Security Engineer

Fujitsu

Singapore

On-site

SGD 120,000 - 180,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fujitsu Singapore is seeking a Security Engineer to lead end-to-end CyberArk PAM and Venafi implementations across enterprise environments. You will deploy, migrate, and integrate privileged access controls and machine identities, working with architects and stakeholders.

The role emphasizes secure, scalable, compliant solutions, with on-prem and cloud components, and requires hands-on deployment experience and strong collaboration.

Qualifications

  • CyberArk CDE-PAM or Privilege Cloud certification is required.
  • Hands-on deployment experience with EPV, CPM, PSM, PVWA, PTA.
  • Strong knowledge of Windows Server and Linux (RHEL).
  • Experience with AD/LDAP authentication and network fundamentals.
  • Experience integrating IAM, SIEM, and ITSM platforms.

Responsibilities

  • Lead CyberArk deployment build, vault and connector setup.
  • Install, configure, and harden CyberArk components.
  • Deploy and configure 2FA platforms (RSA, SecurEnvoy, Cisco Duo).
  • Design Venafi architecture and machine identity management.
  • Migrate and upgrade CyberArk environments (on-prem to on-prem / cloud / SaaS).
  • Onboard privileged accounts and define rotation policies.
  • Integrate with Active Directory / LDAP and SIEM/ITSM tools.
  • Provide L2/L3 support and troubleshoot certificate lifecycle issues.
  • Create runbooks, SOPs, and knowledge transfer sessions.
  • Ensure compliance with security best practices and zero trust.

Skills

CyberArk deployment
PAM (Privileged Access Management)
MFA integration
Windows & Linux
AD / LDAP
Networking basics

Tools

Venafi TLS Protect
RSA Authentication Manager
SecurEnvoy
Cisco Duo
Active Directory
PVWA / EPV / CPM / PSM

Job description

  • Certificate revocation processes
  • Password policies
  • Networking (firewalls, ports, VPN)

Job Location: Singapore

Location Flexibility: Primary Location Only

The Security Engineer is mainly responsible for the end-to-end implementation, integration, and operationalization of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on deployment, migration, onboarding, and integration of privileged access controls, certificates, and machine identities in line with security best practices.

The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver secure, scalable, and compliant PAM, CLM and 2FA solutions.

