{"id":1197286,"url":"https://alion.io/job/shopee-security-engineer-appsec-secure-sdlc-information-security","title":"Security Engineer (AppSec - Secure SDLC) - Information Security","company":{"id":49909,"name":"Shopee","domain":"shopee.com","url":"https://alion.io/company/shopee","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Career site","truth_index":null},"role":"Security","role_family":"Security","seniority":"junior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Singapore"],"countries":["SG"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":51000,"max_usd":124000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":227},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"CI/CD","optional":false},{"name":"Function Calling","optional":false},{"name":"Git","optional":false},{"name":"Go","optional":false},{"name":"JavaScript","optional":false},{"name":"LLM","optional":false},{"name":"Python","optional":false},{"name":"Tool Use","optional":false},{"name":"Claude Code","optional":true},{"name":"CodeQL","optional":true},{"name":"Cursor","optional":true},{"name":"Java","optional":true},{"name":"Maven","optional":true},{"name":"Model Context Protocol","optional":true},{"name":"npm","optional":true},{"name":"Nuclei","optional":true},{"name":"OpenAI Codex","optional":true},{"name":"RAG","optional":true},{"name":"Semgrep","optional":true},{"name":"SonarQube","optional":true}],"status":"live","first_seen_at":"2026-09-24T19:12:45Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-26T06:28:09Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"We are looking for a Security Engineer with good security fundamentals and software development capabilities to contribute to the development of our internal Secure SDLC tools and automation capabilities.\nYou will work on code security, software supply-chain security, vulnerability analysis, and AI-assisted security engineering. You will also collaborate with the team to integrate security capabilities into real-world software development workflows.\nParticipate in the design, development, and continuous improvement of internal security tools and platforms, including but not limited to:AI-assisted code review and vulnerability analysis;\nStatic Application Security Testing (SAST);\nSoftware Composition Analysis (SCA) and software supply-chain security;\nSecurity automation and other Secure SDLC tools.\n\nDevelop and improve security detection rules, analysis logic, and automated workflows based on security requirements.\nParticipate in secure code review, vulnerability analysis, and false-positive investigation to improve detection accuracy and vulnerability coverage.\nUse AI-assisted development, code-analysis, and security-research tools to improve engineering and security-analysis efficiency.\nContribute to LLM- or Agent-based security tools involving repository search, tool use, task orchestration, and result validation.\nIntegrate security tools with Git, source-code management platforms, CI/CD pipelines, and other developer workflows.\nParticipate in feature development, testing, troubleshooting, performance improvement, and ongoing system maintenance.\nCollaborate with security and engineering teams to support the analysis, remediation, and continuous improvement of security issues.\nKeep up with developments in application security, DevSecOps, software supply-chain security, and AI-assisted security engineering.\nBachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related field.\nAt least 2 years of relevant experience in security engineering, application security, secure code review, or a related area.\nGood application security fundamentals and an understanding of common Web, API, and code-security risks, such as injection, access-control vulnerabilities, authentication and authorization weaknesses, SSRF, unsafe file handling, and sensitive-data exposure.\nBasic code-reading and analysis skills, with the ability to understand the root causes and remediation approaches of common vulnerabilities.\nFamiliarity with at least one programming language, such as Go, Python, Java, or JavaScript, and the ability to implement common features, modify existing code, debug issues, and troubleshoot problems.\nPractical experience using AI-assisted development, code-analysis, or security tools, with the ability to perform basic validation of AI-generated code and analysis results.\nGood computer science fundamentals, including networking, operating systems, databases, processes, threads, and common software runtime mechanisms.\nFamiliarity with standard software development practices and technologies, such as Git, CI/CD, containers, APIs, or dependency management.\nBasic understanding of LLM and AI Agent concepts, including context, prompts, tool use, and task decomposition.\nGood learning ability, analytical thinking, and execution skills.\nAbility to complete module development, security-analysis tasks, and project delivery through effective teamwork and with appropriate guidance.\nPreferred Qualifications\nExperience using Claude Code, Codex, Cursor, or similar AI-assisted development tools in practical projects.\nExperience using CodeQL, Semgrep, SonarQube, Nuclei, or similar security-analysis tools to solve practical problems.\nExperience in SAST, SCA, secure code review, vulnerability research, DevSecOps, or software supply-chain security.\nExperience developing security tools, automation scripts, scanning plugins, or internal engineering tools.\nDevelopment, research, or practical experience in one or more of the following areas:AI Agents;\nModel Context Protocol (MCP);\nRetrieval-Augmented Generation (RAG);\nLLM-based automated workflows.\n\nBasic understanding of static-analysis concepts, such as abstract syntax trees, control flow, data flow, or taint analysis.\nFamiliarity with common package and dependency-management ecosystems, such as Maven, npm, pip, or Go Modules.\nExperience with CTFs, vulnerability disclosures, security research, open-source contributions, or relevant internships.","description_format":"text","description_chars":4467,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Commerce"],"lifecycle":[{"event":"open","at":"2026-09-24T19:12:45Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":20,"reasons":["conf:5","velocity","win:early","comp:junior,brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/shopee-security-engineer-appsec-secure-sdlc-information-security","json_url":"https://alion.io/job/shopee-security-engineer-appsec-secure-sdlc-information-security.json","meta":{"generated_at":"2026-09-27T04:07:55Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3850,"day_limit":5000,"remaining_today":1150,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}