What You Do
As an Application Security Engineer, you will support NUS IT’s efforts to build secure, reliable, and user-centric digital services for the University community. This role contributes to the University by strengthening application security across the software delivery lifecycle, with a sub-focus on mobile security, DevSecOps, and secure platform engineering. You will play a key role in developing the CyberN'US mini app within the uNivUS superapp, while helping to embed secure coding practices, automated security controls, and platform hardening measures into application development and delivery processes. Working closely with cross-functional teams, you will help ensure that security is built into applications and platforms from design through deployment and operations.
Core Responsibilities:
Mobile application development and enhancement
- Develop, test, maintain, and enhance the CyberN'US mini app as part of the uNivUS superapp.
- Support the design and implementation of secure, intuitive, and reliable mobile application features for iOS and Android environments.
- Write clean, maintainable, and efficient code in accordance with development standards and secure coding practices.
- Participate in code reviews, testing, debugging, and issue resolution to ensure application quality, performance, and security.
- Work closely with UX/UI designers, backend developers, product owners, and relevant stakeholders to deliver a seamless user experience.
Application security and secure software delivery
- Support the implementation of secure software development lifecycle practices across application development activities.
- Embed security controls and best practices into CI/CD pipelines to enable continuous and automated security testing.
- Assist with integrating and maintaining relevant application security tools and checks, such as code scanning, dependency review, and secret detection.
- Identify, assess, and support remediation of application security findings in collaboration with development and platform teams.
- Promote secure coding awareness and contribute to improving security hygiene in day-to-day development workflows.
Secure platform engineering and container security
- Support the monitoring and hardening of containerised application environments and orchestration platforms such as Kubernetes.
- Assist with implementing security baselines, configuration standards, access controls, and platform protection measures.
- Help review container and platform configurations to identify security gaps, misconfigurations, or weaknesses.
- Support vulnerability management and remediation for container images, application components, and related platform services.
- Contribute to secure deployment practices for modern application platforms and cloud-native environments.
Security monitoring, logging, and operational support
- Support the design and maintenance of security logging, monitoring, and alerting use cases for the CI/CD platform and related application environments.
- Assist with the use of SIEM and related tools to improve visibility into security events, operational issues, and platform risks.
- Maintain technical documentation, implementation notes, runbooks, and operational procedures related to application security controls.
- Provide regular updates on development progress, technical issues, risks, and security improvement opportunities.
Collaboration and continuous improvement
- Collaborate effectively with cross-functional teams, including software engineers, infrastructure teams, product managers, and security stakeholders.
- Participate in project planning, sprint activities, technical discussions, and team meetings.
- Document development processes, technical configurations, coding standards, and project-related information clearly and consistently.
- Keep up to date with developments in mobile security, application security, DevSecOps, and secure platform engineering.
Find Your Best Opportunity
Tell them AcademicJobs.com sent you!

