Vulnerability Engineer (OWASP TOP 10, CI/CD, DevOps, API, AWS)

ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD

Singapore, SGonsitePosted Jun 17, 2026
Posting intelligenceActively listedReposted 7×, possible evergreen/ghost posting

Skills

ansiblegithubgitlabcicdaws

About the role

Application Security Engineer / DevSecOps Engineer

Role Overview

Singapore Citizens only due to CAT Clearance requiremen

We are seeking an experienced security professional to drive application security initiatives across the software development lifecycle. The role focuses on threat modelling, secure development practices, vulnerability management, cloud security, and integrating security controls into modern DevOps and CI/CD environments.

Key Responsibilities

Conduct threat modelling and security risk assessments to identify, evaluate, and mitigate application security risks.

Implement and promote secure development practices aligned with OWASP Top 10 and OWASP Application Security Verification Standard (ASVS) .

Integrate security testing into Agile, DevOps, and CI/CD pipelines using tools such as GitLab, GitHub, and Ansible .

Perform application security reviews and manage vulnerability remediation, patching, and risk tracking activities.

Utilise SAST tools including Fortify-on-Demand and SonarQube to identify and address code vulnerabilities.

Support security awareness initiatives and provide guidance to development and project teams.

Collaborate with stakeholders across development, infrastructure, and security teams to strengthen application security posture.

Requirements

Singapore Citizens only due to CAT Clearance requiremen t

Minimum 4 years of experience across software development, application security, and cloud computing (AWS) .

Strong understanding of REST, SOAP, SSL/TLS , and web/mobile application architectures.

Experience with threat modelling, vulnerability management, and secure SDLC practices .

Familiarity with Agile, DevOps, CI/CD , and security automation.

Strong analytical, troubleshooting, and problem-solving skills.

Excellent communication and stakeholder management capabilities.

Preferred Skills

Experience with Government Commercial Cloud (GCC) .

Certifications such as CISSP, OSCP, AWS Security, AWS DevOps Engineer , or equivalent.

Key Technologies

AWS, GCC, REST, SOAP, SSL/TLS, GitLab, GitHub, Ansible, Fortify-on-Demand, SonarQube, OWASP Top 10, OWASP ASVS, CI/CD, DevOps, Agile.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for DevOps / SRE roles in Singapore varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our DevOps / SRE hub for Singapore medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.