SH

Security Engineer (AppSec - Secure SDLC) - Information Security

Shopee

SingaporeFull-time

About this role

About the team The Engineering and Technology team is at the core of Shopee’s platform development, building scalable and reliable systems to support a rapidly growing business. At Shopee’s scale, even seemingly simple problems can become complex engineering challenges, requiring strong technical foundations and long-term solutions. Our security engineering team builds internal platforms that help developers deliver secure software efficiently. We develop Secure SDLC capabilities including SAST, SCA, software supply-chain security, and DevSecOps automation. We also apply AI and Agent technologies to code review, vulnerability analysis, false-positive reduction, and security automation, embedding security directly into CI/CD pipelines and developer workflows. Responsibilities We are looking for a Security Engineer with good security fundamentals and software development capabilities to contribute to the development of our internal Secure SDLC tools and automation capabilities. You will work on code security, software supply-chain security, vulnerability analysis, and AI-assisted security engineering. You will also collaborate with the team to integrate security capabilities into real-world software development workflows. Participate in the design, development, and continuous improvement of internal security tools and platforms, including but not limited to: AI-assisted code review and vulnerability analysis; Static Application Security Testing (SAST); Software Composition Analysis (SCA) and software supply-chain security; Security automation and other Secure SDLC tools. Develop and improve security detection rules, analysis logic, and automated workflows based on security requirements. Participate in secure code review, vulnerability analysis, and false-positive investigation to improve detection accuracy and vulnerability coverage. Use AI-assisted development, code-analysis, and security-research tools to improve engineering and security-analysis efficiency. Contribute to LLM- or Agent-based security tools involving repository search, tool use, task orchestration, and result validation. Integrate security tools with Git, source-code management platforms, CI/CD pipelines, and other developer workflows. Participate in feature development, testing, troubleshooting, performance improvement, and ongoing system maintenance. Collaborate with security and engineering teams to support the analysis, remediation, and continuous improvement of security issues. Keep up with developments in application security, DevSecOps, software supply-chain security, and AI-assisted security engineering. Requirements Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related field. At least 2 years of relevant experience in security engineering, application security, secure code review, or a related area. Good application security fundamentals and an understanding of common Web, API, and code-security risks, such as injection, access-control vulnerabilities, authentication and authorization weaknesses, SSRF, unsafe file handling, and sensitive-data exposure. Basic code-reading and analysis skills, with the ability to understand the root causes and remediation approaches of common vulnerabilities. Familiarity with at least one programming language, such as Go, Python, Java, or JavaScript, and the ability to implement common features, modify existing code, debug issues, and troubleshoot problems. Practical experience using AI-assisted development, code-analysis, or security tools, with the ability to perform basic validation of AI-generated code and analysis results. Good computer science fundamentals, including networking, operating systems, databases, processes, threads, and common software runtime mechanisms. Familiarity with standard software development practices and technologies, such as Git, CI/CD, containers, APIs, or dependency management. Basic understanding of LLM and AI Agent concepts, including context, prompt…

Frequently asked questions

What does a Security Engineer (AppSec - Secure SDLC) - Information Security at Shopee do?

About the team The Engineering and Technology team is at the core of Shopee’s platform development, building scalable and reliable systems to support a rapidly growing business. At Shopee’s scale, even seemingly simple problems can become complex engineering challenges, requiring strong technical fo…

How much does a Security Engineer (AppSec - Secure SDLC) - Information Security at Shopee pay?

The employer did not list a salary for this role. Most similar Singapore roles publish their band on the job page.

Is this Security Engineer (AppSec - Secure SDLC) - Information Security role remote, hybrid, or on-site?

The listing is based in Singapore. Check the posting for remote or hybrid options.

How do I apply for this Security Engineer (AppSec - Secure SDLC) - Information Security role?

You can apply directly on Shopee's careers page. ApplyLah can tailor your résumé and cover letter to this exact role in seconds first.