About the job
Assurity Trusted Solutions (ATS), a wholly owned subsidiary of the Government Technology Agency (GovTech), is committed to being a trusted partner in enhancing digital security. Over the past decade, ATS has provided a comprehensive array of products and services including infrastructure and operational services, authentication services, governance and assurance services, and managed processes. In an ever-evolving digital and cyber landscape, ATS emphasizes trust and collaboration, working alongside GovTech, government agencies, and commercial partners to effectively mitigate cyber risks and strengthen security measures.
As an integral part of the application security core competency within the Development & Innovation for Technology ProducTisation & Operations (DITTO) department, you will play a pivotal role in shaping the application security landscape of our organization.
Your responsibilities will encompass providing expert consultancy and support to application teams in areas such as security assessments, DevSecOps practices, and security training and awareness initiatives, aimed at elevating the application security competency and standards within our organization.
Key Responsibilities:
- Design and implement the application security roadmap to enhance security practices across the organization.
- Establish secure application development practices, standards, and guidelines, fostering a culture of security within application teams.
- Oversee application security processes and maintain an automated source code scanning platform.
- Conduct secure code quality reviews and perform application penetration testing and vulnerability assessments.
- Assist with various application testing and delivery methodologies, including CI/CD.
- Educate and empower developers on secure coding practices across multiple programming platforms such as Java, C#, PHP, etc., and guide them in writing security acceptance criteria in user stories.
- Train application teams to develop security unit tests and carry out secure coding assessments.
- Collaborate with the DevOps team to enhance security within the CI/CD pipeline.
Qualifications:
- A minimum of 3-5 years of combined experience in software development, application security, and cloud computing (e.g., Azure, AWS).
- Proficient in conducting manual secure source code reviews across at least one of the following programming platforms: Java, PHP, JavaScript, C#, Android, or iOS, utilizing both waterfall and Agile methodologies.
- Experience in threat modeling, with the ability to create threat profiles for application projects to identify, assess, and mitigate application security risks.
- Familiarity with mobile and web application programming interfaces (API) architecture, including REST, SOAP, SSL/TLS.
- Knowledge of industry security best practices such as OWASP Top 10 and OWASP Application Security Verification Standard.
- Experience with using SAST tools for secure code analysis.

