IT Security Engineer (Hybrid: On-Prem & Azure Cloud)

SHAW SERVICES PTE. LTD.

Orchard (NE)

On-site

USD 120,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SHAW SERVICES PTE. LTD. seeks a Security Engineer to safeguard hybrid assets, bridging on‑premise and cloud security in a unified environment. You will lead firewall policy design, IAM governance, vulnerability management, and PCI‑DSS compliance across digital and physical domains.

Required: 3–5 years in IT security, deep firewall expertise (SonicWall, Palo Alto, Cisco ASA), and hands‑on with Cisco ISE, Wazuh, Graylog, plus Azure security tooling. Bonus AZ-500 or CISSP/CISM.

Qualifications

  • Minimum 3–5 years of hands-on IT security experience across hardware and cloud.
  • Deep expertise in at least two firewalls (SonicWall, Palo Alto, or Cisco ASA).
  • Experience with Cisco ISE, Wazuh or Graylog for security monitoring.
  • Strong PCI-DSS understanding and ability to prepare technical controls.

Responsibilities

  • Hybrid infrastructure & network security: design, deploy, and maintain firewall policies.
  • Cloud Security & DevSecOps: governance, Azure security tooling, and IaC guardrails.
  • Physical security: oversee integration of biometric systems and CCTV infrastructure, drive audits.

Skills

Firewalls
IAM
PCI-DSS compliance
Cloud security
DevSecOps

Tools

Cisco ISE
Wazuh
Graylog
SonicWall
Palo Alto
Cisco ASA
Fortinet
Microsoft Azure

Job description

Role Purpose:

We are seeking a versatile Security Engineerto safeguard our organization’s digital and physical assets. This role is unique—you will bridge the gap between on-premise infrastructure(Firewalls, Biometrics CCTV) and Cloud Security(Azure, DevSec Ops). You will be the technical lead in ensuring our hybrid environment is resilient against threats and compliant with international standards like PCI-DSS.

Key Responsibilities:
1. Hybrid Infrastructure & Network Security
  • Next-Gen Firewall Management:Design, deploy, and maintain robust firewall policies across SonicWall, Palo Alto, Cisco ASA, and Fortinetenvironments.

  • Network Governance:Manage SonicWall NMS/GMS and administer Cisco ISEto ensure strict Identity and Access Management (IAM).

  • Vulnerability Management:Execute regular scans via OpenVAS, prioritizing and remediating risks across the internal network.

  • Security Monitoring:Lead threat detection efforts by analyzing logs through Wazuhand Graylogto identify and respond to incidents in real-time.

2. Cloud Security & DevSecOps (Microsoft Azure)
  • Cloud Governance:Manage and optimize Microsoft Defender for Cloudto maintain a strong security posture (CSPM).

  • Azure Security Engineering:Configure Azure Firewalls, NSGs, and Key Vaults to protect cloud-native workloads.

  • Infrastructure as Code (IaC) Security:Design and implement security guardrails within the Azure DevOpspipeline (DevSecOps), ensuring code is scanned before deployment.

3. Physical Security & Compliance
  • Integrated Physical Security:Oversee the technical maintenance of Biostar biometric systems, CCTV networks, and TZ server rackaccess controls.

  • Audit Leadership:Serve as the primary technical point of contact for security audits, specifically driving PCI-DSScompliance and internal risk assessments.

Required Experience & Qualifications:
  • Experience:Minimum 3–5 years of hands‑on experience in IT Security, covering both hardware and cloud environments

  • Technical Proficiency:

  1. Firewalls:Deep expertise in at least two of the following: SonicWall, Palo Alto, or Cisco ASA.

  2. On‑Prem Tools:Proven knowledge with Cisco ISE, Wazuh, or Graylog.

  3. Cloud:Strong working knowledge of Microsoft Azure(Identity, Networking, and Security tools).

  4. DevSecOps: Good to have knowledge on Security Scans such as Dependency Scanning, Secrets Scanning, Code Security scanning.

  • Compliance:Practical experience in preparing documentation and technical controls for PCI-DSS.

  • Physical Security:Familiarity with biometric integration (Biostar) and CCTV infrastructure.

  • Certification(Bonus):AZ-500 (AzureSecurity Engineer), PCNSE, or CISSP/CISM.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid IT Security Engineer: On-Prem & Azure Cloud
Hybrid IT Security Engineer: On-Prem & Azure Cloud

SHAW SERVICES PTE. LTD. • Orchard (NE)

On-site
USD 120,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Heath • Houston (TX)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Benefits
401k
PTO
+1
Cybersecurity Engineer
Cybersecurity Engineer

JPS Tech Solutions • Chicago (IL)

On-site
USD 140,000 - 210,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Eleven Recruiting • Santa Monica (CA)

On-site
USD 140,000 - 190,000
Network Security Engineer
Network Security Engineer

Liquid-Env-Solutions-of-Texa • Irving (TX)

On-site
USD 95,000 - 150,000
Security Engineer
Security Engineer

Enterprise Engineering Inc. (EEI) • New York (NY)

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

FutureRecruit.net • New York (NY)

Hybrid
USD 90,000 - 130,000
Azure Security Engineer
Azure Security Engineer

Zeektek • Sacramento (CA)

On-site
USD 140,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000