Singapore – Monetary Authority of Singapore (MAS): Notice 127 on Cyber Hygiene, TRM Guidelines
Hong Kong – Hong Kong Insurance Authority (HKIA): GL20 on Cybersecurity
Australia – Australian Prudential Regulation Authority (APRA): CPS 234 (Information Security), CPS 230 (Operational Risk Management)
Malaysia – Bank Negara Malaysia (BNM): Risk Management in Technology (RMiT)
China – National Financial Regulatory Administration (NFRA)
India – Insurance Regulatory and Development Authority of India (IRDAI): Information and Cyber Security Guidelines
Design, implement, and maintain security automation across CI/CD pipelines, including SAST, DAST, and secret detection
Conduct secure code reviews for change deployments and new designs — review pull requests, release candidates, and infrastructure changes to identify security defects before they reach production; provide actionable, context-rich feedback that helps developers ship securely and on time
Partner with engineering teams to perform threat modeling, secure code reviews, and architecture risk assessments for new features, services, and system designs — ensuring security is embedded from the earliest design stages through implementation
Triage, prioritize, and remediate vulnerabilities discovered through automated tooling, bug bounty programs, and penetration tests
Build and maintain secure-by-default frameworks, libraries, and paved-road templates that make the secure path the easy path for developers
Develop, maintain, and continuously improve SOPs and guidelines for DevSecOps — define standardised operating procedures covering secure development lifecycle, pipeline security gates, vulnerability handling workflows, secure release processes, and incident response playbooks; ensure guidelines are practical, adopted by engineering teams, and aligned with regulatory expectations
Ensure AppSec controls and evidence support the regulatory obligations of our APAC markets (e.g., APRA CPS 234 information security capability, MAS TRM secure development, BNM RMiT software lifecycle controls)
Develop and deliver security training and documentation to raise the security baseline across engineering
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Respond to security incidents, conduct root cause analysis, and drive systemic improvements
Contribute to our vulnerability management program, including SLAs, metrics, and reporting to engineering leadership and to GRC teams supporting regulatory submissions
Escalate unresolved security issues and non-compliances to the CISO — identify and formally escalate risks that remain unresolved beyond defined SLAs, regulatory non-compliances, or exceptions that exceed accepted risk appetite, ensuring executive visibility and timely decision-making
Champion a healthy security culture through collaboration rather than gatekeeping
5+ years of experience in application security, software engineering, or a closely related field
Strong understanding of OWASP Top 10, CWE/SANS Top 25, and common web/API attack patterns