SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
PropertyGuru, Southeast Asia's leading PropTech platform serving 32+ million monthly property seekers, is seeking a Lead Application Security Engineer to shape and drive AppSec strategy across modern, high-scale web, mobile, API, data, and AI-powered products.
You will operate as a senior individual contributor and technical authority, partnering with engineering, product, and platform teams to embed security into every stage of the software development lifecycle. You'll define security standards and patterns, lead architecture-level risk assessments, build automation, run offensive testing against AI systems, and act as a trusted advisor helping teams ship secure products without friction.
Key responsibilities include:
- Evolving AppSec strategy across application types (web, mobile, APIs, data, AI/ML); defining standards, secure-by-default patterns, and roadmap
- Owning threat modelling as a practice: running structured sessions (STRIDE, DREAD) with engineering teams on critical services and AI/ML pipelines, tracking identified risks to closure
- Leading AI red teaming and adversarial testing of LLM-powered and agentic features (prompt injection, jailbreaks, insecure tool/plugin use, data exfiltration, model integrity, unsafe autonomous actions)
- Embedding security triage across the SDLC by automating SAST, SCA, IaC scanning, DAST/API testing, container scanning, and secrets detection
- Hardening CI/CD pipelines (GitHub Actions, Jenkins) with least privilege, ephemeral credentials, provenance controls, and policy-as-code (OPA, CODEOWNERS, branch protection)
- Leading vulnerability management using ASPM tools; automating triage, prioritisation, ticketing (Jira), SLA tracking, and reporting
- Driving application testing and assurance: logic/authZ validation, mobile testing (OWASP MASVS), and secure API design/testing
- Securing the software supply chain: signed artifacts, SBOMs, dependency vetting, container security, and CI/CD provenance
- Partnering on Data and AI/ML security: data protection, vector database access control, model integrity, and privacy-by-design
- Mentoring developers and AppSec engineers, running training/code clinics, and improving developer experience with helpful tooling
- Maintaining high-quality documentation and tracking actionable metrics (MTTR, coverage, SLA adherence, repeat issues, signal to noise ratio)
PropertyGuru offers hybrid flexible working focused on outcomes over hours, holistic rewards covering financial, physical, and mental health, multi-directional career development, and inclusive benefits including equal paternity leave.
QUALIFICATIONS:
- Bachelor's or Master's degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience
- 8+ years of experience in security engineering, DevSecOps, automation, or application vulnerability management roles, with demonstrated growth into a staff/lead-level scope
- Hands-on experience threat modelling complex systems and leading security architecture reviews with engineering and product stakeholders
- Practical experience red-teaming or adversarially testing AI/LLM systems, or strong applied knowledge of AI/ML security and a track record of picking up offensive testing quickly
- Advanced scripting and automation skills in Python, Bash, or similar languages
- Proven hands-on experience with security tools across the SDLC: SAST, DAST, ASPM, secrets scanning, vulnerability management platforms
- Familiarity with cloud environments, infrastructure-as-code, CI/CD pipelines, and modern application architectures
- Relevant certifications (e.g., OSCP, GCSA, GIAC, AWS Security) are a plus; AI security-specific credentials or research (e.g., published AI red teaming work, OWASP LLM Top 10 contributions) are a strong plus
- Self-starter who thrives in fast-moving environments with minimal oversight
- Strong written and verbal communication skills, able to explain technical and risk issues clearly to both technical and non-technical stakeholders
- Comfortable collaborating across functions and influencing product, engineering, and risk leaders
- Highly organised, detail-oriented, and results-driven
- Naturally curious, innovative, and process-improvement minded
- Experienced mentor and collaborator