Cyber Platform Engineer

FLARE CONSULTING PTE. LTD.

Singapore

On-site

SGD 100,000 - 145,000

Part time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

FLARE CONSULTING PTE. LTD. is seeking a Cyber Platform Engineer on a contract basis in Singapore.

The role covers hands-on administration, maintenance, and lifecycle management of cybersecurity platforms across multiple secured sites. Expect regular onsite work, strict adherence to cybersecurity policies, and collaboration with internal stakeholders and vendors. Key platforms include Palo Alto firewalls, Carbon Black EDR, Cloudflare DMS/WAF, and CyberArk PAM.

Qualifications

  • Experience with Palo Alto Networks Next-Generation Firewalls, Carbon Black EDR, Cloudflare DMS/WAF, and CyberArk PAM.
  • Experience with cybersecurity compliance and regulatory requirements (Cybersecurity Act and Codes of Practice).
  • Willingness to perform onsite visits at secured premises and coordinate with vendors.

Responsibilities

  • Perform quarterly preventive maintenance of all onsite perimeter firewalls, including health checks, patching, firmware updates, and diagnostics.
  • Conduct quarterly log and account reviews to detect anomalies and ensure policy compliance.
  • Manage Carbon Black EDR servers and sensors (OS, database, backup, patching, health checks).
  • Administer Cloudflare DMS: user reviews, onboarding/offboarding, documentation, SSL certificates, and change management.
  • Manage CyberArk PAM: privileged account onboarding/offboarding, access management, password rotation, and audit reviews.
  • Ensure compliance with Cybersecurity Act and applicable Codes of Practice.

Skills

Strong enterprise networking
Firewall policy management
Security incident response
Onsite maintenance coordination
Regulatory/compliance awareness

Tools

Palo Alto Networks Next-Generation Firewalls
Carbon Black EDR
Cloudflare DMS/WAF
CyberArk PAM

Job description

Cyber Platform Engineer (Contract)

Location:Singapore (Onsite at various secured premises)
Employment Type:Contract

About the Role

We are seeking a skilledCyber Platform Engineerto join our team and take ownership of the operational administration, maintenance, and lifecycle management of our organization's critical cybersecurity platforms. This is a hands‑on role that requires strong technical expertise, disciplined change management, and a commitment to security compliance.

The successful candidate will manage and maintain:

  • Palo Alto Next‑Generation Firewallsacross multiple sites

  • Carbon Black EDRplatform (server and sensor management)

  • Cloudflare DDoS Mitigation Services (DMS)and Web Application Firewall

  • CyberArk Privileged Access Management (PAM)platform

This role involves regular onsite visits, quarterly preventive maintenance, and close coordination with internal stakeholders and vendors. The engineer must ensure all activities comply with organizational cybersecurity policies and regulatory requirements, including the Cybersecurity Act and applicable Codes of Practice.

Key Responsibilities
Palo Alto Firewall Operations & Maintenance
  • Perform comprehensive quarterly preventive maintenance of all onsite perimeter firewalls, including health checks, patching, firmware updates, and diagnostics.

  • Conduct quarterly log and account reviews to detect anomalies and ensure policy compliance.

  • Execute patching and mitigations based on the organizational patch management timeline:

    • Critical vulnerabilities: within 45 days

    • High/Medium vulnerabilities: within 60 days

    • Low vulnerabilities: within 90 days

  • Conduct annual firewall configuration and rules reviews, and periodic security reviews.

  • Perform ad‑hoc onsite maintenance, including graceful shutdowns (up to 3 times per quarter), replacement of faulty devices or parts (e.g., Ethernet cables), and cabling services.

  • Provide configuration services including signature updates, CVE patching, log backup extraction, firewall rules whitelisting, and system configuration.

  • Support cybersecurity assessments and audits related to firewall infrastructure.

  • Ensure all firewall rules, configurations, and operations remain compliant throughout the contract period.

  • Raise change requests in accordance with the organizational Change Management process.

EDR Platform Operations & Maintenance
  • Maintain and operate Carbon Black EDR servers hosted on RHEL 8, covering OS, database, application, backup, health checks, patching, and service maintenance.

