Flo Energy Logo

Flo Energy

Senior Security Engineer

Posted 4 Days Ago
Be an Early Applicant
In-Office
Singapore, SGP
Senior level
In-Office
Singapore, SGP
Senior level
The Senior Security Engineer will embed security into application development and cloud infrastructure, collaborating with teams to enhance security practices and drive improvements across systems.
The summary above was generated by AI

About Flo Energy

Hi, we are Flo! We are on a mission to switch as many people and businesses as possible to affordable, renewable solutions.

We began in a small shophouse in Singapore and have grown rapidly ever since, expanding into Australia with even bigger plans ahead.

Unlike other retailers, we have built our own best-in-class energy platform entirely in-house. Designed specifically for the sector, it automates complex processes and keeps costs down, letting us offer genuinely affordable products to our customers.

Behind Flo is a diverse team of passionate engineers, data scientists, operators, and energy experts. We come from different backgrounds, but we are united by the shared goal of creating a more sustainable future. If you want to make an impact and help accelerate the renewable energy transition, we would love to meet you.

Find out more about us on https://floenergy.sg/business


About the role

We are seeking a Senior Security Engineer (DevSecOps / Application Security) to join Flo as our first dedicated security engineer, focusing on embedding security into our application development and cloud infrastructure.


You will work closely with Engineering and Platform (DevOps) teams to integrate security into the software development lifecycle and cloud environments. This role is hands-on and execution-focused, while also requiring the ability to identify security gaps, recommend improvements, and influence teams to adopt secure practices.


This role is ideal for someone who enjoys working closely with developers, improving security in real-world systems, and driving practical security outcomes through collaboration.


What you'll do

As the Senior Security Engineer, you will focus on application and cloud security while supporting the broader cybersecurity posture of the organization. As the first security engineer, you will play a key role in improving how security is implemented in practice and how engineering teams adopt secure development practices.


Secure Development & Cloud Practices:

  • Collaborate with developers to embed secure coding practices and conduct code reviews for high-risk features.
  • Conduct threat modeling and provide security input on application and cloud design.
  • Integrate security scanning tools (SAST, DAST, SCA) into CI/CD pipelines.
  • Collaborate with the Platform Team (DevOps) to secure containerized workloads (e.g., Docker, Kubernetes), infrastructure-as-code, and serverless applications.
  • Work with the Platform Team to secure configuration across AWS accounts, including IAM, encryption, and network controls.
  • Implement and manage Web Application Firewalls (WAFs) to protect applications from OWASP Top 10 vulnerabilities and other common attacks.


Security Innovation & Continuous Improvement:

  • Stay current with emerging threats, vulnerabilities, and cybersecurity technologies.
  • Proactively identify security gaps and drive practical improvements across application and cloud environments.
  • Proactively identify areas for risk reduction and security automation.
  • Collaborate across teams to build a culture of security-first thinking in everything we build and deploy.
  • Work closely with Engineering and Platform teams to drive adoption of security best practices.
  • Communicate security risks and recommendations clearly and concisely.
  • Support teams in balancing security requirements with delivery timelines.
  • Contribute to building a culture of security awareness across engineering.


Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field.
  • Strong experience in cybersecurity roles focused on application and cloud environments, preferably in senior or lead-level positions.
  • Strong understanding of secure coding, web security standards (e.g., OWASP Top 10), and CI/CD security practices.
  • Hands-on experience with CI/CD security.
  • Programming or scripting experience in Python or a general-purpose language such as Java, Kotlin, Go, or Ruby is preferred.
  • Familiarity with AWS security services, IAM policies, and network security configurations.
  • Strong understanding of IAM, SSO/SAML, and API security.
  • Experience with vulnerability scanners, container security, and code analysis tools (e.g., Snyk, Trivy, Semgrep).
  • Exposure to infrastructure-as-code (e.g., Terraform, CloudFormation) and cloud-native security tools like AWS Config, GuardDuty, and Security Hub.
  • Awareness of compliance frameworks such as ISO 27001, SOC 2, and PDPA.
  • Relevant certifications such as CompTIA Security+, AWS Certified Security, or equivalent.
  • Ability to clearly communicate security risks and remediation paths to engineering and platform teams.and SaaS management.

Top Skills

AWS
Ci/Cd
CloudFormation
Dast
Docker
Go
Guardduty
Iam
Java
Kotlin
Kubernetes
Python
Ruby
Sast
Sca
Security Hub
Terraform
Wafs

Flo Energy Singapore Office

Similar Jobs

10 Days Ago
In-Office
Singapore, SGP
Senior level
Senior level
Artificial Intelligence • Hardware • Information Technology • Machine Learning
The Senior Engineer develops and tests security firmware for SSD products, collaborates with teams, and integrates AI tools to enhance efficiency.
Top Skills: CC++NvmePciePythonRustSASSata
22 Days Ago
In-Office or Remote
Singapore, SGP
Senior level
Senior level
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
As a Senior Corporate Security Engineer, you will defend Airwallex's systems against threats, focusing on incident response, digital forensics, and security control development while securing IT infrastructure and deploying security tools.
Top Skills: Alibaba CloudBashCloud-Based VpnCrowdstrikeGCPGoogle WorkspaceMdm ToolingOktaPowershellPythonSplunk
24 Days Ago
In-Office or Remote
Singapore, SGP
Senior level
Senior level
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
As a Senior Software Engineer on the Identity & User Security team, you'll develop high-quality front-end solutions, enhance user security, and collaborate with product teams to optimize identity management systems.
Top Skills: Ant DesignApollo GraphqlCSS3Ecmascript 6+EmotionGCPGitlab Ci/CdHTML5Material UiNode.jsReactScssStyled-ComponentsTypescript

What you need to know about the Singapore Tech Scene

The digital revolution has driven a constant demand for tech professionals across industries like software development, data analytics and cybersecurity. In Singapore, one of the largest cities in Southeast Asia, the demand for tech talent is so high that the government continues to invest millions into programs designed to develop a talent pipeline directly from universities while also scaling efforts in pre-employment training and mid-career upskilling to expand and elevate its workforce.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account