Skip to content

Open nowPosted 19 days ago

Security Engineer

MyCareersFuture94,028 open roles

Pay
SGD 7,000 – SGD 15,000 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity EngineerMyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 19 days ago

The posting

We're hiring a Software Engineer (Security) to own security at Padlet — across our application, network, and infrastructure layers, along with the compliance programs that wrap around them.

You'll design and implement defences in the product, harden our network and cloud posture, drive our SOC 2 program through a compliance automation platform, and run incident response when things get noisy. The work is broad by design: we'd rather have one engineer with real ownership across the stack than split the function into pieces that never quite add up.

We expect this person to use AI heavily — coding agents like Claude Code, LLM-powered audit tools, and custom skills/agents — to punch well above the weight of a single headcount. Reviewing code for vulnerabilities, drafting and updating policies, triaging findings, preparing audit evidence, and scanning dependencies are all things we expect you to accelerate with AI rather than do by hand.

You'll be embedded with engineering, close enough to the code to know what's realistic and what isn't.

What you'll do

  • Own application security. Design and implement controls in the product — auth hardening, rate limiting, bot mitigation, signup abuse prevention, injection and CSRF defenses, secrets management, supply chain hygiene.
  • Own network and infrastructure security. Set WAF rules, TLS posture, network segmentation, DDoS mitigation, cloud IAM, and key management. Partner with infrastructure engineers where the work overlaps and drive it to done.
  • Own compliance. Run our compliance program through a compliance automation platform — control mapping, evidence collection, policy drafting and updates, auditor questions. Drive adjacent frameworks (GDPR, regional data protection) as we expand into new markets.
  • Use AI to audit and improve code. Lean on Claude Code, AI-powered SAST tools, and custom agents to scan our codebase for vulnerabilities, review PRs for security issues, draft fixes, and keep dependencies healthy. Build lightweight internal tooling (skills, scripts, agents) when off-the-shelf options don't cut it.
  • Run incident response and remediation. Triage findings from pen tests, bug bounty reports, and third-party audits. Coordinate responders during live incidents. Run post-mortems so fixes actually stick.
  • Run the security awareness program. Organize training, tabletop exercises, and internal communications that keep security top-of-mind for engineers and the broader team.

What we're looking for

  • You're a working engineer. You've spent meaningful time building and shipping software, ideally at a company operating at scale. You read and write code daily, you're comfortable in a real codebase, and you can hold your own in architecture and design discussions.
  • Security fluency. Working knowledge across application security (OWASP Top 10 and beyond), network security (TLS, DNS, CDNs, WAFs, firewall rules), and infrastructure security (cloud IAM, secrets, container and supply chain security). You've implemented or helped implement real defenses in at least a couple of these areas.
  • AI-native working style. You already use AI tools heavily in your day-to-day work — whether that's Claude Code, Cursor, Copilot, or similar — and you have strong instincts for when AI speeds things up and when it's a liability. You're comfortable writing prompts, building small agents or skills, and reviewing AI output critically (especially for security-sensitive code). If your current workflow doesn't involve AI, this role isn't a fit.
  • Compliance experience. You've been through at least one recognized compliance audit (SOC 2, ISO 27001, or similar) and understand what controls look like in practice, not just on paper. Hands-on experience with a compliance automation platform is a strong plus.
  • Pragmatism with complexity. You enjoy digging into how systems actually work, and you're thoughtful about the tradeoffs security controls impose — latency, friction, engineering cost, product performance. You can tell the difference between a theoretical risk and an exploitable one, and you know when a defense is worth the cost and when a lighter-touch approach gets most of the benefit without slowing the product down.
  • Clear communication. You can translate between engineers, auditors, and non-technical stakeholders. You write status updates people actually read.

Nice to have

  • Experience defending a consumer product against abuse at scale (spam, scraping, account fraud, content abuse)
  • Familiarity with Cloudflare (Turnstile, WAF, Workers), GCP security tooling, or comparable cloud stacks
  • Background in threat modeling, red team exercises, or offensive security research
  • Prior work in edtech, fintech, healthtech, or another regulated/sensitive domain
  • Experience building a security awareness program that engineers actually pay attention to

Why this role

At most companies, security is split across a handful of people who each own a sliver — and the gaps between those slivers are where real problems live. This role is the opposite: one engineer who owns the full picture, from the product code to the network edge to the audit deliverable. You'll have the scope to actually move things, the AI tooling to move them faster, and the support of an engineering team that takes security seriously.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.