IT Security Engineer

MINDTECK SINGAPORE PTE LTD

Singapore

On-site

SGD 60,000 - 120,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mindteck Singapore Pte Ltd is seeking an IT Security Engineer to implement, operate, and support security controls for mission-critical systems in a secure environment. The role spans Day 1 project security and Day 2 operations security, collaborating with Security Leads, Infra, System, and Software teams to meet government security policies.

The incumbent will contribute to security architecture, threat modelling, vulnerability management, and CI/CD security, ensuring robust incident response,

Qualifications

  • Degree in Computer Science / Cybersecurity / Information Security or equivalent
  • 3-7 years of IT experience in cybersecurity or infrastructure security
  • Experience supporting security in projects or production environments
  • Familiarity with Singapore Government security policies (IM8 preferred)
  • Hands-on experience with Kubernetes / Docker security
  • IAM and access control
  • Security tools (SAST, DAST, SIEM, vulnerability scanners)
  • CI/CD and DevSecOps practices
  • Basic knowledge of network security, application security, and cloud security
  • CEH, CompTIA Security+, or equivalent
  • Other certifications (e.g., CISSP Associate, GIAC, AWS/Azure Security) advantageous

Responsibilities

  • Security Implementation & Engineering: implement security architecture and controls as designed by Security Leads/Architects
  • Support system, application, and infrastructure security configurations
  • Assist in threat modelling and risk assessment activities
  • Translate security requirements into technical implementation across platforms
  • Compliance Support: assist with IM8, WOG security requirements, and PDPA
  • Prepare documentation for Security Risk Assessments, Vulnerability Assessments, and Penetration Testing
  • Maintain security documentation and evidence for audits
  • DevSecOps & Secure Development: implement and maintain security tools in CI/CD pipelines (SAST, DAST, SCA, container scanning)
  • Monitor findings and work with developers on remediation
  • Support secure coding practices and DevSecOps adoption
  • Assist in API security, secrets management, and secure communications setup
  • Security Testing Support: coordinate VA/PT activities and track remediation
  • Document findings and closure evidence for certification/go-live
  • System & Platform Hardening: harden operating systems, middleware, databases, Kubernetes, containers
  • Configure API Gateways, WAF, and authentication/authorization mechanisms (OAuth2, mTLS)
  • Incident Response: investigate, contain, remediate security incidents; perform RCA
  • Vulnerability & Patch Management: regular scans, patch tracking, remediation
  • Security Monitoring: monitor SIEM alerts; tune rules and dashboards
  • Audit & Compliance Support: evidence collection and remediation tracking
  • Access Control Administration: RBAC, MFA, PAM; perform least-privilege reviews

Education

Bachelor's degree in Computer Science / Cybersecurity / Information Security or equivalent

Tools

Kubernetes
Docker
IAM and access control
SAST/DAST/SIEM
CI/CD / DevSecOps
Vulnerability scanners
Cloud security basics

Job description

Singaporean only

Role Overview

The IT Security Engineer will be responsible for implementing, operating, and supporting security controls for mission-critical systems within a secured environment.

This role covers both:

  • Day 1 Security (Build / Project Implementation)
  • Day 2 Security (Operations / Production Support)

The Security Engineer will work closely with Security Leads, Infra, System, and Software teams to ensure compliance with government security policies and standards.

