Product Security Engineering Lead (Shift-Left)


Hong Kong
Permanent
$200,000 SGD a year
Financial Technology
PR/587896_1785724962
Product Security Engineering Lead (Shift-Left)

Key Responsibilities

  • Define, implement, and validate security controls, architecture patterns, and reference designs across cloud, on-premises, and colocation environments.
  • Review infrastructure, platforms, applications, and technical configurations against internal security baselines, industry standards, and relevant regulatory requirements.
  • Conduct threat-modelling exercises and technical risk assessments for new and existing products, platforms, and technology initiatives.
  • Identify attack paths, design weaknesses, vulnerabilities, and control gaps, and recommend proportionate mitigation strategies.
  • Perform secure code reviews and work with engineering teams to address security issues before applications and services are released into production.
  • Review technical designs, functional requirements, and solution architectures to identify potential security weaknesses at an early stage.
  • Embed security controls, tools, and processes throughout the software development lifecycle.
  • Partner with software engineers, product teams, and platform teams to resolve application, cloud, infrastructure, and network security risks.
  • Provide expert guidance on secure software development, cloud security, platform security, application security, and network protection.
  • Assess security vulnerabilities across AWS services, on-premises systems, data stores, APIs, enterprise applications, and supporting infrastructure.
  • Support the integration and improvement of security testing capabilities, including static analysis, dynamic testing, dependency scanning, container scanning, and infrastructure security assessments.
  • Track security findings through remediation and provide clear guidance to developers and technical stakeholders.
  • Produce security assurance reporting covering risks, control effectiveness, identified gaps, remediation progress, and improvement recommendations.
  • Contribute to the development of security tooling, automation, internal frameworks, and engineering-led security capabilities.
  • Research emerging attack techniques, vulnerabilities, technologies, and industry developments relevant to the organisation's environment.
  • Deliver security education, technical training, and awareness sessions for engineering and wider technology teams.
  • Contribute to external security initiatives where appropriate, including technical articles, conference presentations, university engagement, and open-source projects.
  • Support the continued development of a strong security culture across the organisation.

Requirements

  • Between five and ten years of experience in product security, application security, security architecture, security engineering, or security research.
  • Strong understanding of software and product security principles, attack techniques, defensive controls, and secure development practices.
  • Proven experience conducting threat modelling, technical risk assessments, and security design reviews.
  • Experience developing practical mitigation strategies for complex technical and architectural risks.
  • Strong technical foundation in software development, engineering, or computer science.
  • Proficiency in one or more programming or scripting languages, together with experience using relevant security tools.
  • In-depth knowledge of common vulnerabilities affecting applications, APIs, networks, cloud environments, infrastructure, containers, and platforms.
  • Strong experience reviewing technical designs, architecture diagrams, and functional requirements to identify security weaknesses.
  • Experience conducting source-code reviews and explaining security vulnerabilities clearly to software engineers.
  • Good understanding of cloud security, particularly within AWS environments.
  • Familiarity with secure software development lifecycle practices and modern DevSecOps tooling.
  • Strong analytical and problem-solving skills, with the ability to investigate complex technical issues.
  • Excellent communication skills and the ability to influence stakeholders through clear, evidence-based reasoning.
  • Ability to communicate technology risks in terms that are appropriate for both technical and business audiences.
  • Strong organisation and time-management skills, with the ability to manage multiple concurrent assessments and remediation activities.
  • Ability to track deliverables, manage follow-up actions, and maintain clear ownership of outstanding security issues.
  • Previous experience within financial services, trading, fintech, or another highly regulated environment would be advantageous.

FAQs

Herzlichen Glückwunsch – wir wissen, dass es ein großer Schritt ist, sich die Zeit für eine Bewerbung zu nehmen. Wenn Sie sich bewerben, werden Ihre Angaben direkt an den zuständigen Berater weitergeleitet, der aktiv nach passenden Talenten sucht. Aufgrund der hohen Nachfrage können wir uns möglicherweise nicht bei allen Bewerbern zurückmelden. Wir behalten Ihren Lebenslauf und Ihre Daten jedoch stets in unserer Datenbank und melden uns bei Ihnen, sobald wir ähnliche Positionen sehen oder Fähigkeiten identifizieren, die das Wachstum von Unternehmen vorantreiben können.

Ja. Auch wenn diese Position nicht perfekt zu Ihrem nächsten Karriereschritt passt, hilft uns Ihre Bewerbung dabei, Ihre Fachkenntnisse und Ziele besser zu verstehen. So stellen wir sicher, dass Sie bei der passenden Gelegenheit auf unserem Radar sind.

Wir arbeiten auf unterschiedliche Weise: Zum einen veröffentlichen wir die aktuell verfügbaren Positionen auf unserer Website. Häufig können wir jedoch aus Gründen der Vertraulichkeit nicht alle Vakanzen ausschreiben. Darüber hinaus arbeiten wir mit Kunden zusammen, die einen stärkeren Fokus auf Fähigkeiten legen und darauf, was erforderlich ist, um ihr Unternehmen zukunftssicher aufzustellen.

Aus diesem Grund empfehlen wir, Ihren Lebenslauf zu registrieren, damit Sie auch für Positionen berücksichtigt werden können, die noch nicht geschaffen wurden.

Ja, wir unterstützen Sie bei der Optimierung Ihres Lebenslaufs und der Vorbereitung auf Vorstellungsgespräche. Von individueller Beratung über die gezielte Vorbereitung auf Interviews bis hin zu Gehalts- und Vertragsverhandlungen stehen wir Ihnen während Ihres gesamten nächsten Karriereschritts zur Seite.

Handverlesene Positionen für Sie