Workspace Security Engineer (AVP/VP)

OCBC (Singapore)

Singapore

On-site

SGD 120,000 - 180,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive base salary
Learning & development opportunities

Job summary

OCBC Bank in Singapore seeks an experienced Workspace Security Engineer to strengthen security across Microsoft endpoint and modern workplace technologies. You will own security policy engineering, design, automation, and control assurance within an enterprise environment.

The role offers growth from a strong Microsoft and EUC foundation into broader workspace security ownership, collaborating with diverse teams to implement robust security controls and monitoring.

Qualifications

  • Approximately 8+ years of EUC/endpoint engineering or cybersecurity in enterprise environments.
  • Strong hands-on experience with Microsoft Intune, Microsoft 365, Entra ID/Azure AD, Active Directory, Group Policy, device compliance, and Conditional Access.

Responsibilities

  • Engineer Microsoft endpoint and modern workplace security policies, configurations, and controls.
  • Contribute to the workspace security roadmap and evolve endpoint security capabilities.
  • Translate requirements into practical policy designs, configurations, and engineering solutions.
  • Configure and enhance security across Intune, M365, Entra ID, and endpoint-management services.
  • Engineer and improve security baselines, attack-surface reduction, and vulnerability remediation.
  • Evaluate new Microsoft security features and develop implementation plans.
  • Define security configuration standards, guardrails, and exception requirements.
  • Develop monitoring and reporting for policy deployment and compliance.
  • Use PowerShell and scripting to improve configuration management and reporting.
  • Investigate complex endpoint-security issues and develop remediation.
  • Produce engineering documentation and operating procedures.
  • Collaborate with stakeholders to deliver workspace security controls.
  • Share reusable engineering practices across the team.

Skills

EUC / endpoint engineering
Microsoft Intune
Azure AD / Entra ID
Policy engineering
Automation / PowerShell
Endpoint security
Documentation

Tools

Microsoft Intune
Microsoft 365
Entra ID / Azure AD
Active Directory
Group Policy
Conditional Access
PowerShell
Microsoft Graph APIs

Job description

WHO WE ARE:

As Singapore's longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

Today, we're on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia's leading financial services partner for a sustainable future.

We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.

Why Join

Protecting our customers' assets and data is at the heart of everything we do at OCBC. As a Cyber Engineering - Risk professional, you'll play a critical role in safeguarding our systems and networks from cyber threats. You'll be part of a team that's shaping the future of cybersecurity in the financial industry.

How you succeed

We are looking for a hands-on Workspace Security Engineer to strengthen our security engineering capability across Microsoft endpoint and modern workplace technologies. This role is suited to an experienced EUC or modern workplace engineer who understands the Microsoft ecosystem and is ready to take deeper ownership of security policy engineering, solution design, automation, and control assurance.

The successful candidate will help shape secure endpoint solutions, translate security requirements into practical configurations, evaluate new capabilities, and develop the standards and monitoring needed to protect enterprise user-computing environments. The role offers the opportunity to grow from a strong Microsoft and EUC foundation into broader workspace security engineering ownership.

