ICT Security Engineer (ELK Platform)

We+ Asia

Singapore

On-site

SGD 120,000 - 180,000

Full time

45 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

We+ Asia seeks an ICT Security Engineer to join the Production Security team of a leading financial institution in Singapore. You will focus on deployment, maintenance, and continuous improvement of the SIEM infrastructure, with emphasis on Logstash, Linux, and scripting.

You will work on Logstash ingestion pipelines, Linux server health, and automation via Python or Bash, collaborating with Production Infrastructure and Observability teams to ensure reliable data flow into ELK.

Qualifications

  • Hands-on production experience with Logstash and ELK components.
  • Proficient Linux administration across RedHat/Ubuntu.
  • Minimum 2 years scripting in Python or Bash.

Responsibilities

  • Troubleshoot Logstash production pipelines and ingestion issues.
  • Investigate data flow problems from client servers to Logstash.
  • Perform health checks on Linux servers and monitor resources.
  • Restart and reconfigure Logstash services in production safely.
  • Develop Python or Bash scripts for automation and log parsing.

Skills

Logstash
Linux administration
Python
Bash
Elastic Stack
Kafka
Production support
Scripting experience
Bachelor's Degree

Education

Bachelor's Degree in Information Technology

Tools

ELK Stack
Ansible
CI/CD pipelines

Job description

We are seeking a skilled ICT Security Engineer to join the Production Security team of a leading financial institution in Singapore. This role is focused on strengthening the bank's ability to detect and respond to cyber threats through the deployment, maintenance, and continuous improvement of its SIEM infrastructure.

While the broader team manages security infrastructure, this specific role is primarily focused on the operational stability and troubleshooting of the Logstash ingestion layer within the bank's SIEM platform.

The day-to-day work involves maintaining Logstash servers, troubleshooting pipeline failures, investigating ingestion issues on Linux servers, and writing Python/Bash scripts for automation. You will work closely with Production Infrastructure and Observability teams to ensure logs from thousands of servers flow seamlessly into the ELK platform.

The successful candidate will be a full-time member of the Production CSIRT / SIEM Engineering team, with opportunities to expand the scope of activities within the team.

This role requires deep technical expertise in Logstash, Linux administration, and scripting (Python or Bash) , with a strong focus on production support and platform management. The ideal candidate is rigorous, self-driven, and comfortable working autonomously in a fast-paced environment.

Core Responsibilities (Day-to-Day)
  • Troubleshoot Logstash production pipelines, including identifying and resolving ingestion failures.
  • Investigate why client servers are not sending data to Logstash, and restore data flow.
  • Perform health checks on Linux servers — checking service status (systemctl), analyzing logs, and investigating CPU/memory/disk issues.
  • Restart and reconfigure Logstash services safely in production environments.
  • Develop Python or Bash scripts for automation, log parsing, and operational tasks.
Platform Management
  • Install, configure, and administer servers within the SIEM infrastructure.
  • Manage project deliverables and contribute to platform improvements.
  • Platform integration skills, including installation, configuration, documentation, and administration of pre-production and production platforms.
Compliance & Governance
  • Contribute to the Permanent Control framework by implementing policies and procedures in day-to-day business activities, such as the Control Plan.
  • Comply with regulatory requirements and internal guidelines.
  • Contribute to the reporting of all incidents according to the Incident Management System.
Mandatory (Must-Have)
  • Hands-on production experience with Logstash — including troubleshooting pipelines, ingestion failures, and service management.
  • Proficient in Linux administration (RedHat / Ubuntu) — comfortable working directly on Linux servers, checking logs, managing services, and investigating resource issues.
  • Minimum 2 years of scripting/programming experience in Python or Bash — used for automation, log parsing, and operational scripting.
  • Production-grade experience with the broader Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) , including data ingestion, indexing, monitoring, and analytics.
  • Strong hands-on experience with Kafka.
  • Proven background in production support across both virtual and physical environments.
  • Bachelor's Degree in Information Technology or a related field.
  • Minimum 7 years of total professional experience, with at least 4–5 years focused on large-scale Elastic Stack (ELK) design, deployment, and support.
Preferred (Nice-to-Have)
  • Experience with automation/orchestration tools (e.g., Ansible or equivalent) and CI/CD pipelines.
  • Platform integration skills, including installation, configuration, documentation, and administration of pre-production and production platforms.
  • Banking sector experience is optional but regarded as a plus.
Personal Attributes
  • Rigorous and detail-oriented approach to work.
  • Strong analytical and problem-solving skills.
  • Self-driven — able to work autonomously and take ownership of tasks.
  • Excellent communication skills and a collaborative team player.
  • High energy, proactive attitude, and a willingness to upskill.
  • Ability to manage multiple priorities simultaneously.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ICT Security Engineer
ICT Security Engineer

WE-PLUS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
ELK SIEM Engineer: Logstash & Linux Ops
ELK SIEM Engineer: Logstash & Linux Ops

We+ Asia • Singapore

On-site
SGD 120,000 - 180,000
ICT Security Engineer (Elastic stack / Python / RHEL / Ubuntu)
ICT Security Engineer (Elastic stack / Python / RHEL / Ubuntu)

Maltem Asia-Pacific • Singapore

On-site
SGD 120,000 - 180,000
ICT Security Engineer (Elastic stack knowledge)
ICT Security Engineer (Elastic stack knowledge)

MIGSO-PCUBED • Singapore

On-site
SGD 90,000 - 140,000
Senior Security Engineer (Elastic Stack)
Senior Security Engineer (Elastic Stack)

Sopra Steria • Singapore

Hybrid
SGD 120,000 - 160,000
Hybrid working mode
18 days annual leave
Health insurance
+3
ICT Security Engineer
ICT Security Engineer

IKAS INTERNATIONAL (ASIA) PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]
Lead Security Engineer, IT Security Operations Engineering and Technology Singapore Experienced[...]

SEA Singapore • Singapore

On-site
SGD 120,000 - 180,000
Consultant ( ICT Security Engineer)
Consultant ( ICT Security Engineer)

MORGAN MCKINLEY PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
ICT Security Engineer
ICT Security Engineer

INFRASOFT TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
ICT Security Engineer
ICT Security Engineer

Infrasoft Technologies Limited • Singapore

On-site
SGD 120,000 - 180,000