Search by job, company or skills

Security Operations Engineer

  • Posted 13 hours ago
  • Be among the first 10 applicants

Job Description

Who are we

dtcpay is a MAS licensed payment service provider that bridges traditional finance and digital assets. We enable businesses to accept and make payments in both fiat and digital currencies, delivering secure, efficient, and seamless payment experiences across borders. As we expand globally, we are shaping the future of digital payments. We are also recognised as one of Singapore's Top 10 Startups in the LinkedIn Top Startups 2025 list, a reflection of our momentum and the exciting journey ahead for our team.

We are looking for a proactive and hands-on Security Operations Engineer to join our Security team. In this role, you will be responsible for protecting our production environment by monitoring security events, responding to incidents, managing security platforms, and continuously improving our security posture. You will work closely with infrastructure, engineering, and compliance teams to detect threats, investigate security incidents, strengthen defenses, and support enterprise security initiatives.

What You'll Do:

  • Monitor security alerts and events, perform threat analysis, and respond to security incidents to ensure the security and availability of company systems.
  • Operate, maintain, and optimize security platforms including SIEM, EDR, WAF, firewalls, NDR, and bastion hosts.
  • Investigate security incidents through triage, root cause analysis, remediation, and post-incident reporting.
  • Conduct regular security assessments, vulnerability assessments, and penetration testing for web applications, mobile applications, APIs, and firmware.
  • Identify, validate, and remediate security vulnerabilities while working closely with engineering teams.
  • Monitor emerging cyber threats, threat intelligence, and newly disclosed vulnerabilities (including 0-day vulnerabilities), and evaluate their impact on the business.
  • Support enterprise security initiatives, compliance assessments, and security governance programs.
  • Promote security awareness by supporting phishing simulations, user education, and security training activities.
  • Continuously improve detection rules, monitoring capabilities, and incident response processes.

What We're Looking For:

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related discipline.
  • Minimum 3 years of experience in Security Operations (SOC), Cybersecurity, or Penetration Testing.
  • Strong analytical and problem-solving skills with the ability to respond effectively under pressure.
  • Willingness to participate in on-call and incident response rotations when required.
  • Experience using penetration testing and vulnerability assessment tools such as Burp Suite, Nmap, Nessus, AWVS, or similar.
  • Solid understanding of common web application vulnerabilities, including SQL Injection, Cross-Site Scripting (XSS), CSRF, SSRF, RCE, and authentication/authorization flaws.
  • Hands-on experience managing enterprise security solutions, including: SIEM, EDR, WAF, Firewalls, Network Detection & Response (NDR), Bastion Hosts.
  • Experience performing security monitoring, incident investigation, threat hunting, and root cause analysis.
  • Proficient in Python for automation or security tooling. Experience developing security utilities, scanners, or proof-of-concept (PoC) tools is an advantage.
  • Knowledge of mobile application security testing or reverse engineering is a plus.
  • Experience securing cloud environments such as AWS, Alibaba Cloud, or Tencent Cloud is an advantage.
  • Proficiency in both English and Mandarin as you will need to work closely with Chinese vendors.
  • The role is based fully onsite, requiring your presence in the office.

Nice to Have:

  • Security certifications such as OSCP, CEH, CISSP, GSEC, or equivalent.
  • Published vulnerabilities with CVE, CNVD, or other recognized vulnerability disclosure programs.
  • Experience with source code security analysis tools such as Fortify SCA, Cppcheck, or similar.
  • Experience supporting security compliance frameworks such as MLPS (Multi-Level Protection Scheme), ISO 27001, PCI DSS, or similar.
  • Experience delivering security awareness training or conducting cybersecurity workshops.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 152060167

Similar Jobs

Malaysia, Kuala Lumpur

Skills:

Incident ResponseSiem ToolsFirewallsincident management toolshardening OSSecurity Monitoringforensic analysis

Beware of Scammers

We don’t charge money for job offers