Lead AppSec Engineer
Sign up free to see how well your resume matches this role.
What you'll do
- Evolve AppSec strategy across application types (web, mobile, APIs, data, AI/ML); define standards, secure-by-default patterns, and roadmap.
- Own threat modelling as a practice: run structured sessions (STRIDE, DREAD or equivalent) with engineering teams on critical services and AI/ML pipelines, track identified risks to closure, and mature the program’s tooling and coverage.
- Lead AI red teaming and adversarial testing of LLM-powered and agentic features - prompt injection, jailbreaks, insecure tool/plugin use, data exfiltration via RAG/vector stores, model/output integrity, and unsafe autonomous actions - and translate findings into engineering fixes and guardrails.
- Embed security triage across the SDLC by automating SAST, SCA, IaC scanning, DAST/API testing, container scanning, and secrets detection.
- Harden CI/CD pipelines (GitHub Actions, Jenkins) with least privilege, ephemeral credentials, provenance controls, and policy-as-code (OPA, CODEOWNERS, branch protection).
- Lead vulnerability management using ASPM tools; automate triage, prioritisation, ticketing (Jira), SLA tracking, and reporting.
- Drive application testing and assurance: logic/authZ validation, mobile testing (OWASP MASVS), and secure API design/testing.
- Secure the software supply chain: signed artifacts, SBOMs, dependency vetting, container security, and CI/CD provenance.
- Partner on Data and AI/ML security: data protection, vector database access control, model integrity, and privacy-by-design.
- Mentor Developers and AppSec engineers, run training/code clinics, and improve developer experience with helpful tooling and fast feedback.
- Maintain high-quality documentation and track actionable metrics (MTTR, coverage, SLA adherence, repeat issues, signal to noise ratio, etc.).
What they're looking for
- Bachelor’s or Master’s degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience.
- 8+ years of experience in security engineering, DevSecOps, automation, or application vulnerability management roles, with demonstrated growth into a staff/lead-level scope.
- Hands-on experience threat modelling complex systems and leading security architecture reviews with engineering and product stakeholders.
- Practical experience red-teaming or adversarially testing AI/LLM systems, or strong applied knowledge of AI/ML security and a track record of picking up offensive testing quickly.
- Advanced scripting and automation skills in Python, Bash, or similar languages.
- Proven hands-on experience with security tools across the SDLC: SAST, DAST, ASPM, secrets scanning, vulnerability management platforms.
- Familiarity with cloud environments, infrastructure-as-code, CI/CD pipelines, and modern application architectures.
Nice to have
- Relevant certifications (e.g., OSCP, GCSA, GIAC, AWS Security) are a plus.
- AI security-specific credentials or research (e.g., published AI red teaming work, OWASP LLM Top 10 contributions) are a strong plus.
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
PropertyGuru is Southeast Asia’s leading PropTech company, and the preferred destination for over 32 million property seekers monthly to connect with over 50,000 agents monthly to find their dream home. PropertyGuru empowers property seekers with more than 2.1 million real estate listings, in-depth insights, and solutions that enable them to make confident property decisions across Singapore, Malaysia, Thailand and Vietnam.
PropertyGuru.com.sg was launched in Singapore in 2007 and since then, PropertyGuru Group has made the property journey a transparent one for property seekers in Southeast Asia. In the last 18 years, PropertyGuru has grown into a high-growth PropTech company with a robust portfolio including leading property marketplaces and award-winning mobile apps across its markets in Singapore, Malaysia, Vietnam, Thailand as well as the region’s biggest and most respected industry recognition platform – PropertyGuru Asia Property Awards, events and publications across Asia.
For more information, please visit: PropertyGuruGroup.com; PropertyGuru Group on LinkedIn.
Recognised as a Top Employers Certified* organisation, we’re proud to be among the best workplaces in the region—celebrating an inclusive culture of excellence, growth, and well-being.
At PropertyGuru, we strive to “Build Southeast Asia’s Trust Platform,” and security sits at the centre of that trust with our customers, agents, and partners across Singapore, Malaysia, Thailand, and Vietnam.
