Senior Associate, Application Security Engineer, Information Security Services
Singapore · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 5일 전
- Work mode
- In office
- Education
- Bachelor's or Master's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Group Technology at DBS Bank is committed to providing a secure, efficient, and innovative banking infrastructure. Within this division, the Application Security Team plays an essential role in embedding security throughout the software development lifecycle to protect millions of customers and complex financial assets in a digital-first world.
We seek a seasoned Application Security Engineer with expertise in proactive defense and advanced security measures. The role involves working at the forefront of DBS’s digital transformation by integrating security controls into application design, development, and deployment while embracing automation and innovative technologies including Python and Generative AI.
Primary Responsibilities
- Offer guidance on application security tools and establish effective security processes, including static (SAST), dynamic (DAST), interactive (IAST) analysis, software composition analysis (SCA), and secure coding standards.
- Embed security activities at every stage of the Software Development Life Cycle (SDLC), promoting secure design principles, coding standards, and comprehensive security testing.
- Conduct thorough root cause analyses and vulnerability assessments for security findings.
- Develop automation tooling and scripts primarily in Python and Go to optimize vulnerability scanning, validate security controls, and generate security metrics.
- Evaluate and trial Generative AI applications to enhance security testing, code review, threat modeling, and remedial actions.
- Continuously refine secure SDLC frameworks, update security standards, and contribute to policy advancement.
- Lead education initiatives to enhance developer knowledge on application security and secure coding practices.
- Stay informed on emerging security threats, technologies, and methodologies to recommend innovative security enhancements.
Qualifications and Experience
- Possess a Bachelor's or Master's degree in Computer Science, Information Technology, or related discipline.
- At least five years’ experience in cybersecurity engineering, information security, or software development focused on secure coding, ideally within financial services.
- In-depth knowledge of prevalent application security vulnerabilities (e.g., OWASP Top 10), exploitation methods, and mitigation techniques.
- Proficiency with secure coding techniques across various programming languages and frameworks.
- Skilled in using application security testing tools (SAST, DAST, IAST) and manual penetration testing methods.
- Hands-on experience adopting DevSecOps procedures, including CI/CD automation, infrastructure as code (Unix/Linux), and self-remediation techniques.
- Programming expertise in Python and familiarity with languages such as Java and JavaScript/TypeScript.
- Understanding of Generative AI concepts and their relevance in cybersecurity domains like vulnerability identification and threat analysis.
- Strong grasp of secure software development lifecycle models and governance frameworks.
Desired Personal Attributes
- Analytical thinker with a passion for tackling complex security challenges through innovative solutions.
- Excellent collaborator with strong communication skills, able to engage effectively with development, DevOps, and security teams.
- Experienced in designing and operationalizing secure development practices and security automation workflows.
- Self-motivated, proactive in fostering security-first culture within development teams.
- Independent and investigative with capacity to lead security projects with limited supervision.
Additional Information
Location: DBS Asia Hub, Singapore
Employment Type: Full time
Schedule: Regular working hours