jobs in Shopee

全职 Security Engineer (AppSec - Secure SLDC) - Information Security 工作, 薪水, Shopee 公司招聘中 - Ricebowl

Security Engineer (AppSec - Secure SLDC) - Information Security

Undisclosed

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

Department Engineering and Technology
LevelExperienced (Individual Contributor)
LocationSingapore

The Engineering and Technology team is at the core of the Shopee platform development. The team is made up of a group of passionate engineers from all over the world, striving to build the best systems with the most suitable technologies. Our engineers do not merely solve problems at hand; We build foundations for a long-lasting future. We don't limit ourselves on what we can or can't do; we take matters into our own hands even if it means drilling down to the bottom layer of the computing platform. Shopee's hyper-growing business scale has transformed most "innocent" problems into huge technical challenges, and there is no better place to experience it first-hand if you love technologies as much as we do.

About the Team:
The Engineering and Technology team is at the core of Shopee’s platform development, building scalable and reliable systems to support a rapidly growing business. At Shopee’s scale, even seemingly simple problems can become complex engineering challenges, requiring strong technical foundations and long-term solutions.

Our security engineering team builds internal platforms that help developers deliver secure software efficiently. We develop Secure SDLC capabilities including SAST, SCA, software supply-chain security, and DevSecOps automation. We also apply AI and Agent technologies to code review, vulnerability analysis, false-positive reduction, and security automation, embedding security directly into CI/CD pipelines and developer workflows.
Job Description:
We are looking for a Security Engineer with good security fundamentals and software development capabilities to contribute to the development of our internal Secure SDLC tools and automation capabilities.
You will work on code security, software supply-chain security, vulnerability analysis, and AI-assisted security engineering. You will also collaborate with the team to integrate security capabilities into real-world software development workflows.

  • Participate in the design, development, and continuous improvement of internal security tools and platforms, including but not limited to:
    • AI-assisted code review and vulnerability analysis;
    • Static Application Security Testing (SAST);
    • Software Composition Analysis (SCA) and software supply-chain security;
    • Security automation and other Secure SDLC tools.
  • Develop and improve security detection rules, analysis logic, and automated workflows based on security requirements.
  • Participate in secure code review, vulnerability analysis, and false-positive investigation to improve detection accuracy and vulnerability coverage.
  • Use AI-assisted development, code-analysis, and security-research tools to improve engineering and security-analysis efficiency.
  • Contribute to LLM- or Agent-based security tools involving repository search, tool use, task orchestration, and result validation.
  • Integrate security tools with Git, source-code management platforms, CI/CD pipelines, and other developer workflows.
  • Participate in feature development, testing, troubleshooting, performance improvement, and ongoing system maintenance.
  • Collaborate with security and engineering teams to support the analysis, remediation, and continuous improvement of security issues.
  • Keep up with developments in application security, DevSecOps, software supply-chain security, and AI-assisted security engineering.
Requirements:
  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related field.
  • At least 2 years of relevant experience in security engineering, application security, secure code review, or a related area.
  • Good application security fundamentals and an understanding of common Web, API, and code-security risks, such as injection, access-control vulnerabilities, authentication and authorization weaknesses, SSRF, unsafe file handling, and sensitive-data exposure.
  • Basic code-reading and analysis skills, with the ability to understand the root causes and remediation approaches of common vulnerabilities.
  • Familiarity with at least one programming language, such as Go, Python, Java, or JavaScript, and the ability to implement common features, modify existing code, debug issues, and troubleshoot problems.
  • Practical experience using AI-assisted development, code-analysis, or security tools, with the ability to perform basic validation of AI-generated code and analysis results.
  • Good computer science fundamentals, including networking, operating systems, databases, processes, threads, and common software runtime mechanisms.
  • Familiarity with standard software development practices and technologies, such as Git, CI/CD, containers, APIs, or dependency management.
  • Basic understanding of LLM and AI Agent concepts, including context, prompts, tool use, and task decomposition.
  • Good learning ability, analytical thinking, and execution skills.
  • Ability to complete module development, security-analysis tasks, and project delivery through effective teamwork and with appropriate guidance.
Preferred Qualifications
  • Experience using Claude Code, Codex, Cursor, or similar AI-assisted development tools in practical projects.
  • Experience using CodeQL, Semgrep, SonarQube, Nuclei, or similar security-analysis tools to solve practical problems.
  • Experience in SAST, SCA, secure code review, vulnerability research, DevSecOps, or software supply-chain security.
  • Experience developing security tools, automation scripts, scanning plugins, or internal engineering tools.
  • Development, research, or practical experience in one or more of the following areas:
    • AI Agents;
    • Model Context Protocol (MCP);
    • Retrieval-Augmented Generation (RAG);
    • LLM-based automated workflows.
  • Basic understanding of static-analysis concepts, such as abstract syntax trees, control flow, data flow, or taint analysis.
  • Familiarity with common package and dependency-management ecosystems, such as Maven, npm, pip, or Go Modules.
  • Experience with CTFs, vulnerability disclosures, security research, open-source contributions, or relevant internships.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多