SL2705 - Security Engineer

FPT Asia Pacific

Singapore

On-site

SGD 150,000 - 230,000

Full time

42 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

FPT Asia Pacific is seeking an experienced Technology Information Security Officer (TISO) to provide security assessment, advisory, and oversight across technology initiatives and business applications in Singapore. You will embed secure-by-design and secure-by-default principles and work with development, architecture, and technology teams to integrate security throughout the SDLC.

You will lead security assessments, risk management, and governance, ensuring alignment with MAS TRM, PDPA, ISO

Qualifications

  • Experience leading security assessments and risk management across technology initiatives.
  • Proven advisory capability to development, architecture, and project teams on secure-by-design/secure-by-default practices.
  • Strong understanding of API security, cloud security architectures, and regulatory requirements.

Responsibilities

  • Conduct comprehensive security assessments to identify risks, gaps, and vulnerabilities.
  • Provide security guidance across the SDLC and development lifecycle.
  • Review and approve security assessments for projects and operations.
  • Promote secure design and secure-by-default across initiatives.
  • Collaborate with risk, audit, architecture, and engineering teams to improve security governance.

Skills

Information Security
Risk Management
Security Assessments
SDLC Security
DevSecOps
Cloud Security (AWS/Azure)
ISO 27001 / NIST
MAS TRM / PDPA knowledge
Communication
Stakeholder Management

Education

Bachelor's degree in Information Security
Advanced certifications (CISSP / CISM / CISA)

Tools

AWS
Azure
Kubernetes
OWASP
SAML/OAuth

Job description

About the Role

We are looking for an experienced Technology Information Security Officer (TISO) to provide security assessment, advisory, and oversight across technology initiatives and business applications.

As a senior individual contributor and Subject Matter Expert (SME), you will ensure that secure-by-design, secure-by-default, and secure operations principles are embedded across the organisation.

You will work closely with development, architecture, project, and technology teams to integrate security throughout the Software Development Life Cycle (SDLC), identify technology risks, recommend appropriate security controls, and ensure alignment with regulatory and industry requirements.

