IT Security Engineer
IT Security Engineer
Location: Ang Mo Kio, Singapore
Experience Required: 3+ years
The IT Security Engineer will be responsible for implementing,operating, and supporting security controls for mission-critical systems withina secured environment. The role spans both project/implementation security (Day1) and operations/production support (Day 2), working closely with SecurityLeads, Infrastructure, System, and Software teams to ensure compliance withgovernment security policies and standards.
KeyResponsibilities
Security Implementation& Engineering
• Implement security architecture and controls asdesigned by Security Leads/Architects
• Support system, application, and infrastructuresecurity configurations
• Assist in threat modelling and risk assessmentactivities
• Translate security requirements into technicalimplementation across platforms
Compliance Support
• Support compliance with IM8/Government securitypolicies, Whole-of-Government (WOG) requirements, and PDPA (where applicable)
• Assist in preparing and documenting Security RiskAssessments (SRA), Vulnerability Assessments (VA), and Penetration Testing (PT)
• Maintain security documentation and evidence for audits
DevSecOps & SecureDevelopment
• Implement and maintain security tools in CI/CDpipelines (SAST, DAST, SCA, container scanning)
• Monitor and triage findings, working with developers onremediation
• Support secure coding practices and DevSecOps adoption
• Assist with API security, secrets management, andsecure communications setup
Security Testing Support
• Support coordination and execution of VA/PT activities
• Track vulnerabilities and ensure timely remediation
• Assist in documenting findings and closure evidence
System & PlatformHardening
• Implement and maintain security hardening for operatingsystems, middleware, databases, and Kubernetes/containers (RBAC, secrets,network policies)
• Support configuration of API Gateways, WAF, andauthentication/authorization mechanisms (OAuth2, mTLS)
Operations & IncidentResponse
• Support investigation, containment, and remediation ofsecurity incidents; perform log analysis and root cause analysis
• Monitor alerts from SIEM and security tools, and assistin tuning detection rules and dashboards
• Perform vulnerability scans, track patching, andescalate high-risk findings
• Support audit preparation, evidence collection, andremediation tracking
• Support access control administration (RBAC, MFA,Privileged Access Management) and periodic user access reviews
Requirements
• Degree in Computer Science, Cybersecurity, InformationSecurity, or equivalent
• 3-7 years of IT experience in cybersecurity orinfrastructure security
• Experience supporting security in projects orproduction environments
• Familiarity with Singapore Government security policies(IM8 preferred)
• Hands-on experience with Kubernetes/Docker security,IAM and access control, security tools (SAST, DAST, SIEM, vulnerabilityscanners), and CI/CD/DevSecOps practices
• Basic knowledge of network, application, and cloudsecurity
• Preferred certifications: CEH, CompTIA Security+, orequivalent; CISSP Associate, GIAC, AWS/Azure Security certifications areadvantageous
• Strong technical troubleshooting and problem-solvingskills, good communication with technical and non-technical teams, anddetail-oriented documentation skills