IT Security Engineer (Hybrid: On-Prem & Azure Cloud)

SHAW SERVICES (PTE) LIMITED.

Singapore

On-site

SGD 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

SHAW SERVICES (PTE) LIMITED. in Singapore seeks a versatile Security Engineer to safeguard a hybrid IT landscape, bridging on-premise infrastructure and cloud security.

You will lead the technical efforts to ensure resilience and PCI-DSS compliance across environments. Responsibilities include firewall design and policy management, IAM governance with Cisco ISE, vulnerability management, and real-time security monitoring using Wazuh/Graylog.

Qualifications

  • 3–5 years of hands-on IT security experience across hardware and cloud environments.
  • Deep expertise in at least two firewalls (SonicWall, Palo Alto, Cisco ASA).
  • Proven knowledge of Cisco ISE, Wazuh, or Graylog.
  • Strong Microsoft Azure security knowledge (Identity, Networking, and Security tools).
  • Experience with PCI-DSS compliance and security audits.

Responsibilities

  • Design, deploy, and maintain firewall policies across multiple vendors.
  • Manage IAM via SonicWall NMS/GMS and Cisco ISE.
  • Perform vulnerability scans with OpenVAS and remediate risks.
  • Lead security monitoring using Wazuh and Graylog for real-time incident response.
  • Govern Azure security including Defender for Cloud, Azure Firewalls, NSGs, and Key Vaults.
  • Implement IaC security within Azure DevOps pipeline.
  • Oversee biometric (Biostar) and CCTV systems, and access controls.
  • Drive PCI-DSS compliance and support security audits.

Skills

Firewall expertise
Azure security
DevSecOps
PCI-DSS compliance
CCTV security
Biometric integration
Wazuh
Graylog
Cisco ISE

Education

AZ-500
PCNSE
CISSP/CISM

Tools

Cisco ISE
Wazuh
Graylog

Job description

Role Purpose: We are seeking a versatile Security Engineer to safeguard our organization's digital and physical assets. This role is unique-you will bridge the gap between on-premise infrastructure (Firewalls, Biometrics CCTV) and Cloud Security (Azure, DevSec Ops). You will be the technical lead in ensuring our hybrid environment is resilient against threats and compliant with international standards like PCI-DSS.

Key Responsibilities
  1. Hybrid Infrastructure & Network Security
    • Next-Gen Firewall Management: Design, deploy, and maintain robust firewall policies across SonicWall, Palo Alto, Cisco ASA, and Fortinet environments.
    • Network Governance: Manage SonicWall NMS/GMS and administer Cisco ISE to ensure strict Identity and Access Management (IAM).
    • Vulnerability Management: Execute regular scans via OpenVAS , prioritizing and remediating risks across the internal network.
    • Security Monitoring: Lead threat detection efforts by analyzing logs through Wazuh and Graylog to identify and respond to incidents in real-time.
  2. Cloud Security & DevSecOps (Microsoft Azure)
    • Cloud Governance: Manage and optimize Microsoft Defender for Cloud to maintain a strong security posture (CSPM).
    • Azure Security Engineering: Configure Azure Firewalls, NSGs, and Key Vaults to protect cloud-native workloads.
    • Infrastructure as Code (IaC) Security: Design and implement security guardrails within the Azure DevOps pipeline (DevSecOps), ensuring code is scanned before deployment.
  3. Physical Security & Compliance
    • Integrated Physical Security: Oversee the technical maintenance of Biostar biometric systems , CCTV networks, and TZ server rack access controls.
    • Audit Leadership: Serve as the primary technical point of contact for security audits, specifically driving PCI-DSS compliance and internal risk assessments.
Required Experience & Qualifications
  • Experience: Minimum 3-5 years of hands-on experience in IT Security, covering both hardware and cloud environments
  • Technical Proficiency:
    • Firewalls: Deep expertise in at least two of the following: SonicWall, Palo Alto, or Cisco ASA.
    • On-Prem Tools: Proven knowledge with Cisco ISE, Wazuh, or Graylog.
    • Cloud: Strong working knowledge of Microsoft Azure (Identity, Networking, and Security tools).
    • DevSecOps : Good to have knowledge on Security Scans such as Dependency Scanning, Secrets Scanning, Code Security scanning.
    • Compliance: Practical experience in preparing documentation and technical controls for PCI-DSS.
    • Physical Security: Familiarity with biometric integration (Biostar) and CCTV infrastructure.
  • Certification(Bonus): AZ-500 (AzureSecurity Engineer), PCNSE, or CISSP/CISM.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Operations
IT Security Operations

U3 INFOTECH PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer (Contract)
Security Engineer (Contract)

CHARTERHOUSE PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer (Contract)
Security Engineer (Contract)

Charterhouse Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Security Architect and Engineering Lead
Security Architect and Engineering Lead

Kerry Consulting • Singapore

On-site
SGD 180,000 - 320,000
Network Security Manager
Network Security Manager

Good co India • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Engineer * (AMK)
Cybersecurity Engineer * (AMK)

MAESTRO HUMAN RESOURCE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
Senior Security Infrastructure Engineer (IT Security Lead)
Senior Security Infrastructure Engineer (IT Security Lead)

sagl consulting pte. ltd. • Singapore

On-site
SGD 180,000 - 240,000
Security Engineer
Security Engineer

NETS • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Consultant, Network Security (Contract)
Cybersecurity Consultant, Network Security (Contract)

Singtel Group • Singapore

On-site
SGD 75,000 - 95,000
Senior Lead Cybersecurity Engineer
Senior Lead Cybersecurity Engineer

CHARTERHOUSE PTE. LTD. • Singapore

On-site
SGD 150,000 - 190,000