jobs in R Systems

全职 Full Stack Engineer 工作, 薪水, R Systems Federal Territory 公司招聘中 - Ricebowl

Full Stack Engineer

R Systems

Undisclosed

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

Job Title: Security Full Stack Engineer (Application Security)

Location: Singapore

Experience: 5+ Years


Role Overview

We are hiring a Security Full Stack Engineer to join a high-impact engineering team focused on securing critical applications. This is a hands-on role where you will go beyond identifying vulnerabilities and take full ownership of fixing them within the codebase.

You will work closely with development and security teams to analyze, triage, and remediate vulnerabilities identified through penetration testing, SAST, DAST, and SCA tools. The role requires strong engineering capabilities combined with deep application security knowledge across modern backend and frontend technologies.


Key Responsibilities

1. Vulnerability Triage & Remediation

  • Analyze and validate vulnerabilities identified through SAST, DAST, and penetration testing
  • Perform root cause analysis and eliminate false positives
  • Write, test, and deploy secure code to remediate vulnerabilities including:
  • Injection flaws (SQL/Command)
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Server-Side Request Forgery (SSRF)
  • Broken Authentication & Access Control
  • API security issues and secrets exposure
  • Manage and upgrade vulnerable third-party libraries and dependencies

2. Engineering & Collaboration

  • Design and document secure remediation solutions and coding practices
  • Work closely with development teams to implement and validate fixes
  • Coordinate with security teams for re-scans and penetration test retesting
  • Track remediation progress and maintain evidence in Jira

3. Governance & Reporting

  • Participate in remediation review meetings and governance discussions
  • Support preparation of security dashboards and reports
  • Maintain documentation for risk acceptance and exception handling

Key Requirements

Technical Skills

  • 5+ years of experience in software engineering with exposure to Application Security
  • Strong hands-on development experience in:
  • Java (Spring Boot)
  • Angular and/or React
  • Solid understanding of OWASP Top 10 and API Security Top 10
  • Experience working with SAST, DAST, and SCA tools (e.g., SonarQube, Checkmarx, Veracode, Snyk)
  • Knowledge of secure coding practices and vulnerability remediation techniques
  • Familiarity with cloud environments (AWS, Azure, or GCP) and secure architecture principles

Soft Skills

  • Strong analytical and problem-solving skills with attention to detail
  • Ability to perform deep root-cause analysis on complex issues
  • Excellent documentation and communication skills
  • Experience working in Agile environments with tools like Jira

Nice to Have

  • Relevant certifications such as CSSLP, CEH, or CASE
  • Experience with API gateways and microservices security

Why Join Us

  • Opportunity to work on high-impact, security-critical applications
  • Hands-on role with real engineering ownership
  • Collaborative environment bridging development and security


If you are passionate about secure coding and want to play a key role in strengthening application security from within, we’d love to hear from you.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多