- Location
- Singapore
- Type
- Full-time
- Department
- Administration
- Experience
- 5+ years
- Closing date
- Today
- Source
- CareersPage
Description
Key Responsibilities:
- Review system architecture, data flows, interfaces, APIs, internet-facing entry points and security controls to identify potential security risks.
- Conduct cybersecurity risk assessments for new and existing IT systems, applications, infrastructure and cloud services.
- Preferably possess experience in threat modelling and develop threat profiles for application projects to identify, quantify and remediate application security risks.
- Review remediation plans and supporting evidence to verify that security risks have been adequately addressed.
- Track and address security vulnerabilities with timely remediation and patching and closure in accordance with established requirements.
- Monitor and investigate cybersecurity alerts and incidents, including malware, phishing, account compromise, data breaches, unauthorized access, and cloud security incidents.
- Perform cybersecurity incident response and management, including incident triage, investigation, containment, remediation, recovery, and post-incident review.
- Conduct security awareness training sessions to promote security awareness and good cybersecurity practices.
Requirements:
- At least 5 years combined work experience in software development, application security and cloud computing (e.g. AWS).
- Good understanding of mobile and web application architectures, including APIs and related technologies and protocols such as REST, SOAP and SSL/TLS.
- Strong knowledge of application security principles and industry best practices, including the OWASP Top 10 and OWASP Application Security Verification Standard (ASVS).
- Familiar with Agile development, CI/CD and DevSecOps practices, including tools such as GitLab, GitHub and Ansible, and the integration of automated security testing into CI/CD pipelines.
- Experience on using SAST code scanning tools such as Fortify-on-Demand, Sonarqube, etc.
- Good verbal/written communications, collaboration skills and experience interacting with various stakeholders.
- Strong analytical, problem-solving and troubleshooting skills, ability to work independently.
- Degree in a relevant discipline, or an equivalent qualification.
- Relevant professional certifications such as CISSP, OSCP, CCSP, CRISC, AWS security certification or equivalent are preferred.
- Experience in working with Government Commercial Cloud (GCC) preferred.