Key Responsibilities
  • CyberArk Deployment & Implementation
  • Install, configure, and harden CyberArk components:
    • Enterprise Password Vault (EPV)
    • Central Policy Manager (CPM)
    • Privileged Session Manager (PSM)
    • Password Vault Web Access (PVWA)
    • Privileged Threat Analytics (PTA)
    • Privilege Cloud Connector
    • CyberArk Adaptive Multi-Factor Authentication (MFA)
    • CyberArk Vendor Privileged Access Manager (Vendor PAM)
  • Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo
  • Develop and Maintain PSM and CPM connectors
  • Execute full-cycle deployment activities:
    • Infrastructure build
    • Installation & configuration
    • System validation and testing
  • Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing
  • Venafi Deployment & Machine Identity Management
  • Install, configure, and administer Venafi TLS Protect platform.
  • Design and document Venafi architecture.
  • Configure machine identity lifecycle management.
  • Implement:
    • Certificate discovery
    • Certificate inventory management
    • Certificate automation workflows
    • CA integrations
  • Enable:
    • Automated certificate issuance
    • Automated renewal
    • Certificate revocation processes
    • Self-service certificate requests
  • Configure network discovery and certificate intelligence capabilities.
  • Monitor certificate compliance and certificate expiry risks.
  • Migration & Upgrade Activities
  • Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)
  • Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)
  • Handle:
    • Vault data migration
    • Cutover planning and execution
  • Support post-migration stabilization and user acceptance testing
  • Account Onboarding & Policy Management
  • Onboard privileged accounts, systems, and applications into CyberArk
  • Configure:
    • Password policies
    • Rotation and reconciliation settings
    • Access controls and role-based permissions
  • Define and implement operational procedures (e.g., break-glass access, onboarding workflows)
  • Integration with Enterprise Systems
  • Integrate CyberArk with:
    • SIEM, ITSM, IAM platforms
    • Endpoint and network security tools
  • Enable session recording, monitoring, and audit logging across systems
  • Integration & Automation
  • Integrate CyberArk and Venafi with:
    • Active Directory / LDAP
    • Entra ID
    • SIEM platforms
    • Splunk
    • QRadar
    • ITSM platforms
    • ServiceNow
    • Identity and Access Management systems
    • Security monitoring platforms
    • Certificate Authorities
    • Microsoft CA
    • DigiCert
    • Entrust
    • GlobalSign
  • PAM Architecture & Design Support
  • Support solution architects in:
    • Gathering requirements
    • Reviewing technical architecture
    • Conducting technical workshops and design validation
  • Contribute to architecture documentation and solution design reviews
  • Operations Readiness & Knowledge Transfer
  • Develop and document:
    • Runbooks
    • SOPs
    • Operational procedures
  • Conduct knowledge transfer sessions for operations teams
  • Ensure readiness for ongoing PAM operations and support
  • Troubleshooting & Support
  • Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues
  • Certificate lifecycle failures
  • Discovery issues
  • Renewal failures
  • CA integration issues
  • Patch Management
  • Automation workflow failures
  • Perform root cause analysis for:
    • Access issues
    • Password rotation failures
    • Session management failures
  • Work with vendors and internal teams to resolve incidents
Technical Skill Requirements
Mandatory
  • CyberArk Certified Delivery Engineer (CDE-PAM / Privilege Cloud)
  • Strong hands-on deployment experience with:
    • EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy
  • Solid understanding of:
    • Windows Server & Linux (RHEL)
    • Active Directory / LDAP
    • Networking (firewalls, ports, VPN)
    • Scripting
  • Knowledge in IAM, Security Best Practices and Zero Trust Methodologies
Preferred
  • Experience in large-scale enterprise deployments (500+ systems onboarding)
  • Venafi TLS Protect Certification
  • Venafi Machine Identity Management Certification
  • Familiarity with:
    • DevOps secrets (e.g., Conjur)
    • Cloud PAM (CyberArk Privilege Cloud)
    • Strong Expertise in PSM and CPM connector developments
    • Experience with PKI and certificate lifecycle management
    • TLS Protect
    • Certificate Lifecycle Management
    • Discovery & Monitoring
    • Machine Identity Management
    • Certificate Authority Integrations
    • Venafi
    • TLS Protect
    • Certificate Lifecycle Management
    • Discovery & Monitoring
    • Machine Identity Management
    • Certificate Authority Integrations
    • Integration experience with:
      • Splunk / QRadar other SIEMs
      • ServiceNow
      • MFA solutions
Soft Skills & Competencies
  • Strong stakeholder engagement & communication skills
  • Ability to lead technical workshops and discussions
  • Structured and documentation-driven mindset
  • Experience working in project-based delivery environments
Typical Deliverables
  • CyberArk deployment build (Vault, CPM, PSM, PVWA, PTA, CyberArk Cloud, Vendor PAM, MFA)
  • Migration and upgrade runbooks
  • System onboarding documentation
  • SOPs and operational guides
  • Integration configuration documents
  • Venafi TLS Protect implementation.
  • Certificate discovery and automation setup

Relocation Supported: No

Visa Sponsorship Approved: No

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyberark - Implementation
Cyberark - Implementation

Helius Technologies Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

Hybrid
SGD 60,000 - 90,000
Cybersecurity Operations and Support Engineer (CyberArk)
Cybersecurity Operations and Support Engineer (CyberArk)

Ensign InfoSecurity • Singapore

Hybrid
SGD 90,000 - 130,000
Senior Cybersecurity Operations and Support Engineer
Senior Cybersecurity Operations and Support Engineer

ensign infosecurity (cybersecurity) pte. ltd. • Singapore

Hybrid
SGD 85,000 - 120,000
Cybersecurity Architect
Cybersecurity Architect

We+ • Singapore

On-site
SGD 180,000 - 240,000
Privileged Access Management Technical Support Lead (VP)
Privileged Access Management Technical Support Lead (VP)

OCBC Bank • Singapore

On-site
SGD 120,000 - 160,000
Competitive base salary
Flexible benefits
Industry-leading learning opportunities
+1
Cyber Security operation
Cyber Security operation

RAPSYS TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 110,000 - 170,000
Cybersecurity Architect - CyberArk (IAM/Production)
Cybersecurity Architect - CyberArk (IAM/Production)

Newtone consulting • Singapore

On-site
SGD 180,000 - 260,000
Cybersecurity Architect
Cybersecurity Architect

WE-PLUS PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
IAM Production-Cybersecurity Architect - CyberArk
IAM Production-Cybersecurity Architect - CyberArk

MIGSO-PCUBED • Singapore

On-site
SGD 180,000 - 260,000