Security Full Stack Engineer

R Systems Singapore Pte Ltd

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

R Systems Singapore Pte Ltd is seeking a Security (Full Stack Engineer) to join a dedicated engineering team focused on hardening Singapore's critical applications. You will be hands-on, fix vulnerabilities, and remediate issues surfaced by SAST, DAST, and penetration testing across Java, Angular, and React apps.

The role requires strong AppSec experience, collaboration with development teams, and a proactive approach to securing APIs, authentication, and data protection in cloud environments.

Qualifications

  • Minimum 5+ years in software engineering focused on AppSec.
  • Strong coding in Java (Spring Boot) and frontend (Angular/React).
  • Deep understanding of OWASP Top 10 and API security.

Responsibilities

  • Vulnerability triage and code remediation across the stack.
  • Collaborate with teams to coordinate rescans and retesting.
  • Maintain Jira backlog with remediation tasks and evidence.
  • Design secure architectures and document remediation notes.
  • Participate in governance meetings and dashboards.

Skills

Java
Angular
React
AppSec
SAST/DAST
SCA tools
Jira
OWASP Top 10
Cloud security

Tools

SonarQube
Checkmarx
Veracode
Snyk

Job description

Role Overview

We are seeking a highly skilled Security (Full Stack Engineer) to join a dedicated engineering team focused on securing Singapore's critical applications. In this role, you will not just find vulnerabilities—you will be the hands-on engineering resource responsible for fixing them. You will analyze, triage, and directly remediate security flaws identified through Penetration Testing, Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST). This role bridges the gap between pure security auditing and core software engineering, ensuring our modern Java, Angular, and React applications are robust against evolving threats.

Key Responsibilities
  1. 1. Vulnerability Triage & Code Remediation
    • Hands-on Fixing: Directly write, test, and deploy secure code to fix vulnerabilities including Injection flaws, XSS, CSRF, SSRF, Broken Authentication, Broken Access Control, Secrets Exposure, and API security issues.
    • Triage & Validation: Analyze findings from SAST/DAST tools and penetration tests, eliminate false positives, and perform root-cause analysis.
    • Dependency Management: Proactively manage and upgrade insecure third-party dependencies and libraries.
  2. 2. Engineering & Collaboration
    • Secure Architecture: Design and document remediation design notes and secure coding recommendations for broader development teams.
    • Testing Coordination: Partner with application teams and security stakeholders to coordinate rescans and penetration test retesting to validate fixes.
    • Backlog Management: Maintain precise tracking of engineering tasks and evidence within Jira.
  3. 3. Governance & Reporting
    • Participate in weekly remediation review meetings and monthly governance reviews.
    • Contribute to monthly security dashboards and executive governance reports.
    • Document risk acceptance reviews and maintain exception registers when immediate remediation isn't feasible.
Job Requirements
Technical Skills & Experience
  • Experience: Minimum of 5+ years of experience in software engineering with a heavy focus on Application Security (AppSec), or as a dedicated AppSec Remediation Specialist.
  • Core Tech Stack: Strong, production-grade coding experience in Java (Spring Boot) and modern frontend frameworks (Angular and/or React).
  • Security Frameworks: Deep conceptual and practical understanding of the OWASP Top 10 and API Security Top 10 vulnerabilities.
  • Tooling Familiarity: Experience interpreting outputs from SAST, DAST, and Software Composition Analysis (SCA) tools (e.g., SonarQube, Checkmarx, Veracode, Snyk, or similar).
  • Cloud & Architecture: Understanding of cloud security best practices (AWS/Azure/GCP) and secure API gateway architectures.
Soft Skills & Process
  • Strong analytical skills to perform root-cause analysis on complex software vulnerabilities.
  • Excellent documentation skills for creating clear remediation design notes and architectural recommendations.
  • Familiarity with Agile workflows and issue tracking tools like Jira.
  • Bonus: Relevant certifications such as CSSLP (Certified Secure Software Lifecycle Professional), CEH, or CASE.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer
IT Security Engineer

KRISE MANNPOWER PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Security-Focused Full-Stack Engineer
Security-Focused Full-Stack Engineer

R Systems Singapore Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Application Development Security Senior Analyst
Application Development Security Senior Analyst

Success Human Resource Centre Pte Ltd • Singapore

On-site
1-month completion bonus
Security Analyst
Security Analyst

RAPSYS TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 70,000 - 90,000
Application Security Engineer
Application Security Engineer

Liberty in Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Liberty Specialty Markets • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Engineer | Hybrid (Singapore)
Cybersecurity Engineer | Hybrid (Singapore)

MRL Consulting Group Ltd. • Singapore

Hybrid
SGD 70,000 - 90,000
Security Engineer
Security Engineer

CodSec • Singapore

On-site
SGD 90,000 - 150,000
Information Technology Security Engineer
Information Technology Security Engineer

Newtone consulting • Singapore

On-site
SGD 60,000 - 110,000
Cybersecurity Engineer (Web Security) - Information Security (2027 Graduate)
Cybersecurity Engineer (Web Security) - Information Security (2027 Graduate)

United States Digital Space LLC • Singapore

On-site
SGD 40,000 - 70,000