Lead Application Security Engineer
Thoughtworks Singapore, SingaporeEst. Est. SGD 9,000–13,000 / monthSenior
Estimated range based on role, country and industry — not published by the company.
Key requirements
- Aws
- Azure
- Gcp
- Kubernetes
- Docker
- Ci/Cd
- Stakeholder Management
- Audit
- Risk Management
- Compliance
Lead Engineers at Thoughtworks act as trusted technical leaders and security advisors who align enterprise risk and executive strategy with modern software delivery, ensuring security measures enhance organizational objectives.
In this role, you bring a strategic and proactive mindset to client engagements, guiding delivery teams in embedding security directly into the software development lifecycle, platform architecture, and cloud environments.
You balance high-level security architecture with hands-on engineering, conducting threat modeling, establishing DevSecOps practices, and following a pragmatic and robust approach to risk management.
As a technical leader, you guide and coach cross-functional teams, cultivate security awareness across accounts, and navigate complex stakeholder environments to build resilient, trustworthy software solutions.
Due to the nature of the projects and specific client security clearance , this role requires the successful candidate to be a Singapore Citizen Or Singapore Permanent residents.
Job Responsibilities
You will lead the design and implementation of enterprise security architectures, zero-trust patterns, and DevSecOps practices and controls across software delivery teams.
You will act as a primary technical advisor to client stakeholders and engineering leads, aligning information security strategies with enterprise risk tolerances and business goals.
You will champion shifting security left in the software development lifecycle by integrating automated SAST, DAST, SCA, and secrets management into CI/CD pipelines.
You will conduct threat modeling sessions, security risk assessments, and architectural reviews to identify vulnerabilities and design pragmatic mitigations alongside delivery teams.
You will oversee cloud platform security governance, Identity and Access Management (IAM), container security (Kubernetes, Docker), and Infrastructure as Code (IaC) compliance across AWS, Azure, or GCP.
You will guide vulnerability management, security incident response workflows, and audit readiness to ensure alignment with industry regulations and public sector standards (e.g., Singapore IM8 / IM8+, SOC 2, ISO 27001, NIST).
You will partner closely with cross-functional teams—including software developers, infrastructure engineers, quality analysts, and product managers—to balance security controls with delivery velocity.
You will cultivate Thoughtworker growth and development by mentoring engineers, providing ongoing supportive feedback, and fostering an inclusive team culture.
You will apply the latest technology thinking and security insights from our Technology Radar to solve complex client security challenges.
You will contribute to Thoughtworks’ security community of practice, supporting pre-sales pursuits, capability development, and technical thought leadership.
Professional Skills
You bring 7+ years of experience in information security engineering, application security, or cloud security within fast-paced software delivery environments.
You possess deep expertise in secure software development practices, threat modeling methodologies (e.g., STRIDE, PASTA), and security standards such as OWASP Top 10 and SANS Top 25.
You have hands-on experience with security automation tools (SAST, DAST, IAST, SCA, secrets scanners) and integrating them into continuous integration and continuous delivery pipelines.
You bring strong technical capabilities in securing cloud infrastructure (AWS, Azure, GCP), container platforms (Kubernetes, Docker), and Infrastructure as Code (IaC) environments.
You have a solid foundation in cryptography, Identity and Access Management (IAM), zero-trust architecture, network security, and API security.
You possess practical knowledge of regulatory frameworks and compliance standards, such as Singapore Public Sector IM8 / IM8+, SOC 2, ISO 27001 (ISMS), PCI-DSS, or GDPR.
You are a natural mentor and technical lea
See your match score for this role.
Xecodai maps the interview stages and shows what is preventing a 95% match.
