Security Engineer

Fujitsu Careers

Singapore

On-site

SGD 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fujitsu is seeking a Security Engineer to lead end-to-end PAM, machine identity management, and 2FA deployments across enterprise environments in Singapore. You will implement CyberArk components, Venafi TLS Protect, and MFA solutions, while ensuring secure, scalable and compliant access controls.

You will collaborate with architects, project managers, and stakeholders to design, validate, and operationalize privileged access across on-prem and cloud environments, and drive migrations,

Qualifications

  • Strong hands-on deployment experience with CyberArk components (EPV/CPM/PSM/PVWA/PTA) and MFA solutions.
  • Experience integrating Venafi TLS Protect and machine identity management.
  • Familiarity with enterprise IAM, PAM, and zero-trust security principles.

Responsibilities

  • Lead CyberArk deployment and implementation across environments.
  • Install, configure, and harden CyberArk components and MFA integrations.
  • Perform migrations and upgrades of CyberArk environments (on-prem to on-prem/cloud/SaaS).
  • Onboard privileged accounts, systems and apps; configure password policies and RBAC.
  • Integrate CyberArk with SIEM, ITSM, IAM and security tools; enable audit logging.
  • Develop and document runbooks, SOPs, and operational procedures.
  • Provide L2/L3 support for PAM, Venafi and MFA platforms.
  • Coordinate with architects, PMs and stakeholders for secure, scalable solutions.
  • Support post-migration stabilization and user acceptance testing.

Skills

CyberArk deployment
CPM
PSM
PVWA
PTA
MFA integration
RSA/SecurEnvoy
Active Directory/LDAP
Scripting
Zero Trust

Job description

Location Flexibility: Primary Location Only

Posting Start Date: 8/6/26

The Security Engineer is mainly responsible for the end-to-end implementation, integration, and operationalization of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on deployment, migration, onboarding, and integration of privileged access controls, certificates, and machine identities in line with security best practices.

The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver secure, scalable, and compliant PAM, CLM and 2FA solutions.