Key Responsibilities
Security Assessments & Risk Management
  • Conduct comprehensive technical security assessments to identify security risks, control gaps, and vulnerabilities.
  • Perform information security risk assessments for business applications throughout the development lifecycle.
  • Assess projects operating under SDLC, Agile, Iterative, DevOps, and DevSecOps methodologies.
  • Identify and communicate significant information security risks and control gaps.
  • Recommend appropriate technical and process controls to mitigate identified risks.
  • Review and approve security assessments for relevant projects and operational requirements.
Application & SDLC Security
  • Serve as a Subject Matter Expert for security throughout the application development lifecycle.
  • Provide security advice to development, engineering, architecture, and project teams.
  • Assess security requirements and controls throughout application design, development, testing, deployment, and operations.
  • Ensure security requirements are incorporated into application and system designs from the beginning.
  • Promote secure-by-design and secure-by-default practices across technology initiatives.
  • Support the implementation of security controls to strengthen application and SDLC security.
Security Architecture & Controls
  • Provide guidance across key security domains including authentication, authorisation, access control, entitlement management, cryptography, encryption, network security, application security, system security, and key management.
  • Assess API security and cloud security architectures across AWS and Azure environments.
  • Review vulnerability management practices against recognised frameworks and industry standards.
  • Provide independent technical security assessments and recommendations on proposed technology solutions.
Security Governance & Continuous Improvement
  • Drive initiatives to strengthen information security processes, policies, standards, and controls.
  • Promote information security best practices across technology teams.
  • Ensure security practices remain aligned with applicable regulatory requirements and industry frameworks.
  • Identify opportunities to improve security governance, assessment processes, and overall technology risk management.
  • Support the continuous improvement of the organisation's information security capabilities.
Stakeholder Management
  • Collaborate with domain architects, project managers, developers, engineers, and technology Subject Matter Experts.
  • Provide clear security guidance and help stakeholders understand their information security responsibilities.
  • Promote awareness of information security policies, standards, controls, and best practices.
  • Work with Risk, Internal Audit, External Audit, and regulatory stakeholders during security reviews and audits.
  • Provide supporting documentation, technical clarification, and security evidence where required.
  • Influence stakeholders and drive appropriate remediation of identified security risks.
Key Responsibilities & Decision-Making
  • Review and approve security assessments for applicable technology projects and operational requirements.
  • Provide independent assessment and advisory on technical and process-related information security matters.
  • Recommend security controls and remediation approaches based on identified technology risks.
  • Escalate significant security risks and control gaps where appropriate.
  • Serve as a senior security reference point for technology and information security matters.
Requirements
  • Minimum 7+ years of progressive experience in Information Security, Technology Risk, IT Audit, Cybersecurity, or related functions.
  • Strong experience within financial services or other highly regulated industries is preferred.
  • Strong knowledge of authentication, authorisation, access controls, entitlement management, cryptography, encryption, network security, application security, system security, and key management.
  • Strong understanding of vulnerability management and application security frameworks, including OWASP and SANS.
  • Hands‑on knowledge of SDLC, Agile, DevOps, and DevSecOps methodologies and their associated security requirements.
  • Strong understanding of Singapore information security, technology risk, and data protection requirements, including MAS TRM and PDPA.
  • Familiarity with industry frameworks and standards such as ISO 27001, NIST CSF, and MITRE ATT&CK.
  • Strong knowledge of API security and cloud security architecture, particularly within AWS and/or Azure environments.
  • Strong analytical and problem‑solving skills with the ability to assess complex security risks and recommend practical solutions.
  • Excellent written and verbal communication skills with the ability to influence, advise, and negotiate with technical and business stakeholders.
  • Ability to independently drive security initiatives and provide guidance or mentorship to other team members.
Education & Certifications
  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related discipline.
  • Advanced qualifications are advantageous.
  • Relevant industry certifications such as CISSP, CISM, CISA, SANS/GIAC, AWS Security, Azure Security, or equivalent recognised cybersecurity certifications are required.
Key Stakeholders
  • You will work closely with internal technology teams, business stakeholders, Risk, Audit, Architecture, Engineering, Development, and other Information Security functions.
  • External stakeholders may include technology vendors, professional service providers, auditors, and other approved third parties.
Team Structure

This is a senior individual contributor / SME role within the Technology Information Security Officer team, reporting directly to the Lead Technology Information Security Officer (TISO).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Officer (ITSO)
IT Security Officer (ITSO)

CAPGEMINI SINGAPORE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer - JN
IT Security Officer - JN

DCI CONSULTANTS PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 170,000
IT Security (ITSO)
IT Security (ITSO)

Tap Growth ai • Singapore

On-site
SGD 60,000 - 90,000
Senior Security Engineer, SDLC & Risk Advisory
Senior Security Engineer, SDLC & Risk Advisory

FPT Asia Pacific • Singapore

On-site
SGD 150,000 - 230,000
IT Security Officer (ITSO)
IT Security Officer (ITSO)

Cognizant • Singapore

On-site
SGD 120,000 - 180,000
Project Cybersecurity Officer
Project Cybersecurity Officer

Hitachi Rail Limited • Singapore

On-site
SGD 120,000 - 150,000
Cybersecurity Consultant, CISOaas
Cybersecurity Consultant, CISOaas

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 110,000
ITSO Officer
ITSO Officer

Rapsys Technologies Pte Ltd. • Singapore

On-site
SGD 70,000 - 100,000
Senior IT Security Officer
Senior IT Security Officer

SCIENTEC CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Lead Engineer/Engineer, Security-By-Design, CISO Office, xCyber
Lead Engineer/Engineer, Security-By-Design, CISO Office, xCyber

HTX (Home Team Science & Technology Agency) • Singapore

On-site
SGD 150,000 - 190,000