Security Engineer

SGB

Singapore

On-site

SGD 90,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SGB is seeking a Product Security professional to lead threat-modeling discussions with product managers and architects, and to design robust access models for users and services. You will validate security controls across cloud environments and integrate secure SDLC practices with automated security testing tools.

The role requires hands-on experience with WAF, Tenable, Burp Suite, and CodeQL, plus strong communication skills in English.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 3+ years in Product Security, AppSec, or DevSecOps roles.
  • Solid foundation in security, SDLC, and DevSecOps framework, proficiency in Java.
  • Experience in Threat Modeling (STRIDE/PASTA) and architectural risk assessments.
  • Hands-on experience with security tools such as WAF, firewall, Tenable, Burp Suite, CodeQL.
  • Strong written and spoken English with collaboration skills.

Responsibilities

  • Lead collaborative threat-modeling sessions with product managers and architects during design phases.
  • Design and implement least-privilege access models for humans and services.
  • Design, analyse and validate security controls across cloud environments.
  • Develop and run secure SDLC practices; integrate automated SAST, DAST, SCA.
  • Run vulnerability management; prioritise and coordinate fixes.
  • Conduct internal information security risk assessments and manage vendor risk evaluations.
  • Develop security standards and best practices.
  • Participate and lead security investigations and incident response.
  • Conduct OWASP Top 10 and secure coding pattern sharing.

Skills

Threat modeling
DevSecOps
SDLC security
Java
Communication

Education

Bachelor's degree in Computer Science/Information Security

Tools

WAF
Firewall
Tenable
Burp Suite
CodeQL

Job description

  • Lead collaborative threat-modeling sessions with product managers and architects during the design phase of new features.
  • Design and implement robust “least-provilege” access models for both human user and service-to-service communications.
  • Design, analyse and validate security controls across cloud infrastructure environments.
  • Develop & run secure SDLC practices, integrate automated SAST, DAST, SCA.
  • Run vulnerability management program, prioritise and coordinate fixes.
  • Conduct internal information security risk assessments and manage security risk evaluations of external vendors and partners.
  • Develop security standards and best practices as needed.
  • Participate and lead security investigation and response to incidents as needed.
  • Conduct periodic sharing sessions, i.e. the OWASP Top 10 and secure coding patterns.

Qualifications required

  • Bachelor's degree or above in Computer Science, Information Security, or a related field.
  • 3+ years in Product Security, AppSec, or DevSecOps roles.
  • Solid foundation in security, SDLC, and DevSecOps framework, proficiency in Java.
  • Experience in Threat Modeling (STRIDE/PASTA) and performing architectural risk assessments.
  • Hands on experience on security tools such as WAF, firewall, and Tenable, Burp Suite, CodeQL.
  • Strong sense of responsibility, excellent communication and team collaboration skills, with the ability to analyze and solve problems independently.
  • Proficient in written and spoken English.

Preferred Qualifications

  • Possession of industry-recognized security certifications (e.g., CISSP, OSCP) is preferred.
  • Deep knowledge on compliance framework, i.e. ISO 27001, SOC2.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

NETS • Singapore

On-site
SGD 180,000 - 240,000
IT Security Engineer
IT Security Engineer

KRISE MANNPOWER PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Application Security Engineer (DevSecOps)
Application Security Engineer (DevSecOps)

Envoy Search Partners Pte Limited • Singapore

On-site
SGD 90,000 - 150,000
Senior Security Engineer
Senior Security Engineer

kwe-apll technology services pte. ltd. • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer - Threat Modeling & Secure SDLC Lead
Security Engineer - Threat Modeling & Secure SDLC Lead

SGB • Singapore

On-site
SGD 90,000 - 140,000
Security Engineer
Security Engineer

SISTIC.com Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Security Engineer - Cyber Threat Management
Security Engineer - Cyber Threat Management

KWE-APLL Technology Services Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Security Solutions Product Manager
Security Solutions Product Manager

VY SYSTEMS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior Engineer, Security Operations
Senior Engineer, Security Operations

kwe-apll technology services pte ltd • Singapore

On-site
SGD 120,000 - 180,000
Staff Product Security Engineer
Staff Product Security Engineer

Airwallex • Singapore

On-site
SGD 120,000 - 180,000