery
- Implement secure software development lifecycle practices across application development activities.
- Embed security controls and best practices into CI/CD pipelines for continuous automated security testing.
- Integrate and maintain application security tools (code scanning, dependency review, secret detection).
- Identify, assess, and support remediation of application security findings with development and platform teams.
- Promote secure coding awareness and improve security hygiene in daily workflows.
Secure Platform Engineering and Container Security
- Monitor and harden containerised application environments and orchestration platforms such as Kubernetes.
- Implement security baselines, configuration standards, access controls, and platform protection measures.
- Review container and platform configurations to identify gaps, misconfigurations, or weaknesses.
- Support vulnerability management and remediation for container images and related components.
- Contribute to secure deployment practices for modern application platforms and cloud‑native environments.
Security Monitoring, Logging, and Operational Support
- Design and maintain security logging, monitoring, and alerting use cases for the CI/CD platform and application environments.
- Utilise SIEM and related tools to improve visibility into security events and platform risks.
- Maintain technical documentation, runbooks, and operational procedures for application security controls.
- Provide regular updates on progress, issues, risks, and improvement opportunities.
Collaboration and Continuous Improvement
- Collaborate effectively with software engineers, infrastructure teams, product managers, and security stakeholders.
- Participate in project planning, sprint activities, technical discussions, and team meetings.
- Document development processes, configurations, coding standards, and project information clearly.
- Stay current with developments in mobile security, application security, DevSecOps, and secure platform engineering.
Key Qualifications
Educational Qualifications
- Bachelor’s degree in Computer Science, Information Security, Information Systems, Computer Engineering, or a related discipline.
Years of Relevant Experience
- Fresh graduate with relevant internship, academic project, or hands‑on experience in mobile application development, secure software development, or related areas.
Technical Skills
- Strong foundation in mobile application development through internship, academic, or personal projects.
- Familiarity with developing or supporting mobile applications for iOS and/or Android platforms.
- Awareness of secure coding practices and common application security principles.
- Familiarity with CI/CD concepts and software delivery workflows.
- Basic understanding of application security, with interest in developing skills in AppSec, DevSecOps, and secure platform engineering.
- Exposure to version control, testing, debugging, and technical documentation practices.
- Willingness to learn container, Kubernetes, and platform security concepts.
Soft Skills
- Ability to work collaboratively in cross‑functional teams while also being independent and self‑driven.
- Good problem‑solving and analytical skills.
- Clear communication skills, both verbal and written.
- Organised, detail‑oriented, and disciplined in documentation.
- Positive learning mindset with strong interest in growing in application security as a long‑term career path.
Nice to Have
Educational Qualifications
- Relevant coursework, capstone projects, or specialised training in cybersecurity, application security, mobile development, DevSecOps, or cloud/platform security.
Technical Skills
- Familiarity with mobile app security best practices.
- Exposure to CI/CD security tooling (static code scanning, software composition analysis, secret scanning).
- Basic exposure to container technologies such as Docker and Kubernetes.
- Familiarity with logging, monitoring, or SIEM platforms.
- Exposure to scripting or automation using languages such as Python, Bash, or similar.
Soft Skills
- Proactive attitude and willingness to take ownership of assigned tasks.
- Ability to balance usability, delivery needs, and security considerations.
- Curiosity and enthusiasm for learning new technologies and security practices.
Benefits
- Family Care Leave of 2 days
- Additional Childcare Leave beyond statutory benefits
- 2 Wellbeing days
- Up to 3 sick days with no MC
- Progressive annual leave starting at 21 days (including National Service!)
- Flexible medical coverage up to $10,000 for you and your dependents