Staff Security Engineer
Job description
About the role
Join our Security Engineering team to protect the infrastructure and products of foodpanda, foodora, and Yemeksepeti. You will design and integrate security controls into our engineering workflows to minimize risk while supporting rapid development across our global platforms. This position requires a hands on approach to building and maintaining scalable security measures that keep our services resilient and trustworthy. You will act as a technical partner to engineering teams, translating complex threats into clear guidance and actionable requirements. The role centers on ownership of security initiatives spanning product, DevSecOps, IAM, data protection, and emerging AI security landscapes. You will manage the full lifecycle of security engineering projects from design through deployment and optimization. Success in this position depends on your ability to operate autonomously in a fast paced, collaborative, and engineering focused environment. Your work will directly influence the security posture of some of the largest delivery platforms operating in Singapore and across the region.
Key facts
What you'll do
- Architect and implement scalable security controls across product, infrastructure, and platform environments to reduce exposure.
- Embed security protocols directly into operational and engineering pipelines to enforce standards without slowing delivery.
- Collaborate with engineering squads to identify, classify, and remediate technical risk through transparent and measurable controls.
- Lead initiatives in product security, DevSecOps, identity and access management, data protection, and AI security governance.
- Own the end to end delivery of security engineering projects, coordinating requirements, implementation, and validation.
- Design and operate detection and response capabilities using SIEM, analyzing telemetry to surface meaningful threats.
- Evaluate and drive adoption of security tooling such as SAST, DAST, CSPM, secrets management, and container security solutions.
- Define and enforce secure architecture patterns for cloud native applications, emphasizing AWS and GCP services.
- Partner with platform and infrastructure teams to strengthen IAM policies, authentication flows, and authorization models.
- Automate security tasks using scripting languages such as Python and Bash, and codify infrastructure using Terraform.
- Conduct threat modeling and risk assessments for new features and major changes, documenting findings and recommendations.
- Provide clear, audience appropriate communication of security risks to both technical and non technical stakeholders.
- Support the integration of Kubernetes and microservices security best practices into development workflows.
- Mentor and enable other engineers to adopt secure development practices across regional delivery brands.
Requirements
- Hold a Bachelor degree in Computer Science, Information Security, Engineering, or a related field from an accredited institution.
- Bring a minimum of 7 years of professional experience in security engineering, application security, cloud security, or DevSecOps roles.
- Demonstrate proficiency with AWS or GCP cloud platforms, CI/CD pipelines, containerization technologies, and API security concepts.
- Show hands on experience with a broad set of security tools including SAST, DAST, CSPM, IAM, SIEM, and secrets management systems.
- Possess deep knowledge of OWASP standards, secure architecture principles, and cloud native security best practices.
- Exhibit strong verbal and written communication skills to explain complex technical risks and translate them into actionable requirements.
- Prove your ability to thrive in high speed, collaborative, and engineering driven environments where priorities shift quickly.
- Display strong ownership and problem solving skills, with the discipline to manage multiple tasks and meet strict deadlines.
- Have experience working with version control systems, infrastructure as code, and secure software development practices.
- Commit to adhering to company policies, security standards, and regulatory requirements relevant to the role.
Nice to have
- Hold professional certifications such as CISSP, CCSP, Security+, or cloud specific security credentials.
- Bring a background in high scale e commerce, fintech, or delivery platforms with complex security needs.
- Have hands on experience with Kubernetes, microservices, software supply chain security, and platform engineering.
- Show familiarity with AI governance, LLM security, or AI integrated engineering workflows.
- Demonstrate scripting and automation skills using Python, Bash, or Terraform to solve security problems at scale.
- Have direct experience managing security for regional or global cloud native infrastructures in multi team environments.
Practical notes
- You will work within a diverse, international team in a fast growing organization based in Singapore.
- The role offers immediate responsibility and the chance to influence security practices for major global delivery brands.
- Benefits include health and dental insurance, free food, and professional development programs as part of your total rewards.
- This position is full time and based in the Singapore office with no required business travel.
- The role is open for immediate hiring and requires the ability to start within a short notice period.
- You will be expected to integrate with cross functional teams and participate in on call rotations as needed for production security issues.