Job title: Application & Cloud Security Engineer

Job Description

Working Hours: Monday – Thursday (8.30am – 6pm), Friday (8.30am – 5.30pm) (Hybrid working arrangement) 
Working Location: Clarke Quay
Salary Package: Up to SGD 11,000 + AWS 
Employment Type: Full-time Contract (2 years renewable with chances of conversion) 

We are seeking an Application & Cloud Security Engineer to lead the evolution of our security programme from advisory to enforcement. This role requires a technical leader who can seamlessly integrate security controls into our development lifecycle whilst maintaining engineering velocity. The successful candidate will transform existing security guardrails into automated enforcement mechanisms and serve as a trusted partner to development teams in building secure, resilient applications.

Key Responsibilities:

  • Work closely with development teams to integrate security into the SDLC and CI/CD pipelines.
  • Implement, configure, and optimise application security tools including SAST, DAST, and Software Composition Analysis (SCA).
  • Design and automate security guardrails to prevent high-risk vulnerabilities from progressing through the development pipeline.
  • Analyse security findings, reduce false positives, and provide hands-on remediation guidance and secure coding best practices.
  • Develop secure-by-default standards for applications, containers, and Infrastructure as Code (IaC).
  • Drive security awareness initiatives and improve secure software engineering maturity across development teams.

Requirements: 

  • Bachelor's Degree in Computer Science, Information Security, Information Technology, or a related discipline.
  • At least 4 years of experience in Application Security, DevSecOps, Product Security, or Secure Software Engineering.
  • Hands-on experience integrating security tools into CI/CD pipelines using GitHub Actions, GitLab CI, Jenkins, or similar platforms.
  • Strong knowledge of Secure SDLC, application security principles, and common web application vulnerabilities (e.g. OWASP Top 10).
  • Experience with cloud platforms such as AWS or Azure, and Infrastructure as Code tools such as Terraform or CloudFormation.
  • Proficiency in at least one programming language such as Python, Java, Go, or JavaScript/Node.js.
  • Experience with security tools such as Snyk, SonarQube, Checkmarx, Wiz, or OWASP ZAP.

 

By submitting your resume, you consent to the collection, use, and disclosure of your personal information per ScienTec’s Privacy Policy (scientecconsulting.com/privacy-policy).

This authorizes us to:

  • Contact you about potential opportunities.
  • Delete personal data as it is not required at this application stage.
  • All applications will be processed with strict confidence. Only shortlisted candidates will be contacted.

Wong Siew Ting (Maeve) - R25127375

ScienTec Consulting Pte Ltd - 11C5781