Application Security Engineer

soprasteria1· Cyber Security
Apply Now ↗
📍 Singapore📍 Singapore, , Singapore📍 sgFull time

About this role

Company Description

Sopra Steria is a listed European technology leader specializing in Consulting, Digital Services, and Software. With over 51,000 employees worldwide across Europe, North America and Asia, the Group supports organizations in driving their digital transformation and delivering sustainable business value.

In Asia Pacific, Singapore serves as the regional headquarter for Sopra Steria’s Infrastructure, Cloud and Cybersecurity services.

Job Description

Description:

For this project, we are forming a team of 6 (including 1 team lead) to assist in a huge government project to perform the following scope of works:

  1. Security Risk Assessment
  2. Security Policies, Standards, Guidelines, And Procedures Review
  3. Security Design
  4. Application Security
  5. Vulnerability assessment and
  6. System Security Acceptance Testing
  7. Cloud Security

The selected candidate will be working collaboratively within the team to fulfil the project requirements. As such, there is no expectation for one individual to possess all skill sets in the 6 domains.

As an expert in Application Security, your role will focus on providing expert advice, conducting security assessments, and helping government teams build security into every stage of their software development lifecycle.

Responsibilities:

  • Perform comprehensive risk assessments of development environments, DevOps workflows, and CI/CD processes.
  • Perform security assessments, threat modelling, and code reviews to identify vulnerabilities in applications.
  • Review and recommend improvements in areas such as identity and access management, network security, secure SDLC practices, source code management, cryptographic key handling, and data protection.
  • Guide application teams on adopting secure development practices and integrating security tools such as SAST, DAST, and VAPT into their workflows.
  • Review existing CI/CD pipelines from a security perspective and provide expert recommendations to align with DevSecOps principles.
  • Mentor and advise internal teams on secure coding practices across various platforms and languages (e.g., JavaScript, Node.js, Java, C#, Python, etc.).
  • Develop and maintain secure coding guidelines and security standards.
  • Collaborate with development teams to remediate security issues and provide guidance on secure coding practices.

Qualifications

  • At least 3 years of experience in application security or software development with security focus.
  • Strong experience in DevSecOps with a solid foundation in cybersecurity and risk assessment.
  • Hands-on knowledge of secure software development lifecycle (SSDLC) principles and tools.
  • Familiarity with integrating security testing tools and practices within CI/CD environments.
  • Experience with secure coding and vulnerability assessments across common web and mobile technologies.
  • Ability to work with and guide development teams without being directly involved in implementation.
  • Excellent communication skills and the ability to translate complex security requirements into practical advice

Additional Information

•Work-life balance: Hybrid working mode, 18 days of Annual leave
Health & insurance: Comprehensive coverage including General Practitioner, hospitalization, dental, and optical
•Performance incentives: Annual bonus based on individual performance
•Learning & development: Training programs, certification opportunities, and training incentives to support career growth
•Team culture: Regular team-building activities and social events

Frequently Asked Questions

Is the salary disclosed for the Application Security Engineer position at soprasteria1?
The salary for this Application Security Engineer role at soprasteria1 is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Application Security Engineer position at soprasteria1 located?
This Application Security Engineer role at soprasteria1 is based in Singapore, Singapore, , Singapore, sg. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Application Security Engineer role at soprasteria1 full-time or part-time?
This is listed as a Full time position. It is posted as a Application Security Engineer role in the Cyber Security department at soprasteria1.
Which team or department does the Application Security Engineer at soprasteria1 belong to?
This Application Security Engineer position is part of the Cyber Security department at soprasteria1. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Application Security Engineer position at soprasteria1?
Click the "Apply Now" button on this page. You will be redirected to soprasteria1's official application portal hosted on smartrecruiters where you can submit your application directly.
When was the Application Security Engineer job at soprasteria1 posted?
This Application Security Engineer position at soprasteria1 was posted on Apr 24, 2026. Apply as soon as possible — early applications are often reviewed first.
Application Security Engineer
soprasteria1
Apply for this role ↗

You'll be redirected to soprasteria1's official application page on SmartRecruiters.