Security Operations Engineer

RecruiterPal

Singapore

Hybrid

SGD 70,000 - 110,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive remuneration
Staggered working hours
Continuous learning opportunities

Job summary

YTL PowerSeraya Pte. Limited is seeking a Security Operations Engineer to join the Infrastructure Operations & Cyber Security team in Singapore.

The role focuses on security event investigation, endpoint protection, vulnerability management, security monitoring, and AI-assisted initiatives to enhance cyber resilience. The candidate will collaborate with internal teams, managed security providers, vendors, and stakeholders to strengthen security controls and continually improve the organisation's

Qualifications

  • Diploma or Degree in Information Technology, Cybersecurity, Computer Science, or a related discipline.
  • 4-6 years of experience in cybersecurity operations, infrastructure security, or a related technical security role.
  • Working knowledge of endpoint protection, EDR technologies, SIEM platforms, and security incident investigation processes.
  • Proficient in vulnerability management, remediation tracking, IOC validation, and security monitoring concepts.

Responsibilities

  • Investigate and follow up on security alerts, incidents, and suspicious activities escalated by the external SOC team across endpoints, servers, email, and cloud environments.
  • Assess security events, determine potential impact, gather relevant technical and business context, and coordinate containment, recovery, remediation, and closure activities.
  • Act as the internal coordination point between infrastructure teams, vendors, system owners, and external security providers during incident investigations.
  • Support security monitoring activities through SIEM dashboards, workbooks, queries, scheduled reporting, evidence collection, and case tracking.
  • Identify and promote practical AI-assisted use cases that improve operational consistency and security investigation effectiveness.

Skills

Security operations
Endpoint protection
EDR
SIEM
Vulnerability management
Threat intelligence
Cloud security
Incident investigation
AI-assisted security

Education

Degree in IT/Cybersecurity/CS
Diploma or equivalent

Tools

SIEM platforms
EDR technologies
Microsoft 365
Azure

Job description

  • Bachelor's Degree or equivalent | Diploma
  • Onsite
About Us

YTL PowerSeraya Pte. Limited, a wholly owned subsidiary of YTL Power International Berhad, is in the business of producing, wholesaling, trading and retailing of energy; with a primary focus on electricity. As an established player in Singapore's energy sector, it supplies the country's energy needs through its multi-utilities platform. With a licensed generation capacity of 3,100 MW*, it is one of Singapore's largest electricity generators.

The YTL PowerSeraya Group has three subsidiaries: the retail arm under the Geneco brand provides electricity price plans and energy solutions to homes and businesses, PetroSeraya is the fuel management arm of the Group, and Taser Power which operates Taser Power Plant.

Besides being a Plaque of Commendation (GOLD) awardee at the National Trade Union Congress's May Day Awards 2023, YTL PowerSeraya has adopted four Tripartite Standards under the Tripartite Alliance for Fair and Progressive Employment Practices, and has committed to be a fair and progressive employer. To find out more about the organisation, please visit ytlpowerseraya.com.

*As at 4 February 2026, our registered generating capacity with EMA is 2,487 MW.

Job Description

We are seeking a motivated and detail-oriented Security Operations Engineer to join our Infrastructure Operations & Cyber Security team. This role is responsible for supporting day-to-day security operations across Azure and on-premises environments, with a focus on security event investigation, endpoint protection, vulnerability management, security monitoring, and cyber awareness initiatives.

The successful candidate will work closely with internal technology teams, managed security service providers, vendors, and business stakeholders to investigate security events, improve cyber resilience, maintain operational security controls, and contribute to the continuous enhancement of the organisation's security posture.

KEY RESPONSIBILITIES

Security Engineering & Hardening

  • Support the implementation, maintenance, and continuous improvement of security controls across infrastructure and cloud environments.
  • Assist with onboarding and validating security log sources into approved SIEM platforms.
  • Support detection tuning, security configuration reviews, and monitoring improvements.
  • Evaluate and implement security technologies that strengthen the organisation's cyber defence capabilities.
  • Support the deployment and maintenance of security hardening standards across Windows, Linux, Microsoft 365, and Azure environments.
  • Ensure controls align with CIS Benchmarks and industry-recognised security best practices.

Vulnerability Management & Threat Advisory

  • Coordinate vulnerability assessment activities for critical infrastructure and servers.
  • Validate assessment findings and engage system owners to ensure timely remediation.
  • Monitor cybersecurity advisories, threat intelligence notifications, and indicators of compromise (IOCs).
  • Perform IOC validation activities and coordinate blacklisting, containment, investigation, and remediation actions where necessary.
  • Track, monitor, and report remediation progress until closure.

Security Operations & Incident Response

  • Investigate and follow up on security alerts, incidents, and suspicious activities escalated by the external SOC team across endpoints, servers, email, and cloud environments.
  • Assess security events, determine potential impact, gather relevant technical and business context, and coordinate containment, recovery, remediation, and closure activities.
  • Act as the internal coordination point between infrastructure teams, vendors, system owners, and external security providers during incident investigations.
  • Support security monitoring activities through SIEM dashboards, workbooks, queries, scheduled reporting, evidence collection, and case tracking.
  • Utilize approved AI-assisted tools to improve alert triage, investigation efficiency, log analysis, and case documentation in accordance with security and data-handling requirements.
  • Identify and promote practical AI-assisted use cases that improve operational consistency and security investigation effectiveness.