Key Responsibilities
Day 1 - Project / Implementation Security
  1. Security Implementation & Engineering
    1. Implement security architecture and controls as designed by Security Leads/Architects
    2. Support system, application, and infrastructure security configurations
    3. Assist in threat modelling and risk assessment activities
    4. Translate security requirements into technical implementation across platforms
  2. Compliance Support
    1. Support compliance with:
      1. IM8 / Government security policies
      2. Whole-of-Government (WOG) security requirements
      3. PDPA (where applicable)
    2. Assist in preparation and documentation for:
      1. Security Risk Assessments (SRA)
      2. Vulnerability Assessments (VA)
      3. Penetration Testing (PT)
    3. Maintain security documentation and evidence for audits
  3. DevSecOps & Secure Development
    1. Implement and maintain security tools in CI/CD pipelines: SAST, DAST, SCA, container scanning
    2. Monitor and triage findings, and work with developers on remediation
    3. Support secure coding practices and DevSecOps adoption
    4. Assist in API security, secrets management, and secure communications setup
  4. Security Testing Support
    1. Support coordination and execution of VA/PT activities
    2. Track vulnerabilities and ensure timely remediation
    3. Assist in documenting findings and closure evidence
    4. Support system security certification and go-live requirements
  5. System & Platform Hardening
    1. Implement and maintain security hardening for:
      1. Operating systems
      2. Middleware and databases
      3. Kubernetes and containers (RBAC, secrets, network policies)
    2. Support configuration of:
      1. API Gateways
      2. WAF
      3. Authentication and authorization mechanisms (OAuth2, mTLS)
Day 2 - Operations / Production Security
  1. Incident Response
    1. Support investigation, containment, and remediation of security incidents
    2. Perform log analysis and assist in root cause analysis (RCA)
    3. Work with SOC and internal teams during incidents
    4. Follow and improve incident response playbooks
  2. Vulnerability & Patch Management
    1. Perform regular vulnerability scans and monitoring
    2. Track and verify patching and remediation activities
    3. Escalate high-risk vulnerabilities and propose mitigation controls
  3. Security Monitoring
    1. Monitor alerts from SIEM and security tools
    2. Assist in tuning detection rules and dashboards
    3. Ensure logging and monitoring coverage across systems
  4. Audit & Compliance Support
    1. Support audit preparation, evidence collection, and remediation tracking
    2. Maintain security records and documentation
    3. Assist in reporting security posture and issues
  5. Access Control Administration
    1. Support implementation of:
      1. RBAC
      2. MFA
      3. Privileged Access Management (PAM)
    2. Perform user access reviews and ensure least privilege
Required Qualifications & Experience

Mandatory

  • Degree in Computer Science / Cybersecurity / Information Security or equivalent
  • 3-7 years of IT experience in cybersecurity or infrastructure security
  • Experience supporting security in projects or production environments
  • Familiarity with Singapore Government security policies (IM8 preferred)
  • Hands-on experience with:
    1. Kubernetes / Docker security
    2. IAM and access control
    3. Security tools (SAST, DAST, SIEM, vulnerability scanners)
    4. CI/CD and DevSecOps practices
    5. Basic knowledge of network security, application security, and cloud security
Preferred Certifications
  • CEH, CompTIA Security+, or equivalent
  • Other certifications (e.g., CISSP Associate, GIAC, AWS/Azure Security) are advantageous
Key Competencies
  • Strong technical troubleshooting and problem-solving skills
  • Ability to follow security standards and implement controls effectively
  • Good communication skills with technical and non-technical teams
  • Detail-oriented with strong documentation skills
  • Collaborative team player with willingness to learn
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Security Engineer
Information Technology Security Engineer

Newtone consulting • Singapore

On-site
SGD 60,000 - 110,000
IT Security Engineer
IT Security Engineer

COLD STORAGE SINGAPORE (1983) PTE LTD • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Engineer – Security Operations & Vulnerability Management
Cybersecurity Engineer – Security Operations & Vulnerability Management

MTS GLOBAL PTE. LTD. • Singapore

On-site
Cyber Security Consultant
Cyber Security Consultant

INFINITE COMPUTER SOLUTIONS PTE LTD • Singapore

On-site
SGD 90,000 - 130,000
IT Security Lead
IT Security Lead

Ensoft Consulting Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
Cybersecurity Engineer | Hybrid (Singapore)
Cybersecurity Engineer | Hybrid (Singapore)

MRL Consulting Group Ltd. • Singapore

Hybrid
SGD 70,000 - 90,000
Security Engineer
Security Engineer

Beecruit Pte Ltd • Singapore

On-site
SGD 60,000 - 80,000
Cyber Security Engineer (Jurong Island)
Cyber Security Engineer (Jurong Island)

KMC O&M PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer
Security Engineer

HYPERSCAL SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Cyber Security Resident Engineer
Cyber Security Resident Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 100,000