What you do
  • Engineer Microsoft endpoint and modern workplace security policies, configurations, and technical controls.
  • Contribute to the workspace security solution roadmap and the continued evolution of endpoint security capabilities.
  • Translate security requirements and control gaps into practical policy designs, configuration changes, and engineering solutions.
  • Configure and enhance security capabilities across Microsoft Intune, Microsoft 365, Entra ID, Conditional Access, device compliance, and endpoint-management services.
  • Engineer and improve security baselines, endpoint protection, attack-surface reduction, application control, device control, vulnerability remediation, and endpoint telemetry.
  • Evaluate new Microsoft security features and develop recommendations, test plans, and implementation approaches for their adoption.
  • Define security configuration standards, reference settings, technical guardrails, and exception requirements.
  • Develop monitoring and reporting capabilities for policy deployment, configuration compliance, control coverage, exceptions, and security effectiveness.
  • Use PowerShell, Microsoft Graph APIs, scripting, and automation to improve configuration management, validation, evidence collection, and reporting.
  • Investigate complex endpoint-security issues, policy conflicts, configuration weaknesses, and control failures, and develop sustainable remediation.
  • Produce clear engineering documentation, test evidence, implementation guidance, and operating procedures.
  • Collaborate with stakeholders from different functions to deliver effective workspace security controls.
  • Contribute technical knowledge, reusable engineering practices, and continuous improvement across the wider cybersecurity engineering team.
Who you are
  • Approximately 8 or more years of relevant experience in EUC, endpoint engineering, modern workplace, infrastructure, or cybersecurity within enterprise environments.
  • Strong hands-on experience with Microsoft Intune, Microsoft 365, Entra ID or Azure AD, Active Directory, Group Policy, device compliance, and Conditional Access.
  • Practical experience designing, configuring, testing, or modernising endpoint policies, including GPO-to-Intune migration or large-scale device-management initiatives.
  • Good understanding of endpoint security baselines, identity-driven access, vulnerability remediation, patching, application deployment, device compliance, and secure configuration management.
  • Ability to analyse security requirements or control gaps and convert them into structured technical solutions and implementation plans.
  • Experience assessing platform capabilities, identifying limitations, and recommending practical improvements or new feature adoption.
  • Experience with PowerShell, Microsoft Graph APIs, scripting, workflow automation, or configuration-as-code practices.
  • Strong troubleshooting, analytical, documentation, communication, and stakeholder-management skills.
  • Ability to work effectively across security and technology teams in a complex enterprise environment.
  • Curiosity and willingness to build deeper expertise across Microsoft endpoint security, advanced control engineering, telemetry, and automation.
Preferred experience
  • Microsoft certifications in Azure, Microsoft 365, Security, Compliance and Identity, Endpoint Administration, or related disciplines.
  • Exposure to Microsoft endpoint protection, application control, attack-surface reduction, security monitoring, vulnerability management, or privileged-workstation security.
  • Experience supporting Windows and mobile-device security; exposure to macOS security is beneficial.
  • Experience developing security dashboards, control metrics, compliance reporting, or configuration-assurance automation.
  • Experience in financial services, regulated industries, or other large and high-availability environments.
  • Experience applying AI-assisted tools or automation to technical assessment, documentation, workflow optimisation, or engineering delivery.
Who we are

As Singapore's longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

Today, we're on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia's leading financial services partner for a sustainable future.

We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here.

What we offer:

Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Workspace Security Engineer (AVP/VP)
Workspace Security Engineer (AVP/VP)

OCBC • Singapore

On-site
SGD 120,000 - 180,000
Competitive base salary
Flexible benefits
Professional development
+1
Workspace Security Engineer (AVP/VP)
Workspace Security Engineer (AVP/VP)

OCBC Bank • Singapore

On-site
SGD 120,000 - 180,000
Competitive base salary
Holistic benefits
Learning & development opportunities
+1
Workspace Security Engineer (AVP/VP)
Workspace Security Engineer (AVP/VP)

OCBC Group • Singapore

Hybrid
SGD 180,000 - 240,000
Flexible benefits
Professional development
Wellbeing programs
Workplace Technology, Senior Operation & Governance Engineer
Workplace Technology, Senior Operation & Governance Engineer

OCBC • Singapore

On-site
SGD 180,000 - 240,000
Competitive base salary
Holistic, flexible benefits
Industry-leading learning & dev
AVP, Network Security Engineer (TISO)
AVP, Network Security Engineer (TISO)

OCBC (Singapore) • Singapore

On-site
SGD 90,000 - 150,000
Competitive base salary
Flexible benefits
Learning and development opportunities
+1
Security Platform Engineer (AVP/VP), CISO
Security Platform Engineer (AVP/VP), CISO

OCBC Group • Singapore

On-site
SGD 150,000 - 190,000
Competitive base salary
Holistic benefits
Learning opportunities
Cyber Security Specialist (Application/Infrastructure/Cloud)
Cyber Security Specialist (Application/Infrastructure/Cloud)

OCBC • Singapore

On-site
SGD 90,000 - 130,000
Competitive base salary
Flexible benefits
Professional development opportunities
Endpoint Security Engineer — Modern Workspace
Endpoint Security Engineer — Modern Workspace

OCBC (Singapore) • Singapore

On-site
SGD 120,000 - 180,000
Competitive base salary
Learning & development opportunities
Cybersecurity Project Manager (AVP/VP, CISO)
Cybersecurity Project Manager (AVP/VP, CISO)

OCBC • Singapore

On-site
SGD 110,000 - 170,000
Competitive base salary
Flexible benefits
Learning & development opportunities
VP/ED, Cyber Risk Management
VP/ED, Cyber Risk Management

OCBC • Singapore

On-site
SGD 350,000 - 650,000
Competitive salary
Flexible benefits
Learning & development
+1