Application Security Specialist (Cybersecurity)
Application Security Specialist (Cybersecurity)
optimum solutions pte ltd- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Responsibilities
Application Support
- Review system architecture, data flows, interfaces, APIs, internet-facing entry points and security controls to identify potential security risks.
- Conduct cybersecurity risk assessments for new and existing IT systems, applications, infrastructure and cloud services.
- Perform threat modelling and develop threat profiles for application projects to identify, quantify and remediate application security risks.
- Review remediation plans and supporting evidence to verify that identified security risks have been adequately addressed.
- Track security vulnerabilities and ensure timely remediation, patching and closure in accordance with established requirements.
Security Monitoring & Incident Management
- Monitor and investigate cybersecurity alerts and incidents, including malware, phishing, account compromise, data breaches, unauthorised access and cloud security incidents.
- Perform cybersecurity incident response and management, including incident triage, investigation, containment, remediation, recovery and post-incident reviews.
Security Awareness & Collaboration
- Conduct security awareness training sessions to promote cybersecurity awareness and good security practices.
- Collaborate with relevant stakeholders to address security risks, vulnerabilities and incidents.
Requirements
- Degree in a relevant discipline or equivalent qualification.
- Minimum 5 years of combined experience in software development, application security and cloud computing (e.g. AWS).
- Good understanding of mobile and web application architectures, APIs and related technologies and protocols, including REST, SOAP and SSL/TLS.
- Strong knowledge of application security principles and industry best practices, including OWASP Top 10 and OWASP Application Security Verification Standard (ASVS).
- Familiarity with Agile development, CI/CD and DevSecOps practices, including tools such as GitLab, GitHub and Ansible, and integration of automated security testing into CI/CD pipelines.
- Hands-on experience with Static Application Security Testing (SAST) tools such as Fortify on Demand, SonarQube or equivalent.
- Relevant professional certifications such as CISSP, OSCP, CCSP, CRISC, AWS Security Certification or equivalent is a plus.