Key Responsibilities
1. CyberArk Deployment & Implementation
  • Install, configure, and harden CyberArk components:
    • Enterprise Password Vault (EPV)
    • Central Policy Manager (CPM)
    • Privileged Session Manager (PSM)
    • Password Vault Web Access (PVWA)
    • Privileged Threat Analytics (PTA)
    • Privilege Cloud Connector
    • CyberArk Adaptive Multi-Factor Authentication (MFA)
    • CyberArk Vendor Privileged Access Manager (Vendor PAM)
  • Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo
  • Develop and Maintain PSM and CPM connectors
  • Infrastructure build
  • System validation and testing
  • Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing
2. Venafi Deployment & Machine Identity Management
  • Install, configure, and administer Venafi TLS Protect platform.
  • Design and document Venafi architecture.
  • Configure machine identity lifecycle management.
  • Implement:
    • Certificate discovery
    • Certificate inventory management
    • Certificate automation workflows
    • CA integrations
  • Enable:
    • Automated certificate issuance
    • Automated renewal
    • Certificate revocation processes
    • Self-service certificate requests
  • Configure network discovery and certificate intelligence capabilities.
  • Monitor certificate compliance and certificate expiry risks.
3. Migration & Upgrade Activities
  • Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)
  • Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)
  • Handle:
    • Vault data migration
    • Cutover planning and execution
  • Support post-migration stabilization and user acceptance testing
4. Account Onboarding & Policy Management
  • Onboard privileged accounts, systems, and applications into CyberArk
  • Configure:
    • Password policies
    • Rotation and reconciliation settings
    • Access controls and role-based permissions
  • Define and implement operational procedures (e.g., break-glass access, onboarding workflows)
5. Integration with Enterprise Systems
  • Integrate CyberArk with:
    • SIEM, ITSM, IAM platforms
    • Endpoint and network security tools
  • Enable session recording, monitoring, and audit logging across systems
6. Integration & Automation
  • Integrate CyberArk and Venafi with:
  • Active Directory / LDAP
  • SIEM platforms
  • Splunk
  • QRadar
  • ITSM platforms
  • ServiceNow
  • Identity and Access Management systems
  • Security monitoring platforms
  • Certificate Authorities
  • Microsoft CA
  • DigiCert
  • Entrust
  • GlobalSign
  • Support solution architects in:
    • Gathering requirements
    • Reviewing technical architecture
    • Conducting technical workshops and design validation
  • Contribute to architecture documentation and solution design reviews
8. Operations Readiness & Knowledge Transfer
  • Develop and document:
    • Runbooks
    • SOPs
    • Operational procedures
  • Conduct knowledge transfer sessions for operations teams
  • Ensure readiness for ongoing PAM operations and support
9. Troubleshooting & Support
  • Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues
  • Discovery issues
  • CA integration issues
  • Patch Management
  • Automation workflow failures
  • Perform root cause analysis for:
    • Access issues
    • Password rotation failures
    • Session management failures
  • Work with vendors and internal teams to resolve incidents
Technical Skill Requirements:
Mandatory
  • Strong hands-on deployment experience with:
  • EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy
  • Solid understanding of:
  • Active Directory / LDAP
  • Scripting
  • Knowledge in IAM, Security Best Practices and Zero Trust Methodologies
Preferred
  • Experience inlarge-scale enterprise deployments(500+ systems onboarding)
  • Venafi Machine Identity Management Certification
  • Familiarity with:
  • DevOps secrets (e.g., Conjur)
  • Strong Expertise in PSM and CPM connector developments
  • Experience with PKI and certificate lifecycle management
  • TLS Protect
  • Certificate Lifecycle Management
  • Discovery & Monitoring
  • Machine Identity Management
  • Certificate Authority Integrations
  • Venafi
  • TLS Protect
  • Certificate Lifecycle Management
  • Discovery & Monitoring
  • Machine Identity Management
  • Certificate Authority Integrations
  • Integration experience with:
  • Splunk / QRadar other SIEMs
  • ServiceNow
  • MFA solutions
  • Ability to lead technical workshops and discussions
  • Structured and documentation-driven mindset
  • Experience working in project-based delivery environments
Typical Deliverables
  • Migration and upgrade runbooks
  • SOPs and operational guides
  • Certificate discovery and automation setup
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Fujitsu • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Operations and Support Engineer (CyberArk)
Cybersecurity Operations and Support Engineer (CyberArk)

Ensign InfoSecurity • Singapore

Hybrid
SGD 90,000 - 130,000
Senior Cybersecurity Operations and Support Engineer
Senior Cybersecurity Operations and Support Engineer

Ensign InfoSecurity (Singapore) Pte. Ltd. • Singapore

On-site
SGD 60,000 - 90,000
SL2495 - Privileged Access Management Security Officer
SL2495 - Privileged Access Management Security Officer

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Senior Cybersecurity Operations and Support Engineer
Senior Cybersecurity Operations and Support Engineer

ensign infosecurity (cybersecurity) pte. ltd. • Singapore

Hybrid
SGD 85,000 - 120,000
Cybersecurity Architect
Cybersecurity Architect

WE-PLUS PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
Cybersecurity engineer
Cybersecurity engineer

TROYTECH INTERNATIONAL CONSULTING PTE LTD • Singapore

On-site
SGD 60,000 - 90,000
Cybersecurity Architect (Cyberark)
Cybersecurity Architect (Cyberark)

Sopra Steria • Singapore

Hybrid
SGD 120,000 - 170,000
Hybrid work
18 days annual leave
Health insurance
+1
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC First Campus • Singapore

On-site
SGD 90,000 - 130,000
Cyber Platform Engineer
Cyber Platform Engineer

V4 IMPACT PTE. LTD. • Singapore

On-site
SGD 110,000 - 170,000