  • Monitor and troubleshoot Carbon Black application services, PostgreSQL/Solr components, log forwarding, and indexing/queue issues.

  • Review system, security, and audit logs not centrally forwarded.

  • Monitor endpoint sensor health, connectivity, and deployment status; troubleshoot offline or faulty sensors, collect diagnostics, and support sensor recovery or redeployment.

  • Support onboarding of new endpoints and validate sensor records against asset inventories.

  • Coordinate with the OEM for advanced troubleshooting, configuration, integration, and professional support when required.

Cloudflare DMS Administration
  • Serve as the first point of contact for all DMS‑related enquiries from internal stakeholders.

  • Perform monthly user access reviews, log reviews, and report reviews from the managed services vendor.

  • Manage onboarding and offboarding of websites on the DMS platform, ensuring all changes are documented in the enterprise cloud repository.

  • Update and maintain DMS‑related documentation, templates, and default configurations.

  • Manage software/hardware maintenance and warranty tracking for DMS components.

  • Process service requests and change requests, including security policy changes (IP whitelisting/blacklisting), log extraction, and notification alert updates.

  • Manage SSL certificate renewals for protected websites and update website maintenance pages as required.

  • Review and optimize DMS rules and notifications in coordination with the vendor and SOC team.

  • Perform continuous monitoring and review of the DMS solution every six months to ensure ongoing effectiveness.

  • Update the Business Impact Assessment (BIA) form annually and manage privileged ID password expiry records.

CyberArk PAM Administration
  • Serve as the first point of contact for all PAM‑related enquiries and ad‑hoc requests.

  • Support investigation and incident response activities as required.

  • Perform monthly user access reviews to ensure only authorized personnel retain access to privileged accounts.

  • Manage onboarding and offboarding of privileged accounts into CyberArk.

  • Process service requests and change requests related to privileged account management.

  • Update the BIA form annually and manage privileged ID password expiry in accordance with organizational policy.

Security & Compliance
  • Ensure all platforms comply with organizational cybersecurity policies, the Cybersecurity Act, and applicable Codes of Practice.

  • Comply with written instructions on cybersecurity‑related matters issued by government authorities and the organization.

  • Ensure data and information across all platforms are protected from leakage, loss, destruction, and falsification in accordance with statutory, regulatory, contractual, and business requirements.

  • Sign confidentiality agreements and handle security‑classified or sensitive information only as authorized in writing.

Security Incident & Response
  • Report all security incidents (virus infections, compromises, unauthorized access, vulnerabilities) immediately.

  • Support investigations and incident response by retrieving relevant logs, configurations, and platform data.

  • Generate detailed incident investigation reports for each incident.

  • Implement preventive measures to thwart recurrence of security incidents.

Backup & Restoration
  • Maintain and update the backup and restoration plan for all platforms, including scope, frequency, type, storage location, access controls, restoration procedures, verification, and protection measures.

  • Ensure system configuration backups are completed before and after system changes, and verify scheduled backups are successful.

  • Ensure backups are stored securely, separately from production systems, and in offline storage where required.

  • Coordinate and document annual backup restoration testing, track remediation of issues, and review the backup plan at least once every 12 months.

  • Maintain backup records and evidence for cybersecurity assessments and audits.

Reporting & Documentation
  • Produce maintenance reports for applicable platforms after every maintenance cycle, including:

    • Summary status report of completed jobs, ad‑hoc support, and outstanding jobs

    • Platform health checklists (firewall, DMS, PAM)

    • System, security, and audit log review findings

    • Software security patch status and tracking

    • Backup records and evidence

    • Software licence subscription expiry tracking

    • Action items on outstanding matters

  • Maintain SOPs, asset inventories, system configuration notes, and troubleshooting guides for all platforms.

  • Maintain and update the enterprise cloud repository with the latest documentation, templates, and status records.

  • Maintain security dashboards or trackers for vulnerabilities, deviations, access reviews, and audit items across all platforms.

Technical Requirements
Mandatory Skills
  • Strong foundation in enterprise networking, including TCP/IP, VLANs, routing, NAT, DNS, network segmentation, firewall traffic flow, and network troubleshooting.

  • Hands‑on experience withPalo Alto Networks Next‑Generation Firewalls(or equivalent), including policy/rule management, NAT, routing, security profiles, log analysis, patching, firmware upgrades, and configuration backup/restoration.

