Application Security Risk Manager
We are seeking an experienced Application Security Risk Manager to provide risk oversight and challenge across application security and technology controls.
The role will partner with Technology, Cybersecurity and Engineering teams to identify security risks and ensure applications are designed, developed and operated securely.
Key Responsibilities:
- Provide risk oversight and challenge across application security and software development activities.
- Conduct security risk assessments for new applications, major technology changes and critical systems.
- Assess security controls across the SDLC, including secure design, development, testing, deployment and production.
- Review risks relating to application vulnerabilities, APIs, integrations, authentication, access management and data protection.
- Assess DevSecOps and CI/CD controls, including SAST, DAST, penetration testing and vulnerability management.
- Review security exceptions, risk assessments and remediation plans and provide independent challenge where required.
- Assess application security across on-premise, cloud and hybrid environments.
- Conduct thematic reviews to identify systemic risks and control weaknesses.
- Oversee significant application security incidents and remediation.
- Develop risk metrics and contribute to application security policies, standards and control frameworks.
- Monitor emerging application security threats and advise stakeholders on relevant risks.
Requirements:
- 8-15 years of experience across application security, cybersecurity, technology risk, security architecture or technology assurance.
- Strong understanding of application security, SDLC and secure software development.
- Knowledge of DevSecOps, CI/CD, APIs, IAM, vulnerability management and cloud security.
- Experience assessing application security controls and technology risks.
- Familiarity with SAST, DAST, penetration testing and frameworks such as OWASP, NIST and ISO 27001.
- Financial services and regulatory experience would be advantageous.
- Strong analytical, communication and stakeholder management skills.
- Certifications such as CISSP, CISM, CRISC, CSSLP or CCSP would be advantageous
To apply:
If you’re interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060

A leading global financial services organisation is looking for...
We are partnering with a leading Singapore-based organization seeking a senior Application Security Architecture leader to drive secure-by-design practices, enterprise security architecture and AI security...
We are looking for an AI Security Specialist to strengthen the organisation’s approach to securing AI adoption and leveraging...
Our client is an established international cybersecurity firm supporting enterprises with complex security challenges. As part of its continued growth in the region, the organisation...
Our client is an established international technology organisation providing enterprise software solutions to customers globally. The business works with large organisations across a range of industries,...
We are seeking an experienced cybersecurity leader to oversee the organisation’s governance, risk, and assurance capabilities. This role is responsible for establishing and maintaining an effective...
A leading international financial institution is seeking an...
We are currently supporting a global client in seeking a senior cybersecurity leader to drive its enterprise Vulnerability Management...
We are looking for an experienced Cybersecurity & Technology Risk Manager to lead the organisation’s security, technology risk and resilience agenda across enterprise technology, digital platforms...
We are looking for an experienced Cybersecurity & Technology Risk Manager to lead the organisation’s security, technology risk and resilience agenda across enterprise...
We are seeking an experienced Head of IT & Cybersecurity to lead the strategy, operations, and continuous improvement of the organisation’s IT infrastructure and cybersecurity posture. This...
An international financial institution is seeking an experienced leader to head its local Information Security Coordination and Business Continuity function. This role combines team leadership, information...
The Head of Cyber Operations will lead the organisation’s cyber defence capability, overseeing 24×7 Security Operations, Threat Intelligence, Threat Hunting, Detection Engineering and Incident...
An organisation operating within a large, complex and mission-critical environment is seeking an experienced leader to head its Incident Management & Reporting function.
This role is responsible...
Our client is an established international technology organisation providing enterprise software solutions to customers globally. The business works with large organisations across...
We are seeking an experienced cybersecurity leader to oversee the organisation’s governance, risk, and assurance capabilities....
We are seeking a Cybersecurity Architect to join a lean and highly collaborative cybersecurity team. This role will be responsible for defining, designing, and driving the implementation of security...
We’re partnering with a leading organisation to hire an experienced Information Security leader to oversee enterprise security capabilities and lead a team responsible for protecting the organisation’s...
A leading multinational organisation is seeking an experienced Security Architect to drive secure architecture and technology initiatives across a regional environment.
This role will be responsible...
An international financial institution is seeking an experienced leader to head its local Information Security Coordination and...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are looking for an experienced Lead Data Security Engineer to design, implement, and enhance enterprise data security capabilities across on-premises and cloud environments. This...
