Security Engineer
Firmus Technologies4 hours ago
Sydney, AustraliaSenior
Responsibilities
- Own CI/CD security gates covering SAST, DAST, SCA, secrets detection, and SBOM generation.
- Build automation for finding triage, dependency uplift, evidence collection, draft threat models, and regression testing.
- Create reusable security libraries, service templates, and developer tooling for secure software delivery.
- Write and review production code, including security-critical paths that automated tools may miss.
- Set application security standards for authentication, service authorization, tenant isolation, secret handling, and logging.
- Lead threat modeling and secure design reviews for REST, gRPC, APIs, multi-tenant applications, and AI assistants or agents.
- Govern AI-agent tool and tool-server access, including scoping, allow-listing, and auditing.
- Own application security posture, vulnerability prioritization, remediation tracking, and vulnerability SLAs.
- Extend SOC 2 Type 2 and ISO 27001 controls into software delivery and provide query-based evidence.
- Coach security champions, support application and API security incident response, and advise engineering leadership and customers on application risk.
Requirements
- Bachelor’s degree in computer science or a related technical field.
- At least 7 years of experience in application security, product security, or software engineering with a security focus.
- Experience securing a public cloud or multi-tenant platform with a public API.
- Deep practical knowledge of the OWASP Top 10, OWASP API Security Top 10, threat modeling, STRIDE, REST, and gRPC.
- Experience improving software security through standards, tooling, reviews, or secure-by-default patterns.
- Production ownership of CI/CD security gates including SAST, DAST, SCA, secrets detection, and SBOM generation.
- Production-quality programming ability in at least one of Python, Go, or TypeScript.
- Hands-on experience with LLM-backed or agentic features, prompt injection, tool misuse, delegated credentials, cross-tenant leakage, and generated code controls.
- Practical experience with OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and software secrets.
- Experience working under SOC 2 Type 2 or ISO 27001 and producing evidence that controls ran.
- Willingness to participate in application and API security incident response and occasional overseas travel.
- Clear and effective written and verbal English communication.
- Bonus qualifications include securing AI agents or sandboxed code execution, running a vulnerability disclosure program, and CSSLP or OSWE certification.
Benefits
- The role is based in Singapore or Australia.
- Occasional overseas travel may be required.
- The position offers exposure to AI infrastructure, energy systems, next-generation compute, and work alongside founders and technical experts.