IT Security Engineer

KRISE MANNPOWER PTE. LTD.

Singapore

On-site

SGD 90,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KRISE MANNPOWER PTE. LTD. is seeking a seasoned Application Security Remediation Specialist to lead vulnerability triage, code fixes, and secure software design collaboration.

The role requires hands-on experience in securing Java (Spring Boot) apps and modern frontend frameworks, with deep knowledge of OWASP Top 10 and API security. You will interpret results from SAST/DAST/SCA tools, manage remediation tasks in Jira, and coordinate with engineering teams to deliver validated fixes while

Qualifications

  • Minimum 5+ years of software engineering with focus on AppSec remediation.
  • Proficient in Java (Spring Boot) and modern frontend frameworks.
  • Strong knowledge of OWASP Top 10 and API Security Top 10.
  • Experience interpreting outputs from SAST, DAST, and SCA tools.
  • Experience with cloud security and secure API gateways.
  • Familiarity with Jira and Agile processes.
  • Certifications CSSLP, CEH, CASE are a plus.

Responsibilities

  • Triage and remediate vulnerabilities in code and dependencies.
  • Write, test, and deploy secure fixes.
  • Review findings from SAST/DAST/QA and validate fixes.
  • Collaborate with engineers and security stakeholders.
  • Maintain remediation documentation and dashboards.

Skills

Analytical thinking
Documentation skills
Agile methodologies
Root-cause analysis
Security mindset

Education

CSSLP
CEH
CASE

Tools

SonarQube
Checkmarx
Veracode
Snyk
Jira

Job description

Key Responsibilities
1.Vulnerability Triage & Code Remediation
  • Hands-on Fixing: Directly write, test, and deploy secure code to fix vulnerabilities including Injection flaws, XSS, CSRF, SSRF, Broken Authentication, Broken Access Control, Secrets Exposure, and API security issues.
  • Triage & Validation: Analyze findings from SAST/DAST tools and penetration tests, eliminate false positives, and perform root-cause analysis.
  • Dependency Management: Proactively manage and upgrade insecure third-party dependencies and libraries.
2.Engineering & Collaboration
  • Secure Architecture: Design and document remediation design notes and secure coding recommendations for broader development teams.
  • Testing Coordination: Partner with application teams and security stakeholders to coordinate rescans and penetration test retesting to validate fixes.
  • Backlog Management: Maintain precise tracking of engineering tasks and evidence within Jira.
3.Governance & Reporting
  • Participate in weekly remediation review meetings and monthly governance reviews.
  • Contribute to monthly security dashboards and executive governance reports.
  • Document risk acceptance reviews and maintain exception registers when immediate remediation isn't feasible.
Job Requirements
Technical Skills & Experience
  • Experience: Minimum of 5+ years of experience in software engineering with a heavy focus on Application Security (AppSec), or as a dedicated AppSec Remediation Specialist.
  • Core Tech Stack: Strong, production-grade coding experience in Java (Spring Boot) and modern frontend frameworks (Angular and/or React).
  • Security Frameworks: Deep conceptual and practical understanding of the OWASP Top 10 and API Security Top 10 vulnerabilities.
  • Tooling Familiarity: Experience interpreting outputs from SAST, DAST, and Software Composition Analysis (SCA) tools (e.g., SonarQube, Checkmarx, Veracode, Snyk, or similar).
  • Cloud & Architecture: Understanding of cloud security best practices (AWS/Azure/GCP) and secure API gateway architectures.
Soft Skills & Process
  • Strong analytical skills to perform root-cause analysis on complex software vulnerabilities.
  • Excellent documentation skills for creating clear remediation design notes and architectural recommendations.
  • Familiarity with Agile workflows and issue tracking tools like Jira.
  • Bonus: Relevant certifications such as CSSLP (Certified Secure Software Lifecycle Professional), CEH, or CASE.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Full Stack Engineer
Security Full Stack Engineer

R Systems Singapore Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer (DevSecOps)
Application Security Engineer (DevSecOps)

Envoy Search Partners Pte Limited • Singapore

On-site
SGD 90,000 - 150,000
Application Development Security Senior Analyst
Application Development Security Senior Analyst

Success Human Resource Centre Pte Ltd • Singapore

On-site
1-month completion bonus
AppSec Remediation Engineer - Secure Code & Governance
AppSec Remediation Engineer - Secure Code & Governance

KRISE MANNPOWER PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Senior Security Consultant
Senior Security Consultant

RIDIK Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Security Analyst
Security Analyst

RAPSYS TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
Security Analyst
Security Analyst

Tap Growth ai • Singapore

On-site
SGD 60,000 - 90,000
Security Analyst
Security Analyst

RAPSYS TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 70,000 - 90,000
Security Analyst
Security Analyst

Rapsys Technologies Pte Ltd. • Singapore

On-site
SGD 60,000 - 100,000
Application Security Engineer
Application Security Engineer

Millennium Technology Services • Singapore

On-site
SGD 80,000 - 110,000