Location: Ang Mo Kio, Singapore
Experience Required: 3+ years
The IT Security Engineer will be responsible for implementing, operating, and supporting security controls for mission-critical systems within a secured environment. The role spans both project/implementation security (Day 1) and operations/production support (Day 2), working closely with Security Leads, Infrastructure, System, and Software teams to ensure compliance with government security policies and standards.
Key Responsibilities
Security Implementation & Engineering
- Implement security architecture and controls as designed by Security Leads/Architects
- Support system, application, and infrastructure security configurations
- Assist in threat modelling and risk assessment activities
- Translate security requirements into technical implementation across platforms
Compliance Support
- Support compliance with IM8/Government security policies, Whole-of-Government (WOG) requirements, and PDPA (where applicable)
- Assist in preparing and documenting Security Risk Assessments (SRA), Vulnerability Assessments (VA), and Penetration Testing (PT)
- Maintain security documentation and evidence for audits
DevSecOps & Secure Development
- Implement and maintain security tools in CI/CD pipelines (SAST, DAST, SCA, container scanning)
- Monitor and triage findings, working with developers on remediation
- Support secure coding practices and DevSecOps adoption
- Assist with API security, secrets management, and secure communications setup
Security Testing Support
- Support coordination and execution of VA/PT activities
- Track vulnerabilities and ensure timely remediation
- Assist in documenting findings and closure evidence
System & Platform Hardening
- Implement and maintain security hardening for operating systems, middleware, databases, and Kubernetes/containers (RBAC, secrets, network policies)
- Support configuration of API Gateways, WAF, and authentication/authorization mechanisms (OAuth2, mTLS)
Operations & Incident Response
- Support investigation, containment, and remediation of security incidents; perform log analysis and root cause analysis
- Monitor alerts from SIEM and security tools, and assist in tuning detection rules and dashboards
- Perform vulnerability scans, track patching, and accelerate high-risk findings
- Support audit preparation, evidence collection, and remediation tracking
- Support access control administration (RBAC, MFA, Privileged Access Management) and periodic user access reviews
Requirements
- Degree in Computer Science, Cybersecurity, Information Security, or equivalent
- 3-7 years of IT experience in cybersecurity or infrastructure security
- Experience supporting security in projects or production environments
- Familiarity with Singapore Government security policies (IM8 preferred)
- Hands-on experience with Kubernetes/Docker security, IAM and access control, security tools (SAST, DAST, SIEM, vulnerability scanners), and CI/CD/DevSecOps practices
- Basic knowledge of network, application, and cloud security
- Preferred certifications: CEH, CompTIA Security+, or equivalent; CISSP Associate, GIAC, AWS/Azure Security certifications are advantageous
- Strong technical troubleshooting and problem-solving skills, good communication with technical and non-technical teams, and detail-oriented documentation skills
Eligibility
Due to government security clearance requirements for this role, only Singapore Citizens are eligible to apply.