Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Security Engineer, Application role.
Rezi rewrites your resume against Firmus Technologies's job description. Free.

Tailor your resume to this Security Engineer, Application role.
Rezi rewrites your resume against Firmus Technologies's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Security Engineer, Application posting at Firmus Technologies — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Security Engineer, Application posting at Firmus Technologies — free, in seconds.
About the Role
Firmus Technologies is seeking a Senior Security Engineer, Application to own application security for Firmus AI Cloud and its internal software. This role focuses on automating security ownership through CI/CD gates, secure paved roads, and threat modeling to ensure the security of public APIs, tenant isolation, and AI assistants.
Responsibilities
- Own CI/CD security gates including SAST, DAST, SCA, secrets detection, and SBOM generation.
- Build systems for repeatable tasks like finding triage, dependency uplift, evidence collection, and draft threat models.
- Develop reusable libraries, service templates, and developer tooling to establish secure paved roads.
- Write and review code in protected services, focusing on security-critical paths.
- Set application security standards for authentication, authorization, tenant isolation, secret handling, and logging.
- Lead threat modeling and secure design reviews to define attacker capabilities and necessary security measures.
- Define security requirements for AI assistants and agents, addressing prompt injection and context poisoning.
- Govern tool access and integration scoping, allow-listing, and auditing for AI agents and software engineers.
- Manage application security posture across services, tracking coverage, open issues, accepted risks, and overdue items.
- Prioritize vulnerability fixes based on exploitability and exposure, adhering to Firmus vulnerability SLAs.
- Drive remediation with owning teams to resolve issues at the source.
- Extend SOC 2 Type 2 and ISO 27001 into the software delivery path, ensuring control evidence is queryable.
- Coach security champions within teams to facilitate secure design decisions.
- Provide application security expertise during incidents and convert failure modes into automated controls.
- Communicate application risk and release readiness to engineering leadership.
- Participate in customer conversations regarding application security.
Requirements
- Bachelor's degree in computer science or a related technical field.
- 7+ years in application security, product security, or software engineering with a security focus.
- Experience securing a public cloud or multi-tenant platform with a public API.
- Deep, practical knowledge of the OWASP Top 10 and the OWASP API Security Top 10.
- Experience threat modeling multi-tenant APIs in production (identity, authorization, tenant isolation, client abuse of published contracts using STRIDE or equivalent for REST and gRPC).
- Proven ability to improve security posture of software developed by other teams through standards, tooling, review, or secure-by-default patterns.
- Experience owning production CI/CD security gates (SAST, DAST, SCA, secrets detection, SBOM) and tuning them for actionable findings with low false-positive rates.
- Proficiency in writing production-quality code in Python, Go, or TypeScript.
- Experience replacing manual security work with automation (finding triage, dependency uplift, evidence collection, regression tests).
- Hands-on experience with LLM-backed or agentic features (prompt injection, tool misuse, agent identity, delegated credentials, cross-tenant data leakage, controls on AI-generated code).
- Familiarity with OWASP guidance for LLM and agentic applications.
- Deep practical experience with OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and secrets management.
- Experience working under SOC 2 Type 2 or ISO 27001, with the ability to produce evidence of control execution.
- Willingness to join incident response for application and API security.
- Willingness to travel overseas occasionally.
- Clear and effective written and verbal communication in English.
- Experience securing AI agents, sandboxed code execution environments, or systems where AI-generated output can trigger automated actions (Bonus).
- Experience running a vulnerability disclosure program (Bonus).
- Security certifications with application-security depth, such as CSSLP or OSWE (Bonus).
Skills
- Application Security
- Product Security
- Software Engineering
- CI/CD Security
- SAST
- DAST
- SCA
- Secrets Detection
- SBOM Generation
- Threat Modeling
- Secure Design Review
- Authentication
- Authorization
- Tenant Isolation
- Secret Handling
- Logging
- Vulnerability Management
- SOC 2 Type 2
- ISO 27001
- Incident Response
- OWASP Top 10
- OWASP API Security Top 10
- STRIDE
- REST
- gRPC
- Python
- Go
- TypeScript
- Automation
- LLM Security
- Agentic Application Security
- Prompt Injection
- Tool Misuse
- Agent Identity
- Delegated Credentials
- Cross-Tenant Data Leakage
- OAuth
- OIDC
- JWT
- RBAC
- ABAC
- Application-Layer Cryptography
- Token Handling
- Secrets Management
- AI Agents
- Sandboxed Code Execution
- Vulnerability Disclosure Program
- CSSLP
- OSWE
Location
- Singapore
- Australia
Work Type
- Full-time
Experience Level
- Senior
- 7+ years
Education Level
- Bachelor's degree in computer science or a related technical field
About the Company
- Firmus Technologies is a global leader in AI infrastructure across Asia Pacific, founded in Australia in 2019.
- Our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a commitment to sustainability.
- We design, build, and operate AI Factories, pushing boundaries in liquid cooling, energy management, AI software orchestration, and construction.
- Our model-to-grid technology approach delivers low-cost AI tokens globally.
- Firmus AI Cloud is a large-scale GPU cloud platform purpose-built for energy-efficient AI compute.
- It empowers developers, enterprises, educational institutions, and government users with unmatched efficiency and cost savings for AI model training and deployment.
- We are committed to delivering a market-leading, proprietary, and scalable cloud experience.