job description
Join the Monetary Authority of Singapore (MAS) as an Application Security Engineer in a dynamic contract role based in Badung, Bali. This is a unique opportunity to contribute to the security of financial applications that power Singapore’s banking and financial ecosystem, while enjoying the vibrant work-life balance of Bali.
In this role, you will play a critical part in designing, implementing, and maintaining robust security controls to protect sensitive financial data and applications. You’ll collaborate with cross-functional teams to identify vulnerabilities, conduct risk assessments, and deliver security training to ensure compliance with industry standards and regulatory requirements.
MAS is a globally respected financial regulator, and this position offers the chance to work on high-impact projects that shape the future of secure digital banking. If you’re passionate about cybersecurity, thrive in a fast-paced environment, and want to make a tangible difference in the financial sector, we’d love to hear from you.
Responsibility
- Design, develop, and implement application security controls for banking and financial systems to mitigate risks and prevent breaches.
- Conduct security assessments, penetration testing, and vulnerability scans on applications to identify and remediate weaknesses.
- Collaborate with development and DevOps teams to integrate security best practices into CI/CD pipelines (SAST/DAST).
- Develop and deliver security awareness training for employees and stakeholders to foster a culture of cybersecurity.
- Monitor and respond to security incidents, performing root cause analysis and implementing corrective actions.
- Ensure compliance with regulatory standards (e.g., ISO 27001, PCI-DSS, MAS guidelines) and industry best practices.
- Stay ahead of emerging cybersecurity threats and recommend proactive measures to safeguard applications.
- Document security policies, procedures, and incident reports for audit and improvement purposes.
Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field. Advanced degrees or certifications (e.g., CISSP, CEH, OSCP) are a plus.
- Minimum 3-5 years of experience in application security, penetration testing, or secure software development.
- Proficiency in security tools such as Burp Suite, OWASP ZAP, Nessus, or similar platforms.
- Strong understanding of secure coding practices (e.g., OWASP Top 10) and frameworks like SAST/DAST.
- Experience with cloud security (AWS, Azure, GCP) and containerization (Docker, Kubernetes) is highly desirable.
- Familiarity with financial sector regulations and compliance requirements (e.g., MAS, PCI-DSS).
- Excellent problem-solving and communication skills to articulate security risks to technical and non-technical stakeholders.
- Ability to work independently in a contract role with minimal supervision and adapt to evolving security landscapes.