Endpoint Security & Platform Protection

  • Administer and support endpoint protection and Endpoint Detection & Response (EDR) platforms.
  • Monitor agent health, policy compliance, signature updates, asset coverage, and endpoint security status.
  • Perform endpoint troubleshooting, agent deployment, reinstallation, and remediation activities.
  • Support housekeeping activities to maintain security tool effectiveness and infrastructure visibility.

Security Awareness & User Engagement

  • Coordinate organisation-wide security awareness initiatives and phishing simulation campaigns.
  • Deliver targeted follow-up activities, awareness communications, and user education programs.
  • Monitor phishing resilience results and prepare reporting on participation rates, trends, and improvement opportunities.
  • Support broader cyber awareness initiatives including newsletters, learning modules, roadshows, and periodic security communications.

Governance, Documentation & Reporting

  • Maintain and update security policies, procedures, standards, technical documents, operational playbooks, and tracking records.
  • Support review and maintenance of incident response procedures, investigation workflows, hardening standards, endpoint security procedures, and operational documentation.
  • Prepare monthly and ad-hoc cyber security reports, dashboards, inventories, metrics, and compliance-related documentation.
  • Maintain accurate operational records to support management reporting, regulatory compliance, audits, and continuous improvement activities.
  • Support multiple operational and project-based initiatives while meeting established timelines and service expectations.
Qualifications
  • Diploma or Degree in Information Technology, Cybersecurity, Computer Science, or a related discipline.
  • 4-6 years of experience in cybersecurity operations, infrastructure security, or a related technical security role.
  • Working knowledge of endpoint protection, EDR technologies, SIEM platforms, and security incident investigation processes.
  • Proficient in vulnerability management, remediation tracking, IOC validation, and security monitoring concepts.
  • Proficient knowledge for Windows, Linux, Microsoft 365, Azure, and general cloud security principles.
  • Understanding of security awareness programs, phishing simulations, malware investigation, and security documentation practices.
  • Exposure to open-source security monitoring or cyber defence tools will be advantageous.
  • Professional certifications such as ISC2 CC, CompTIA Security+, Microsoft SC-200, CEH, CHFI, or similar certifications will be advantageous.

We do not expect candidates to be AI specialists. We are looking for security professionals who are curious about responsible AI usage and able to leverage modern technologies to improve cyber defence operations.

  • Familiarity with AI-assisted security operations, threat detection, log analysis, and incident investigation use cases.
  • Ability to evaluate and validate AI-assisted outputs while maintaining human oversight and professional judgement.
  • Understanding of responsible AI principles including privacy, security, transparency, and appropriate handling of sensitive information.
  • Interest in emerging cybersecurity technologies, attack techniques, threat intelligence, and cyber defence innovation.
  • Continuous learning mindset with a willingness to explore new tools, methodologies, and automation opportunities.
Other Information

WHAT WE OFFER

  • Opportunity to work in a critical cyber security function supporting enterprise infrastructure and operational resilience.
  • Hands-on exposure to cloud security, security operations, threat investigation, vulnerability management, and cyber defence technologies.
  • Access to continuous learning and professional development opportunities in cybersecurity, cloud technologies, AI, and emerging security domains.
  • Opportunity to work alongside experienced cybersecurity and infrastructure professionals in a collaborative environment.
  • Competitive remuneration package commensurate with experience.
  • Staggered working hours and a culture that values innovation, security, teamwork, and continuous improvement.

At YTL PowerSeraya, our people are driven to shape their career and future, and we pave the way to help them get to where they want to be. We seek to develop our people and help transform their potential into performance. Join our team and work with people who are as passionate in shaping the future as you are.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Engineer
Security Operations Engineer

HYPERSCAL SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 110,000 - 150,000
Competitive remuneration
Continuous learning opportunities
Staggered working hours
+1
Security Operations Engineer - Cloud & Endpoint Protection
Security Operations Engineer - Cloud & Endpoint Protection

RecruiterPal • Singapore

Hybrid
SGD 70,000 - 110,000
Competitive remuneration
Staggered working hours
Continuous learning opportunities
Security Engineer
Security Engineer

NCS • Singapore

On-site
SGD 90,000 - 150,000
Enterprise Security Engineer
Enterprise Security Engineer

Mediacorp Pte. Ltd. • Singapore

On-site
SGD 120,000 - 180,000
Security Operations Engineer: Cloud & Incident Response
Security Operations Engineer: Cloud & Incident Response

HYPERSCAL SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 110,000 - 150,000
Competitive remuneration
Continuous learning opportunities
Staggered working hours
+1
Security Engineer
Security Engineer

NCS Group • Singapore

On-site
SGD 60,000 - 90,000
Security Engineer
Security Engineer

Tap Growth ai • Singapore

On-site
SGD 90,000 - 140,000
Security Engineer (Yearly Contract Renewal)
Security Engineer (Yearly Contract Renewal)

NCS Group • Singapore

On-site
SGD 90,000 - 130,000
IT Security Engineer
IT Security Engineer

COLD STORAGE SINGAPORE (1983) PTE LTD • Singapore

On-site
SGD 90,000 - 130,000
Assistant Shift Charge Engineer
Assistant Shift Charge Engineer

HYPERSCAL SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 58,000 - 85,000