DevSecOps Engineer (Application Security)
Dragonpass- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Location: Singapore (Hybrid)
You must be fluent in Mandarin
Please only apply if you have hands-on DevSecOps and Application Security experience within software engineering environments, including SAST, SCA, DAST, vulnerability management, CI/CD security and secure software development practices. Fluency in both Mandarin and English is essential.
Join Dragonpass at a Defining Growth Moment
We're not looking for someone who sits on the sidelines writing reports.
We're looking for a hands-on security engineer who enjoys solving problems, working closely with development teams and embedding security into every stage of the software development lifecycle.
Dragonpass is a global travel and lifestyle platform trusted by leading brands including Visa, Mastercard, Barclays and Revolut. As our global technology estate continues to grow, we're investing heavily in strengthening our DevSecOps capability and building a world-class secure development environment.
This is an opportunity to join a fast-growing international business where you'll have real influence, work on large-scale technology platforms and help shape the future of application security.
The Opportunity
As DevSecOps Engineer, you'll work closely with our Security, Engineering, DevOps and Architecture teams to drive secure-by-design development practices across the organisation.
You'll be responsible for application security testing, vulnerability management, automation and supporting engineering teams to identify and remediate security risks early in the development lifecycle.
This is a highly collaborative role requiring strong technical expertise, excellent communication skills and the ability to work effectively across both English-speaking and Mandarin-speaking teams globally.
What You'll Be Doing
- Drive application security testing across the software development lifecycle
- Manage and optimise security testing platforms including SAST, SCA and DAST tools
- Integrate security controls into CI/CD pipelines and development workflows
- Identify, triage and support remediation of security vulnerabilities
- Partner with developers, QA engineers, DevOps teams and architects to improve security posture
- Support penetration testing programmes and validate remediation activities
- Assist with threat modelling, risk assessments and security design reviews
- Build security dashboards, reporting and risk metrics for stakeholders
- Develop secure coding guidance, training materials and best practices
- Support security frameworks, compliance initiatives and audit requirements
- Promote a secure-by-design culture across engineering teams
Experience Required
- Strong hands-on experience in DevSecOps, Application Security or Security Engineering
- Fluent spoken and written Mandarin and English are essential
- Experience with SAST, SCA, DAST and vulnerability management platforms
- Experience securing CI/CD pipelines and software delivery environments
- Strong understanding of secure software development practices
- Hands-on Java development, code review and architecture analysis experience
- Experience with container and infrastructure security scanning
- Knowledge of threat modelling and security risk assessment methodologies
- Experience within FinTech, Payments or Financial Services environments is highly desirable
- Understanding of security frameworks including ISO, NIST, SOC2 and GDPR
- Experience working within Agile software development environments
What We're Looking For
Security-First Mindset
You naturally identify risks and proactively seek secure solutions.
Hands-On Problem Solver
You enjoy getting into the detail, investigating issues and supporting remediation.
Collaborative Communicator
You can effectively engage technical and non-technical stakeholders in both Mandarin and English.
Continuous Improver
You are passionate about automation, optimisation and improving security maturity.
Influencer
You can build strong relationships and promote secure development practices across engineering teams.
Why Join Dragonpass
- Work with globally recognised brands and partners
- Be part of a growing international technology organisation
- Play a key role in shaping Application Security and DevSecOps strategy
- Exposure to large-scale, enterprise-grade platforms and technology
- Collaborative global environment with international career opportunities
- Competitive salary and benefits package
Working Pattern: Hybrid working with 3 days per week in our Singapore office, Monday-Friday, 09:00-17:30.
We're committed to building an inclusive workplace and welcome applications from people of all backgrounds and experiences. At Dragonpass, we believe diversity drives innovation and helps us build better products for our customers worldwide.
More Info
Key Skills
infrastructure security scanning
Agile software development environments
CI/CD security
threat modelling
secure software development practices
security risk assessment

