أبلاي إيدج ابدأ البحث عن عمل

Information Technology Security Engineer

Ascendion · Singapore, Singapore

قدّم وتابع مع أبلاي إيدج
The IT Security Engineer will be responsible for implementing, operating, and supporting security controls for mission-critical systems within a secured environment.This role covers both:Day 1 Security (Build / Project Implementation)Day 2 Security (Operations / Production Support)The Security Engineer will work closely with Security Leads, Infra, System, and Software teams to ensure compliance with government security policies and standards.Key ResponsibilitiesDay 1 – Project / Implementation Security1. Security Implementation & EngineeringImplement security architecture and controls as designed by Security Leads/ArchitectsSupport system, application, and infrastructure security configurationsAssist in threat modelling and risk assessment activitiesTranslate security requirements into technical implementation across platforms2. Compliance SupportSupport compliance with:IM8 / Government security policiesWhole‑of‑Government (WOG) security requirementsPDPA (where applicable)Assist in preparation and documentation for:Security Risk Assessments (SRA)Vulnerability Assessments (VA)Penetration Testing (PT)Maintain security documentation and evidence for audits3. DevSecOps & Secure DevelopmentImplement and maintain security tools in CI/CD pipelines:SAST, DAST, SCA, container scanningMonitor and triage findings, and work with developers on remediationSupport secure coding practices and DevSecOps adoptionAssist in API security, secrets management, and secure communications setup4. Security Testing SupportSupport coordination and execution of VA/PT activitiesTrack vulnerabilities and ensure timely remediationAssist in documenting findings and closure evidenceSupport system security certification and go-live requirements5. System & Platform HardeningImplement and maintain security hardening for:Operating systemsMiddleware and databasesKubernetes and containers (RBAC, secrets, network policies)Support configuration of:API GatewaysWAFAuthentication and authorization mechanisms (OAuth2, mTLS)Day 2 – Operations / Production Security1. Incident ResponseSupport investigation, containment, and remediation of security incidentsPerform log analysis and assist in root cause analysis (RCA)Work with SOC and internal teams during incidentsFollow and improve incident response playbooks2. Vulnerability & Patch ManagementPerform regular vulnerability scans and monitoringTrack and verify patching and remediation activitiesEscalate high-risk vulnerabilities and propose mitigation controls3. Security MonitoringMonitor alerts from SIEM and security toolsAssist in tuning detection rules and dashboardsEnsure logging and monitoring coverage across systems4. Audit & Compliance SupportSupport audit preparation, evidence collection, and remediation trackingMaintain security records and documentationAssist in reporting security posture and issues5. Access Control AdministrationSupport implementation of:RBACMFAPrivileged Access Management (PAM)Perform user access reviews and ensure least privilegeRequired Qualifications & ExperienceDegree in Computer Science / Cybersecurity / Information Security or equivalent3–7 years of IT experience in cybersecurity or infrastructure securityExperience supporting security in projects or production environmentsFamiliarity with Singapore Government security policies (IM8 preferred) *Only Singaporean profiles will be considered for this role*Hands-on experience with:Kubernetes / Docker securityIAM and access controlSecurity tools (SAST, DAST, SIEM, vulnerability scanners)CI/CD and DevSecOps practicesBasic knowledge of network security, application security, and cloud securityPreferred CertificationsCEH, CompTIA Security+, or equivalentOther certifications (e.g., CISSP Associate, GIAC, AWS/Azure Security) are advantageousKey CompetenciesStrong technical troubleshooting and problem-solving skillsAbility to follow security standards and implement controls effectivelyGood communication skills with technical and non-technical teamsDetail-oriented with strong documentation skillsCollaborative team player with willingness to learn