Role Overview
We are seeking an experienced
Application Security Officer
to support cybersecurity risk management, application security reviews, security operations, and incident response activities across enterprise applications, infrastructure, and cloud environments.
The successful candidate will work closely with stakeholders, project teams, and technology teams to identify, assess, and remediate cybersecurity risks while promoting secure development practices and cybersecurity awareness.
Responsibilities
Review system architecture, data flows, interfaces, APIs, internet-facing entry points, and existing security controls to identify potential security risks.
Conduct cybersecurity risk assessments for new and existing IT systems, applications, infrastructure, and cloud services.
Develop threat models and threat profiles for application projects to identify, quantify, and remediate application security risks.
Review remediation plans and supporting evidence to verify that identified security risks have been adequately addressed.
Track security vulnerabilities and ensure timely remediation, patching, and closure in accordance with established requirements.
Monitor and investigate cybersecurity alerts and incidents, including malware, phishing, account compromise, data breaches, unauthorized access, and cloud security incidents.
Perform cybersecurity incident response and management activities, including incident triage, investigation, containment, remediation, recovery, and post-incident review.
Conduct security awareness training sessions to promote cybersecurity awareness and security best practices.
Requirements
Experience & Technical Skills
At least 5 years
of combined work experience in software development, application security, and cloud computing environments (e.g., AWS).
Good understanding of mobile and web application architectures, including APIs and related technologies and protocols such as REST, SOAP, and SSL/TLS.
Strong knowledge of application security principles and industry best practices, including OWASP Top 10 and OWASP Application Security Verification Standard (ASVS).
Familiarity with Agile development methodologies, CI/CD, and DevSecOps practices, including tools such as GitLab, GitHub, and Ansible, as well as the integration of automated security testing into CI/CD pipelines.
Experience using SAST code scanning tools such as Fortify-on-Demand, SonarQube, or equivalent solutions.
Experience in threat modelling and developing threat profiles for application projects is preferred.
Soft Skills
Good verbal and written communication skills.
Strong collaboration skills and experience engaging with various stakeholders.
Strong analytical, problem-solving, and troubleshooting abilities.
Ability to work independently and effectively manage assigned responsibilities.
Education
Degree in a relevant discipline or an equivalent qualification.
Preferred Qualifications
Relevant professional certifications such as CISSP, OSCP, CCSP, CRISC, AWS Security Certification, or equivalent.
Experience working with Government Commercial Cloud (GCC) environments is preferred.
Company Overview – CMC APAC
CMC APAC Pte. Ltd.
, a member of
CMC Global
under
CMC Corporation,
is a Singapore-based regional hub delivering ICT and digital transformation solutions across the Asia-Pacific region.
As the Asia-Pacific arm of CMC Global, CMC APAC extends the Group’s technological expertise into one of the world’s most dynamic digital markets. Building on a strong foundation as a leading digital transformation (DX) provider in Vietnam, we serve as a strategic hub for delivering AI, Data, Cloud, and next-generation technology solutions across the region.
About CMC Global
CMC Global is a leading technology and AI transformation services provider, serving over 300 global clients across industries such as:
Banking & Financial Services
Healthcare
Manufacturing
Automotive
The company delivers end-to-end solutions in AI, Data, Cloud, and Digital Transformation, supporting enterprises in solving complex business challenges at scale.
Founded in 2017, CMC Global builds upon the long-standing legacy of CMC Corporation (established in 1993), one of Vietnam’s leading technology groups, with a vision to bring Vietnamese ICT solutions to the global market.
Global Presence & Capabilities
With an international network spanning Asia-Pacific, Europe, and North America, CMC Global provides:
24/7 global delivery capability
Strong engineering talent pool
Scalable and cost-effective delivery models
At CMC APAC, we combine global delivery excellence with local market expertise to support enterprises in achieving:
Operational efficiency
Business growth
Sustainable, long-term value
Learn More
CMC APAC: https://cmc-apac.sg/
CMC Global: *************