DBS Bank logo

AVP/Sr. Assoc, Security Engineer (IAM), Information Security Services, Group Technology

DBS Bank
2 days ago
Full-time
On-site
Singapore, Singapore
Data Science

AVP / Sr. Assoc, Security Engineer (IAM), Information Security Services, Group Technology  

 

Business Function 

Group Technology empowers the bank with an efficient, nimble and resilient infrastructure and system through a strategic focus on productivity, quality & control, technology, coupled with strengthening people capability and banking on innovation. In Group Technology, we manage the majority of the Bank's operational processes and inspire to delight our business partners and customers through our multiple banking delivery channels. 

 

Job Summary 

We are seeking an experienced Security Engineer with a strong application development background to design, build, and implement secure solutions within the Identity and Access Management (IAM) space, focusing on secrets management. This role involves driving secure integration of applications and platforms, including providing operational support for highly resilient systems, and partnering with various teams to deliver secure-by-default services at enterprise scale. 

 

Responsibilities 

  • Design, build, test, operate, and continuously improve enterprise security solutions for IAM involving secrets management (namely API and SSH keys, SSL/TLS certificates etc) across various application deployment environments. 

  • Engineer and operate highly available, resilient, and secure application-focused platforms for secrets management, workload identity and service-to-service authentication. 

  • Configure, manage, and support secrets management solutions and related technologies for applications, including authentication methods, secret engines, policy management, audit logging, replication, backup, disaster recovery, and platform upgrades. 

  • Integrate applications, APIs, microservices, batch workloads, containers, CI/CD pipelines, and cloud-native platforms with IAM services using secure, automated, and repeatable development patterns, with emphasis on secure API design and implementation. 

  • Develop robust automation, reusable tooling, APIs, scripts, and Infrastructure as Code to reduce manual effort, improve consistency, strengthen controls, and accelerate secure application onboarding. 

  • Provide operational support for critical security platforms, including monitoring, incident response, troubleshooting, escalation management, root-cause analysis, and implementation of preventive actions. 

  • Partner with application development, DevOps, cloud, risk, audit, and security operations teams to embed robust application security and IAM controls into software development lifecycles and delivery pipelines. 

  • Maintain operational documentation, architecture diagrams, runbooks, control evidence, service metrics, and knowledge articles to support audit readiness and sustainable operations for application security services. 

Requirements 

  • Bachelor's degree in Computer Science, Information Security, Engineering or equivalent practical experience. 

  • Minimum 7 years of relevant experience in application security, security engineering, software development, or IAM, with at least 3 years of hands-on experience in secrets management solution, machine/non-human identity, PKI or service-to-service authentication. 

  • Strong software engineering capability in Java and at least one scripting or automation language (e.g., Python, JavaScript/Node.js, Go, or shell scripting) for security tool development and automation. 

  • Strong hands-on development and implementation experience with enterprise secrets management solutions including production deployment, configuration, operations, troubleshooting, and lifecycle management for applications. 

  • Experience designing, developing, and operating highly resilient application systems, including clustering, failover, backup and restore, disaster recovery, observability, capacity management, and service reliability practices. 

  • Practical experience with secure API design and development, cryptography concepts, TLS/SSL, certificates, key management, SSH key management, token-based authentication, OAuth/OIDC, JWT, SAML, or workload identity patterns. 

  • Experience with CI/CD pipelines, Infrastructure as Code for application deployments, container platforms (e.g., Kubernetes, Docker), and cloud services across AWS, Azure, or GCP in a development and security context. 

  • Proven experience in requirements gathering, secure solution design, development, integration testing, performance testing, change implementation, and production support for enterprise application technology platforms. 

 

Functional / Technical Competencies 

  • Deep understanding of non-human identities, including service accounts, application identities, workload identities, managed identities, service principals, API credentials, certificates, keys, and tokens. 

  • Strong knowledge of identity lifecycle governance for machine and application identities, including discovery, ownership, onboarding, least privilege, rotation, expiry, decommissioning, monitoring, and auditability. 

  • Strong understanding of secure coding practices, application security principles, cryptography, threat modeling, secrets handling and secure software development lifecycle (SSDLC) practices. 

  • Strong technical knowledge of APIs, cloud platforms, Kubernetes or containers, and enterprise monitoring or logging tools, with an emphasis on development and security integration. 

  • Ability to troubleshoot complex production issues across application, identity, and related layers while communicating clearly with technical and non-technical stakeholders. 

  • Strong automation mindset with experience using CI/CD, Git-based workflows, policy-as-code, configuration management, and repeatable engineering practices for security development. 

  • Good documentation, stakeholder engagement, mentoring, and operational discipline expected to support critical banking technology services. 

Location:

DBS Asia Hub

Job:

Technology

Schedule:

Regular

Employee Status:

Full time