  • Hands‑on experience withCarbon Black EDR(or equivalent), including server administration, sensor health monitoring and troubleshooting, log review, endpoint onboarding, and maintenance of supporting OS/application services.

  • Experience withCloudflare(or equivalent DDoS mitigation and WAF platforms), including WAF/security rules, IP whitelisting/blacklisting, SSL certificate management, log review, and website onboarding/offboarding.

  • Experience withCyberArk PAM(or equivalent privileged access management solutions), including privileged account onboarding/offboarding, access management, password rotation, session management, and audit log review.

  • Understanding of secure network environments, including air‑gapped networks, restricted connectivity, controlled offline transfer of patches/files, and use of data diodes or unidirectional gateways.

Good‑to‑Have Skills
  • Strong understanding of network security concepts including firewall policies, IPS, application‑layer inspection, high availability, and secure administrative access.

  • Familiarity with vulnerability assessment, patch management, security hardening, change management, and cybersecurity incident response processes.

  • Experience supporting cybersecurity platforms within highly secure, segregated, or air‑gapped enterprise network environments.

  • Familiarity with PKI and TLS/SSL certificate lifecycle management.

Preferred Certifications
  • CCNAor equivalent networking certification -highly preferred.

  • Palo Alto Networks Certified Next‑Generation Firewall Engineeror equivalent - preferred.

  • CyberArk Defender – PAM- preferred;CyberArk Sentry – PAMwill be advantageous.

  • RelevantCloudflaretechnical certification, accreditation, or recognized training in WAF/DDoS administration -advantageous.

Working Arrangement
  • Onsite at designated secure premises across Singapore, as required for quarterly preventive maintenance or ad‑hoc works.

  • Expected to complete scheduled quarterly maintenance windows and ad‑hoc response for onsite troubleshooting. Time‑off will be given for work performed after office hours.

  • The engineer will be subjected tosecurity clearance prior to commencement of work. Clearance processing takesat least four weeks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Operations Engineer - A26310
Platform Operations Engineer - A26310

Activate Interactive Pte Ltd • Singapore

On-site
SGD 100,000 - 167,000
Competitive compensation
Medical coverage
Flexible work arrangement
M01 - Cyber Platform Engineer
M01 - Cyber Platform Engineer

FPT Asia Pacific • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Platform Engineer
Cybersecurity Platform Engineer

OPTIMUM SOLUTIONS (SINGAPORE) PTE LTD • Singapore

On-site
SGD 90,000 - 150,000
Cyber Platform Engineer
Cyber Platform Engineer

NSEARCH GLOBAL PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
null
Platform Operations Engineer — Cybersecurity Platforms (Onsite SG)
Platform Operations Engineer — Cybersecurity Platforms (Onsite SG)

Activate Interactive Pte Ltd • Singapore

On-site
SGD 100,000 - 167,000
Competitive compensation
Medical coverage
Flexible work arrangement
Security Platform Engineer: Firewall & EDR Expert
Security Platform Engineer: Firewall & EDR Expert

FPT Asia Pacific • Singapore

On-site
SGD 90,000 - 130,000
Onsite Cyber Platform Engineer: Firewalls, EDR & PAM
Onsite Cyber Platform Engineer: Firewalls, EDR & PAM

FLARE CONSULTING PTE. LTD. • Singapore

On-site
SGD 100,000 - 145,000
Cyber Security Firewall Engineer (FortiGate, Palo Alto)
Cyber Security Firewall Engineer (FortiGate, Palo Alto)

Flintex Consulting • Singapore

On-site
SGD 90,000 - 150,000
Cyber Security Firewall Engineer (FortiGate, Palo Alto)
Cyber Security Firewall Engineer (FortiGate, Palo Alto)

Flintex Consulting Pte Ltd • Singapore

On-site
SGD 56,000 - 67,000
Security Platform Engineer (Palo Alto, EDR, Cloudflare)
Security Platform Engineer (Palo Alto, EDR, Cloudflare)

OPTIMUM SOLUTIONS (SINGAPORE) PTE LTD • Singapore

On-site
SGD 90,000 - 150,000