Lead Security Engineer

THOUGHTWORKS PTE. LTD.

Singapore

On-site

SGD 150,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Thoughtworks Singapore is seeking a Lead Security Engineer to guide security strategy across client software deliveries, embedding security into SDLC, cloud platforms, and IaC. You will mentor peers, drive risk-informed decisions, and champion zero-trust and DevSecOps practices.

Strong communication with stakeholders is essential in a fast-paced tech consultancy. You will lead security design reviews, threat modeling sessions, and governance across AWS, Azure, or GCP while aligning with

Qualifications

  • 7+ years of experience in information security engineering, application security, or cloud security.
  • Deep expertise in secure software development, threat modeling (STRIDE, PASTA), and OWASP Top 10 / SANS Top 25.
  • Hands-on experience with security automation tools and CI/CD integration.
  • Strong capabilities in securing cloud infrastructure (AWS, Azure, GCP), containers and IaC.
  • Foundation in cryptography, IAM, zero-trust, network and API security.
  • Knowledge of regulatory frameworks (Singapore IM8 / IM8+, SOC 2, ISO 27001, PCI-DSS, GDPR).
  • Natural mentor with strong leadership and coaching abilities.
  • Excellent communication and stakeholder management; translating risk into action.
  • Comfort with ambiguity and balancing security with delivery velocity.
  • Open mindset toward AI and AI-assisted security governance.

Responsibilities

  • Lead the design and implementation of enterprise security architectures, zero-trust patterns, and DevSecOps across software delivery teams.
  • Primary technical advisor to client stakeholders, aligning security with risk tolerances and business goals.
  • Champion shifting security left by integrating SAST, DAST, SCA, and secrets management into CI/CD pipelines.
  • Conduct threat modeling, risk assessments, and architectural reviews to identify and mitigate vulnerabilities.
  • Oversee cloud platform security governance, IAM, container security, and IaC compliance across AWS, Azure, or GCP.
  • Guide vulnerability management, incident response workflows, and audit readiness for regulatory alignment.
  • Partner with cross-functional teams to balance security controls with delivery velocity.
  • Mentor engineers and foster an inclusive security-focused culture.
  • Apply Thoughtworks technology radar insights to client security challenges.
  • Contribute to Thoughtworks security community of practice and pre-sales pursuits.

Skills

Security architecture
Threat modeling
Mentoring
Communication
Cloud security

Tools

SAST tooling
DAST tooling
IAST tooling
SCA tooling
Secrets scanning
Kubernetes
Docker
IaC tooling (Terraform)

Job description

Lead Engineers at Thoughtworks act as trusted technical leaders and security advisors who align enterprise risk and executive strategy with modern software delivery, ensuring security measures enhance organizational objectives.

In this role, you bring a strategic and proactive mindset to client engagements, guiding delivery teams in embedding security directly into the software development lifecycle, platform architecture, and cloud environments.

You balance high-level security architecture with hands‑on engineering, conducting threat modeling, establishing DevSecOps practices, and following a pragmatic and robust approach to risk management.

As a technical leader, you guide and coach cross‑functional teams, cultivate security awareness across accounts, and navigate complex stakeholder environments to build resilient, trustworthy software solutions.

