Overview
We are seeking a highly skilled and motivated Application Security / DevSecOps Lead to drive the security strategy and practices within our client's software development lifecycle.
The ideal candidate will be responsible for embedding security into the application development process, leading the DevSecOps initiatives, and collaborating closely with development, operations, and security teams to ensure robust, scalable, and secure software delivery.
This is a permanent role directly based with our client.
Reg: R
Lic: 16S8060
Responsibilities
- Lead the design, implementation, and continuous improvement of application security and DevSecOps practices across the development lifecycle.
- Establish and enforce secure coding standards, threat modeling, and secure design principles.
- Develop and maintain automated security testing tools and integrate security scans into CI/CD pipelines (SAST, DAST, SCA).
- Collaborate with development teams to conduct code reviews, vulnerability assessments, and remediation guidance.
- Manage vulnerability triage and coordinate remediation efforts with development and infrastructure teams.
- Drive security awareness and training programs to build security-minded developers and engineers.
- Define and monitor key metrics to measure the effectiveness of application security initiatives.
- Stay up-to-date with the latest security trends, vulnerabilities, and compliance requirements.
- Partner with compliance, risk, and audit teams to ensure regulatory and policy adherence.
- Lead incident response efforts related to application security issues and contribute to root cause analysis.
- Manage teams across multiple countries.
Requirements
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).
- 10+ years of relevant experience, with 5 recent years of targeted experience in application security, secure software development, or DevSecOps roles.
- Strong understanding of software development methodologies, secure coding standards, and application architectures.
- Hands-on experience with DevSecOps tools such as Jenkins, GitLab CI/CD, SonarQube, Fortify, Veracode, Snyk, or similar.
- Proficient with security testing methodologies including static code analysis, dynamic testing, penetration testing, and software composition analysis.
- Experience leading security programs and working with cross-functional agile teams.
- Knowledge of cloud security best practices and platforms (AWS, Azure, GCP).
- Familiarity with compliance standards such as OWASP Top 10, PCI-DSS, GDPR, HIPAA, or similar.
To apply
If you're interested to apply or find out more, please share your CV or reach out to Chen Yi at for a discussion.
Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
We’re unlocking community knowledge in a new way.
Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr