- Singapore
工作地点
职位描述
岗位职责
Role: Application Security Remediation Services
Exp: 6+yrs
Location: Singapore
Job Description:
1. Objective
Provide dedicated engineering resources to identify, triage, remediate, validate, and report vulnerabilities identified through Penetration Testing, Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST) across Singapore critical applications.
2. Resource Assumptions
Vendor shall provide 3–4 dedicated Engineers, including 1 Lead. Resources shall have expertise in secure coding, OWASP Top 10, SAST/DAST tooling, penetration testing remediation, Java/Angular/React technologies, API security, cloud security practices.
3. In-Scope Services
Vulnerability triage, root-cause analysis, code remediation, dependency upgrades, SAST issue fixes, DAST issue fixes, penetration test observation remediation, false-positive validation, retesting coordination, security reporting, and secure coding recommendations.
4. Out-of-Scope Services
Execution of independent penetration testing, procurement of security tools, infrastructure refresh projects, security operations monitoring, compliance audits, and features unrelated to security remediation.
5. Vulnerability Remediation Services
Remediate vulnerabilities including Injection flaws, XSS, CSRF, SSRF, Broken Authentication, Broken Access Control, Security Misconfiguration, Sensitive Data Exposure, Insecure Dependencies, API Security issues, Secrets Exposure, and other findings identified through security assessments.
6. Governance Model
Weekly remediation review meetings, monthly security governance reviews, leadership reporting, remediation backlog tracking, risk acceptance reviews, and quarterly continuous improvement assessments.
7. Commercial Deliverables
Vulnerability remediation backlog, remediation design notes, secure coding recommendations, retest evidence, exception registers, monthly security dashboards, and executive governance reports.
8. Acceptance Criteria
Vulnerabilities validated as fixed through rescans, penetration test retesting, or security team verification. Deliverables submitted on time, tracked in JIRA, and approved by application and security stakeholders.
9. Vendor Performance Metrics
重要安全守则
申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。