Senior Cybersecurity Engineer
Full-time
Senior Executive
2 days ago
About the RoleWe are looking for a Senior Cybersecurity Engineer to work across two fronts: protecting our own systems, data, and customers, and deliv.....
About the Role
We are looking for a Senior Cybersecurity Engineer to work across two fronts: protecting our own systems, data, and customers, and delivering security projects for our clients. You will design and build security controls across multi-cloud environments (AWS and Azure), lead incident response, and partner with engineering teams to make security a built-in part of how software ships. On the client side, you will scope and deliver hands-on security engagements, advise customer stakeholders, and represent us as a trusted technical expert.
This is a hands-on technical role that balances internal security ownership with customer-facing project delivery, so comfort working directly with clients is essential.
What You'll Do
Internal security (our own environment)
- Design, implement, and maintain security controls across our AWS and Azure environments, covering identity (IAM, Azure AD/Entra ID), networking, encryption, logging, and workload protection.
- Build and enforce cloud security guardrails using native services (AWS Security Hub, GuardDuty, Azure Defender, Microsoft Sentinel) and cloud security posture management (CSPM) tooling.
- Lead detection and response efforts, including triage, investigation, containment, and post-incident review.
- Build and tune detection logic, alerting pipelines, and automation to reduce manual toil and improve mean time to detect and respond.
- Run and improve vulnerability management: scanning, prioritization, remediation tracking, and reporting.
- Develop and maintain security architecture standards, runbooks, and documentation.
Client project delivery
- Scope, plan, and deliver hands-on security engagements for customers (cloud security reviews, architecture design, hardening, assessments, and remediation).
- Serve as the technical lead and primary point of contact on client projects, translating requirements into deliverables.
- Advise customer stakeholders (engineers through executives) on risk, remediation, and security best practices.
- Conduct or coordinate penetration tests, configuration reviews, and red team exercises for clients, then drive remediation of findings.
- Produce clear, professional client-facing deliverables: assessment reports, architecture diagrams, and remediation roadmaps.
- Support compliance and audit work for clients, with a focus on Singapore government and regulated-sector frameworks (IM8, GCC/GCC+, MTCS, CCoP, PDPA, MAS TRM where relevant), alongside international standards (SOC 2, ISO 27001).
Cross-cutting
- Partner with software and infrastructure teams (internal and client) to embed security into the SDLC (threat modeling, secure code review, CI/CD security gates).
- Evaluate, deploy, and manage security tooling (SIEM, EDR, IDS/IPS, CSPM, secrets management, identity and access).
- Mentor junior engineers and raise security awareness across teams.
What We're Looking For
Required
- 5+ years of experience in cybersecurity, security engineering, or a closely related field.
- Strong knowledge of network security, operating system internals (Linux and Windows), and common attack and defense techniques.
- Deep hands-on experience securing AWS and Azure at scale: identity and access management, network segmentation (VPC/VNet, security groups, NSGs), key management, and workload and data protection.
- Proficiency with at least one scripting or programming language (Python, Go, Bash, or similar) for automation and tooling.
- Experience with detection and response: SIEM platforms, EDR tools, and log analysis at scale.
- Solid grasp of common frameworks and standards (MITRE ATT&CK, NIST CSF, OWASP Top 10, CIS Benchmarks).
- Working knowledge of Singapore government security and compliance requirements, including IM8 (Instruction Manual on ICT & SS Management, managed by GovTech), the Government on Commercial Cloud (GCC and GCC+) guardrails for AWS and Azure, MTCS (SS 584), the Cybersecurity Act and Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure, and the Personal Data Protection Act (PDPA).
- Strong analytical skills and the judgment to prioritize risk in a fast-moving environment.
- Clear written and verbal communication, with the ability to explain technical risk to non-technical stakeholders.
- Comfort working directly with clients: scoping engagements, managing expectations, and presenting findings to customer stakeholders.
- Ability to manage multiple concurrent projects and shift between internal work and client delivery.
Nice to Have
- Industry certifications (OSCP, GIAC/SANS, CISSP, CCSP, or equivalent), including cloud security certs (AWS Certified Security Specialty, Azure Security Engineer Associate AZ-500).
- Experience with infrastructure as code (Terraform, CloudFormation) and policy as code.
- Background in application security, threat modeling, or secure software development.
- Familiarity with container and Kubernetes security.
- Experience delivering projects under Singapore Government on Commercial Cloud (GCC/GCC+) or for CSA-regulated CII owners.
- Familiarity with CSA Cyber Essentials and Cyber Trust certification marks.
- Eligibility for Singapore government security clearance, where required for public-sector engagements.
- Hands-on penetration testing across multiple scopes: web applications, APIs, external and internal network/infrastructure, cloud configuration reviews (AWS and Azure), and mobile or wireless where applicable.
- Familiarity with common offensive tooling (Burp Suite, Nmap, Metasploit, Cobalt Strike, cloud-native testing tools) and structured methodologies (OWASP WSTG, PTES, NIST SP 800-115).
- Prior experience in a consulting, professional services, or managed security services (MSSP) environment.
- Prior experience leading incident response for production systems.
- Experience operating in a regulated or compliance-heavy environment.
What Success Looks Like
- In your first 90 days: you understand our environment, threat landscape, and tooling, and you have closed or improved several high-priority gaps.
- Within 6 months: you own key areas of our detection and response program and have measurably reduced risk in those areas.
- Within a year: you are a trusted technical leader who has shaped our security architecture and lifted the capability of the whole team.
Official account of Jobstore.