Senior Security Engineer

Webot

Singapore

On-site

SGD 180,000 - 240,000

Full time

12 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Webot is seeking a Workplace Security Engineer to design and implement security controls across identity, endpoint, network access, and data protection. You will be the technical owner for key security platforms and collaborate with IT, Cloud, and Compliance teams to meet financial industry security requirements.

You will own secure identity architecture, enable robust SSO, manage remote access, enforce endpoint baselines, and drive data protection and vulnerability governance across the

Qualifications

  • 5+ years in security engineering / IT security with hands-on implementation experience.
  • Proficient in Python, Go, or PowerShell/Bash with a track record of building tools or automation.
  • Solid understanding of RESTful APIs, JSON/YAML processing, and Git.
  • Experience with Infrastructure as Code (Terraform) applied to security architecture is a strong plus.
  • Deep experience in at least two of the following: IAM/SSO, Endpoint security, Zero Trust / VPN / SASE, strong troubleshooting skills, audits.

Responsibilities

  • Own secure identity architecture across Google Workspace and AWS IAM Identity Center; design group/role models and access governance.
  • Improve SSO posture, MFA enforcement, and conditional access patterns; onboard new SaaS apps into SSO.
  • Own and optimize remote access and ZTNA/SASE through Prisma Access/GlobalProtect etc.; work with network teams on policy design.
  • Define endpoint security baselines and compliance via Jamf Pro, ABM, Google Endpoint Management, Cortex XDR.
  • Design and tune data protection controls via Google Workspace DLP and Prisma Cloud DLP; create data classification patterns.
  • Own vulnerability scanning results triage, risk rating, remediation tracking, and verification.
  • Improve alerting quality and detection coverage; lead incident investigations and post-incident improvements.
  • Design, develop, and maintain security tools and automation to bridge security platforms.

Skills

Security engineering
Python
Go
Git
REST APIs
Terraform

Tools

Jamf Pro
Cortex XDR
Google Workspace admin
Prisma Access

Job description

We are looking for a Workplace Security Engineer to design, implement, and continuously improve corporate security controls across identity, endpoint, network access (VPN/ZTNA), and data protection. You will be the technical owner for key security platforms and work with IT, Cloud, and Compliance teams to meet financial industry security requirements.

Key Responsibilities
1) Identity & Access Engineering
  • Own secure identity architecture across Google Workspace and AWS IAM Identity Center:
  • Design group/role models, least privilege, and access governance processes.
  • Improve SSO posture (SAML/OAuth), session policies, MFA enforcement, conditional access patterns where applicable.
  • Lead onboarding of new SaaS apps into SSO and define standard patterns (SAML attributes, role mapping, break-glass access).
2) Zero Trust / Remote Access Engineering
  • Own and optimize enterprise remote access and ZTNA/SASE through: Prisma Access / GlobalProtect; Prisma ZTNA / Prisma SASE; Google BeyondCorp (where applicable)
  • Work with network teams on policy design, segmentation, and logging requirements.
3) Endpoint Security Engineering
  • Define and enforce endpoint security baselines and compliance through: Jamf Pro + Apple Business Manager; Google Endpoint Management; Palo Alto Cortex XDR
  • Drive improvements in device posture: encryption, OS baseline, EDR coverage, hardening, local admin controls.
4) Data Security & DLP Engineering
  • Design and tune data protection controls through: Google Workspace DLP, Prisma Cloud DLP
  • Define data classification patterns, DLP rules/exception workflows, and measurable reduction in risky exfiltration events.
5) Vulnerability & Patch Governance
  • Own vulnerability scanning results triage, risk rating, remediation tracking, and verification.
  • Define patch SLAs, exception workflows, and reporting; coordinate with IT/Ops/R&D teams (execution may be performed by owning teams).
6) Security Monitoring, Incident Response & Continuous Improvement
  • Improve alerting quality and detection coverage across IAM/endpoint/network/DLP telemetry.
  • Lead investigations for escalated incidents, produce incident reports and post-incident improvements (runbooks, control changes).
7) Security Automation & Tooling
  • Design, develop, and maintain custom security tools, scripts, and API integrations to bridge gaps between disparate security platforms.
  • Automate routine engineering tasks, compliance checks, and incident response workflows using SOAR tools or custom code (Python/Go).
8) Documentation & Audit Readiness
  • Build security standards, runbooks, and audit evidence pipelines for access control, remote access, endpoint protection, and DLP.
Qualifications
  • 5+ years in security engineering / IT security with strong hands-on implementation experience.
  • - Proficient in at least one programming/scripting language (Python, Go, or PowerShell/Bash) with a track record of building tools or automation.
  • Solid understanding of RESTful APIs, JSON/YAML processing, and version control systems (Git).
  • Experience with Infrastructure as Code (Terraform) applied to security architecture is a strong plus.
  • Deep experience in at least two of the following:

-- IAM/SSO (Google Workspace / AWS IAM Identity Center, SAML/OAuth)

-- Endpoint security (Jamf/ABM, EDR—Cortex XDR)

-- Zero Trust / VPN / SASE (Prisma Access/GlobalProtect, Prisma ZTNA/SASE, BeyondCorp)

-- Strong troubleshooting skills across Windows/macOS, and solid networking fundamentals.

-- Experience supporting audits and producing evidence in regulated environments is a strong plus.

Nice to Have
  • Scripting/automation (Python, Bash), IaC mindset, good operational excellence.
  • Relevant certs: Palo Alto (PCNSA/PCNSE), Jamf certs, Google Workspace admin, AWS security.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

NETS • Singapore

On-site
SGD 90,000 - 130,000
Security Engineer, Enterprise SaaS Security - Singapore
Security Engineer, Enterprise SaaS Security - Singapore

GOOGLE ASIA PACIFIC PTE. LTD. • Singapore

On-site
SGD 120,000 - 170,000
Staff Product Security Engineer
Staff Product Security Engineer

Airwallex • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer (Contract)
Security Engineer (Contract)

CHARTERHOUSE PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Security Automation Engineer
Security Automation Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 42,000 - 66,000
Security Operations Engineer (2 Year Contract)
Security Operations Engineer (2 Year Contract)

MORGAN MCKINLEY PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer (Cybersecurity Engineer) - #1598
IT Security Officer (Cybersecurity Engineer) - #1598

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 90,000 - 120,000
Network Security Manager
Network Security Manager

Good co India • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Consultant, Network Security (Contract)
Cybersecurity Consultant, Network Security (Contract)

Singtel Group • Singapore

On-site
SGD 75,000 - 95,000
Senior Security Engineer, Trust and Safety Workspace - Singapore
Senior Security Engineer, Trust and Safety Workspace - Singapore

GOOGLE ASIA PACIFIC PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000