

Search by job, company or skills

Location: Ang Mo Kio, Singapore
Experience Required: 3+ years
The IT Security Engineer will be responsible for implementing, operating, and supporting security controls for mission-critical systems within a secured environment. The role spans both project/implementation security (Day 1) and operations/production support (Day 2), working closely with Security Leads, Infrastructure, System, and Software teams to ensure compliance with government security policies and standards.
Key Responsibilities
Security Implementation & Engineering
• Implement security architecture and controls as designed by Security Leads/Architects
• Support system, application, and infrastructure security configurations
• Assist in threat modelling and risk assessment activities
• Translate security requirements into technical implementation across platforms
Compliance Support
• Support compliance with IM8/Government security policies, Whole-of-Government (WOG) requirements, and PDPA (where applicable)
• Assist in preparing and documenting Security Risk Assessments (SRA), Vulnerability Assessments (VA), and Penetration Testing (PT)
• Maintain security documentation and evidence for audits
DevSecOps & Secure Development
• Implement and maintain security tools in CI/CD pipelines (SAST, DAST, SCA, container scanning)
• Monitor and triage findings, working with developers on remediation
• Support secure coding practices and DevSecOps adoption
• Assist with API security, secrets management, and secure communications setup
Security Testing Support
• Support coordination and execution of VA/PT activities
• Track vulnerabilities and ensure timely remediation
• Assist in documenting findings and closure evidence
System & Platform Hardening
• Implement and maintain security hardening for operating systems, middleware, databases, and Kubernetes/containers (RBAC, secrets, network policies)
• Support configuration of API Gateways, WAF, and authentication/authorization mechanisms (OAuth2, mTLS)
Operations & Incident Response
• Support investigation, containment, and remediation of security incidents; perform log analysis and root cause analysis
• Monitor alerts from SIEM and security tools, and assist in tuning detection rules and dashboards
• Perform vulnerability scans, track patching, and escalate high-risk findings
• Support audit preparation, evidence collection, and remediation tracking
• Support access control administration (RBAC, MFA, Privileged Access Management) and periodic user access reviews
Requirements
• Degree in Computer Science, Cybersecurity, Information Security, or equivalent
• 3-7 years of IT experience in cybersecurity or infrastructure security
• Experience supporting security in projects or production environments
• Familiarity with Singapore Government security policies (IM8 preferred)
• Hands-on experience with Kubernetes/Docker security, IAM and access control, security tools (SAST, DAST, SIEM, vulnerability scanners), and CI/CD/DevSecOps practices
• Basic knowledge of network, application, and cloud security
• Preferred certifications: CEH, CompTIA Security+, or equivalent; CISSP Associate, GIAC, AWS/Azure Security certifications are advantageous
• Strong technical troubleshooting and problem-solving skills, good communication with technical and non-technical teams, and detail-oriented documentation skills
Eligibility
Due to government security clearance requirements for this role, only Singapore Citizens are eligible to apply.
Unisoft is a dynamic recruitment firm connecting top talent with businesses through data-driven hiring solutions. With 30 years of expertise, we specialize in seamless and strategic placements across industries. At Unisoft, we don’t just fill roles—we build careers.
Job ID: 152517511
Skills:
Ansible, PowerShell, Cyberark, Python, Tenable vulnerability management platform, Palo Alto Networks Prisma Cloud, Tenable One, Nessus Scanners, Tenable Security Center, AI solutions
Skills:
Email Security, Vulnerability Management, Iam, Firewalls, Siem, PAM, EDR, Web Application Firewalls, Endpoint Protection
Skills:
package delivery , Requirements Traceability, Penetration Testing, Integration Testing, Leadership, Threat and Vulnerability Management, Acceptance Criteria, Customer Acceptance Checking and Onboarding, Deployment Plan, Cybersecurity Framework Application, mitigation, Risk Management, Operations Management, System Validation, supplier interfacing, Resource Planning
Skills:
it security operations , certificate management , Network Security, Cyber Security, Azure Security, trust management, Security Architecture, Cissp, conditional access, Enterprise Security Solutions, Security Operations
Skills:
security tools , Power Bi, M365, Bitbucket, Siem, Azure, AWS, Google Workspaces, ClickUp, vulnerability scanning tools, Entra, GCP Services