Role
We’re looking for a Lead Application Security Engineer to shape and drive our AppSec strategy across modern, high-scale web, mobile, API, data, and AI-powered products.
You’ll operate as a senior individual contributor and technical authority, partnering closely with engineering, product, and platform teams to embed security into every stage of the software development lifecycle. You’ll define standards and patterns, lead architecture-level risk assessments, build automation, run offensive testing against AI systems, and act as a trusted advisor helping teams ship secure products without friction.
Key Responsibilities
- Evolve AppSec strategy across application types (web, mobile, APIs, data, AI/ML); define standards, secure-by-default patterns, and roadmap.
- Own threat modelling as a practice: run structured sessions (STRIDE, DREAD or equivalent) with engineering teams on critical services and AI/ML pipelines, track identified risks to closure, and mature the program’s tooling and coverage.
- Lead AI red teaming and adversarial testing of LLM-powered and agentic features - prompt injection, jailbreaks, insecure tool/plugin use, data exfiltration via RAG/vector stores, model/output integrity, and unsafe autonomous actions - and translate findings into engineering fixes and guardrails.
- Embed security triage across the SDLC by automating SAST, SCA, IaC scanning, DAST/API testing, container scanning, and secrets detection.
- Harden CI/CD pipelines (GitHub Actions, Jenkins) with least privilege, ephemeral credentials, provenance controls, and policy-as-code (OPA, CODEOWNERS, branch protection).
- Lead vulnerability management using ASPM tools; automate triage, prioritisation, ticketing (Jira), SLA tracking, and reporting.
- Drive application testing and assurance: logic/authZ validation, mobile testing (OWASP MASVS), and secure API design/testing.
- Secure the software supply chain: signed artifacts, SBOMs, dependency vetting, container security, and CI/CD provenance.
- Partner on Data and AI/ML security: data protection, vector database access control, model integrity, and privacy-by-design.
- Mentor Developers and AppSec engineers, run training/code clinics, and improve developer experience with helpful tooling and fast feedback.
- Maintain high-quality documentation and track actionable metrics (MTTR, coverage, SLA adherence, repeat issues, signal to noise ratio, etc.).
Who You Are
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience.
- 8+ years of experience in security engineering, DevSecOps, automation, or application vulnerability management roles, with demonstrated growth into a staff/lead-level scope.
- Hands-on experience threat modelling complex systems and leading security architecture reviews with engineering and product stakeholders.
- Practical experience red-teaming or adversarially testing AI/LLM systems, or strong applied knowledge of AI/ML security and a track record of picking up offensive testing quickly.
- Advanced scripting and automation skills in Python, Bash, or similar languages.
- Proven hands-on experience with security tools across the SDLC: SAST, DAST, ASPM, secrets scanning, vulnerability management platforms.
- Familiarity with cloud environments, infrastructure-as-code, CI/CD pipelines, and modern application architectures.
- Relevant certifications (e.g., OSCP, GCSA, GIAC, AWS Security) are a plus; AI security-specific credentials or research (e.g., published AI red teaming work, OWASP LLM Top 10 contributions) are a strong plus.
Essential Personal Skills
- Self-starter who thrives in fast-moving environments with minimal oversight.
- Operates with high integrity, discretion, and accountability.
- Strong written and verbal communication skills, able to explain technical and risk issues clearly to both technical and non-technical stakeholders, including senior leadership.
- Comfortable collaborating across functions and influencing product, engineering, and risk leaders.
- Highly organised, detail-oriented, and results-driven.
- Naturally curious, innovative, and process-improvement minded.
- Experienced mentor and collaborator — able to support, guide, and grow junior and mid-level team members.
Our commitment to you:
Hybrid flexible working that focuses on outcomes over hours.
Holistic rewards package covering your financial, physical & mental health.
Multi-directional career development across all levels.
Inclusive benefits like equal paternity leave, supporting all employees in work-life balance.
At PropertyGuru, you’ll be part of a Top Employers Certified* company that puts people at the heart of everything we do.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.