Job Responsibilities
  • You will lead the design and implementation of enterprise security architectures, zero‑trust patterns, and DevSecOps practices and controls across software delivery teams.
  • You will act as a primary technical advisor to client stakeholders and engineering leads, aligning information security strategies with enterprise risk tolerances and business goals.
  • You will champion shifting security left in the software development lifecycle by integrating automated SAST, DAST, SCA, and secrets management into CI/CD pipelines.
  • You will conduct threat modeling sessions, security risk assessments, and architectural reviews to identify vulnerabilities and design pragmatic mitigations alongside delivery teams.
  • You will oversee cloud platform security governance, Identity and Access Management (IAM), container security (Kubernetes, Docker), and Infrastructure as Code (IaC) compliance across AWS, Azure, or GCP.
  • You will guide vulnerability management, security incident response workflows, and audit readiness to ensure alignment with industry regulations and public sector standards (e.g., Singapore IM8 / IM8+, SOC 2, ISO 27001, NIST).
  • You will partner closely with cross‑functional teams—including software developers, infrastructure engineers, quality analysts, and product managers—to balance security controls with delivery velocity.
  • You will cultivate Thoughtworker growth and development by mentoring engineers, providing ongoing supportive feedback, and fostering an inclusive team culture.
  • You will apply the latest technology thinking and security insights from our Technology Radar to solve complex client security challenges.
  • You will contribute to Thoughtworks’ security community of practice, supporting pre‑sales pursuits, capability development, and technical thought leadership.
Professional Skills
  • You bring 7+ years of experience in information security engineering, application security, or cloud security within fast‑paced software delivery environments.
  • You possess deep expertise in secure software development practices, threat modeling methodologies (e.g., STRIDE, PASTA), and security standards such as OWASP Top 10 and SANS Top 25.
  • You have hands‑on experience with security automation tools (SAST, DAST, IAST, SCA, secrets scanners) and integrating them into continuous integration and continuous delivery pipelines.
  • You bring strong technical capabilities in securing cloud infrastructure (AWS, Azure, GCP), container platforms (Kubernetes, Docker), and Infrastructure as Code (IaC) environments.
  • You have a solid foundation in cryptography, Identity and Access Management (IAM), zero‑trust architecture, network security, and API security.
  • You possess practical knowledge of regulatory frameworks and compliance standards, such as Singapore Public Sector IM8 / IM8+, SOC 2, ISO 27001 (ISMS), PCI‑DSS, or GDPR.
  • You are a natural mentor and technical leader, skilled at inspiring cross‑functional teams, driving security awareness, and coaching peers.
  • You demonstrate excellent communication and stakeholder management skills, with a proven ability to translate complex security risks into actionable business decisions for leadership.
  • You are resilient in ambiguous situations, capable of evaluating trade‑offs under constraints and solving security challenges from technical and business perspectives.
  • You bring an open and thoughtful mindset toward AI, exploring AI‑assisted security automation, threat detection, and responsible AI governance practices.
Learning and Development

There is no one‑size‑fits‑all career path at Thoughtworks: However you want to develop your career is entirely up to you. But we also balance autonomy with the strength of our cultivation culture. This means your career is supported by interactive tools, numerous development programs and teammates who want to help you grow. We see value in helping each other be our best and that extends to empowering our employees in their career journeys.

About Thoughtworks

Thoughtworks is a dynamic and inclusive community of bright and supportive colleagues who are revolutionizing tech. As a leading technology consultancy, we’re pushing boundaries through our purposeful and impactful work. For 30+ years, we’ve delivered extraordinary impact together with our clients by helping them solve complex business problems with technology as the differentiator. Bring your brilliant expertise and commitment for continuous learning to Thoughtworks. Together, let’s be extraordinary.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Application & Cloud Infrastructure Security Engineer
Lead Application & Cloud Infrastructure Security Engineer

Thoughtworks • Singapore

On-site
SGD 180,000 - 240,000
Lead Security Engineer: Enterprise DevSecOps Architect
Lead Security Engineer: Enterprise DevSecOps Architect

THOUGHTWORKS PTE. LTD. • Singapore

On-site
SGD 150,000 - 190,000
Lead Developer(NextJS/NodeJS)
Lead Developer(NextJS/NodeJS)

Thoughtworks • Singapore

On-site
SGD 180,000 - 240,000
Senior Developer (Java/NodeJS+React/TS)
Senior Developer (Java/NodeJS+React/TS)

Referrals Only • Singapore

On-site
SGD 70,000 - 90,000
Senior InfoSec Architect & DevSecOps Leader
Senior InfoSec Architect & DevSecOps Leader

Thoughtworks • Singapore

On-site
SGD 180,000 - 240,000
Lead Technology Advisory Analyst
Lead Technology Advisory Analyst

Thoughtworks • Singapore

On-site
SGD 90,000 - 130,000
Client Partner
Client Partner

Visa Hunt • Singapore

On-site
SGD 250,000 - 320,000
Senior Software Engineer - Client-Facing Tech Leader
Senior Software Engineer - Client-Facing Tech Leader

Referrals Only • Singapore

On-site
SGD 70,000 - 100,000
Career development programs
Supportive team culture
Continuous learning opportunities
Principal/Lead Cybersecurity Specialist
Principal/Lead Cybersecurity Specialist

CAPGEMINI SINGAPORE PTE. LTD. • Singapore

Hybrid
SGD 180,000 - 260,000
Lead Cybersecurity Specialist
Lead Cybersecurity Specialist

CAPGEMINI SINGAPORE PTE. LTD. • Singapore

On-site
SGD 180,000 - 280,000
Competitive remuneration
Comprehensive benefits package
Flexible working arrangements