jobs in KRISE MANNPOWER PTE. LTD.

全职 IT Security Engineer 工作, 薪水 up to SGD 8,500, KRISE MANNPOWER PTE. LTD. Islandwide (Singapore) 公司招聘中 - Ricebowl

IT Security Engineer

KRISE MANNPOWER PTE. LTD.

SGD8,500 - SGD8,500 每月

Islandwide (Singapore)

分享
保存

工作地点

  • Islandwide (Singapore) Singapore

职位描述

岗位职责

Key Responsibilities

1.⁠ ⁠Vulnerability Triage & Code Remediation

•⁠ ⁠Hands-on Fixing: Directly write, test, and deploy secure code to fix vulnerabilities including Injection flaws, XSS, CSRF, SSRF, Broken Authentication, Broken Access Control, Secrets Exposure, and API security issues.

•⁠ ⁠Triage & Validation: Analyze findings from SAST/DAST tools and penetration tests, eliminate false positives, and perform root-cause analysis.

•⁠ ⁠Dependency Management: Proactively manage and upgrade insecure third-party dependencies and libraries.

2.⁠ ⁠Engineering & Collaboration

•⁠ ⁠Secure Architecture: Design and document remediation design notes and secure coding recommendations for broader development teams.

•⁠ ⁠Testing Coordination: Partner with application teams and security stakeholders to coordinate rescans and penetration test retesting to validate fixes.

•⁠ ⁠Backlog Management: Maintain precise tracking of engineering tasks and evidence within Jira.

3.⁠ ⁠Governance & Reporting

•⁠ ⁠Participate in weekly remediation review meetings and monthly governance reviews.

•⁠ ⁠Contribute to monthly security dashboards and executive governance reports.

•⁠ ⁠Document risk acceptance reviews and maintain exception registers when immediate remediation isn't feasible.

Job Requirements

Technical Skills & Experience

•⁠ ⁠Experience: Minimum of 5+ years of experience in software engineering with a heavy focus on Application Security (AppSec), or as a dedicated AppSec Remediation Specialist.

•⁠ ⁠Core Tech Stack: Strong, production-grade coding experience in Java (Spring Boot) and modern frontend frameworks (Angular and/or React).

•⁠ ⁠Security Frameworks: Deep conceptual and practical understanding of the OWASP Top 10 and API Security Top 10 vulnerabilities.

•⁠ ⁠Tooling Familiarity: Experience interpreting outputs from SAST, DAST, and Software Composition Analysis (SCA) tools (e.g., SonarQube, Checkmarx, Veracode, Snyk, or similar).

•⁠ ⁠Cloud & Architecture: Understanding of cloud security best practices (AWS/Azure/GCP) and secure API gateway architectures.

Soft Skills & Process

•⁠ ⁠Strong analytical skills to perform root-cause analysis on complex software vulnerabilities.

•⁠ ⁠Excellent documentation skills for creating clear remediation design notes and architectural recommendations.

•⁠ ⁠Familiarity with Agile workflows and issue tracking tools like Jira.

•⁠ ⁠Bonus: Relevant certifications such as CSSLP (Certified Secure Software Lifecycle Professional), CEH, or CASE.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多