FPT Asia Pacific Pte Ltd

M04 - IT Security Engineer

FPT Asia Pacific Pte Ltd Singapore, Singapore

IT Services and IT Consulting · 10,001+ employees

4 h ago
security Senior (5-10 yrs) Full-time Singapore
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The IT Security Engineer will conduct cybersecurity risk assessments, perform threat modelling, and manage incident response activities. They will also collaborate with technical teams to ensure security controls are integrated into CI/CD pipelines and remediate identified vulnerabilities.

What they look for

Application Security Cybersecurity Risk Management Vulnerability Management Cloud Security Incident Response Threat Modelling AWS CI/CD DevSecOps SAST OWASP Top 10 API Security SSL/TLS GitLab GitHub Ansible

Requirements

Candidates must hold a degree in Information Technology, Computer Science, or Cybersecurity and possess at least 5 years of experience in software development and application security. Proficiency in cloud environments like AWS, knowledge of OWASP standards, and experience with security testing tools are required.

Full description

Job Overview

We are seeking an experienced IT Security Officer (ITSO) to support application security, cybersecurity risk management, vulnerability management, cloud security, and incident response. The role involves assessing security risks, reviewing system architectures, identifying vulnerabilities, and ensuring compliance with cybersecurity standards and best practices.

Key Responsibilities

  • Review system architectures, data flows, interfaces, APIs, internet-facing entry points, and security controls to identify potential security risks.
  • Conduct cybersecurity risk assessments for new and existing IT systems, applications, infrastructure, and cloud services.
  • Perform threat modelling and develop threat profiles to identify, assess, and mitigate application security risks.
  • Review remediation plans and supporting evidence to ensure identified security risks are adequately addressed.
  • Track security vulnerabilities and ensure timely remediation, patching, and closure in accordance with established requirements.
  • Monitor and investigate cybersecurity alerts and incidents, including malware, phishing, account compromise, data breaches, unauthorised access, and cloud security incidents.
  • Manage cybersecurity incidents, including triage, investigation, containment, remediation, recovery, and post-incident reviews.
  • Support the integration of automated security testing into CI/CD pipelines.
  • Conduct security awareness training sessions to promote cybersecurity best practices.
  • Collaborate with technical teams, project stakeholders, and relevant parties to address security concerns and strengthen security controls.

Requirements

  • Degree in Information Technology, Computer Science, Cybersecurity, or a related discipline, or an equivalent qualification.
  • Minimum 5 years of combined experience in software development, application security, and cloud computing environments such as AWS.
  • Good understanding of mobile and web application architectures, APIs, and related technologies and protocols, including REST, SOAP, and SSL/TLS.
  • Strong knowledge of application security principles, industry best practices, OWASP Top 10, and OWASP Application Security Verification Standard (ASVS).
  • Familiarity with Agile development, CI/CD, and DevSecOps practices, including tools such as GitLab, GitHub, and Ansible.
  • Experience using Static Application Security Testing (SAST) tools such as Fortify on Demand, SonarQube, or equivalent solutions.
  • Good understanding of cybersecurity risk assessment, vulnerability management, and incident response processes.
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Good written and verbal communication skills, with the ability to collaborate effectively with various stakeholders.
  • Ability to work independently and manage security-related activities effectively.

Preferred Qualifications

  • Experience in threat modelling and application security risk assessment.
  • Experience working with Government Commercial Cloud (GCC).
  • Relevant professional certifications such as CISSP, OSCP, CCSP, CRISC, AWS Security Certification, or equivalent.

Similar roles