Search Jobs

Search by job, company or skills

Senior Security Engineer

Senior Security Engineer

Webot
5-7 Years
Early Applicant
  • Posted 12 days ago
  • Be among the first 10 applicants

Job Description

Job Summary

We are looking for a Workplace Security Engineer to design, implement, and continuously improve corporate security controls across identity, endpoint, network access (VPN/ZTNA), and data protection. You will be the technical owner for key security platforms and work with IT, Cloud, and Compliance teams to meet financial industry security requirements.

Key Responsibilities

1) Identity & Access Engineering

  • Own secure identity architecture across Google Workspace and AWS IAM Identity Center:
  • Design group/role models, least privilege, and access governance processes.
  • Improve SSO posture (SAML/OAuth), session policies, MFA enforcement, conditional access patterns where applicable.
  • Lead onboarding of new SaaS apps into SSO and define standard patterns (SAML attributes, role mapping, break-glass access).

2) Zero Trust / Remote Access Engineering

  • Own and optimize enterprise remote access and ZTNA/SASE through: Prisma Access / GlobalProtect; Prisma ZTNA / Prisma SASE; Google BeyondCorp (where applicable)
  • Work with network teams on policy design, segmentation, and logging requirements.

3) Endpoint Security Engineering

  • Define and enforce endpoint security baselines and compliance through: Jamf Pro + Apple Business Manager; Google Endpoint Management; Palo Alto Cortex XDR
  • Drive improvements in device posture: encryption, OS baseline, EDR coverage, hardening, local admin controls.

4) Data Security & DLP Engineering

  • Design and tune data protection controls through: Google Workspace DLP, Prisma Cloud DLP
  • Define data classification patterns, DLP rules/exception workflows, and measurable reduction in risky exfiltration events.

5) Vulnerability & Patch Governance

  • Own vulnerability scanning results triage, risk rating, remediation tracking, and verification.
  • Define patch SLAs, exception workflows, and reporting; coordinate with IT/Ops/R&D teams (execution may be performed by owning teams).

6) Security Monitoring, Incident Response & Continuous Improvement

  • Improve alerting quality and detection coverage across IAM/endpoint/network/DLP telemetry.
  • Lead investigations for escalated incidents, produce incident reports and post-incident improvements (runbooks, control changes).

7) Security Automation & Tooling

  • Design, develop, and maintain custom security tools, scripts, and API integrations to bridge gaps between disparate security platforms.
  • Automate routine engineering tasks, compliance checks, and incident response workflows using SOAR tools or custom code (Python/Go).

8) Documentation & Audit Readiness

  • Build security standards, runbooks, and audit evidence pipelines for access control, remote access, endpoint protection, and DLP.

Qualifications

  • 5+ years in security engineering / IT security with strong hands-on implementation experience.
  • - Proficient in at least one programming/scripting language (Python, Go, or PowerShell/Bash) with a track record of building tools or automation.
  • Solid understanding of RESTful APIs, JSON/YAML processing, and version control systems (Git).
  • Experience with Infrastructure as Code (Terraform) applied to security architecture is a strong plus.
  • Deep experience in at least two of the following:

-- IAM/SSO (Google Workspace / AWS IAM Identity Center, SAML/OAuth)

-- Endpoint security (Jamf/ABM, EDR—Cortex XDR)

-- Zero Trust / VPN / SASE (Prisma Access/GlobalProtect, Prisma ZTNA/SASE, BeyondCorp)

-- DLP engineering (Google Workspace DLP / Prisma Cloud DLP)

-- Strong troubleshooting skills across Windows/macOS, and solid networking fundamentals.

-- Experience supporting audits and producing evidence in regulated environments is a strong plus.

Nice to Have

  • Scripting/automation (Python, Bash), IaC mindset, good operational excellence.
  • Relevant certs: Palo Alto (PCNSA/PCNSE), Jamf certs, Google Workspace admin, AWS security.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Palo Alto Cortex XDR

Google Workspace DLP

GlobalProtect

Google Endpoint Management

AWS IAM Identity Center

Google BeyondCorp

Jamf Pro

Prisma Access

Google Workspace

Prisma ZTNA

Prisma Cloud DLP

Apple Business Manager

Prisma SASE

About Company

Similar Jobs

5-7 yrs
Singapore
Skills:
threat modeling , Sql, API security, Javascript, Topologies, Networking Concepts, Python, Encryption, Go, Security Protocols, Security control implementations, Computer and network security, Security design reviews, Security Assessments, Technical security assessments, Authentication and access control, SaaS security, Protocols, security engineering
5-7 yrs
Singapore
Skills:
Gcp, network security, Iam, Siem, Bash, Azure, Python, AWS, EDR, cloud security posture management
7-9 yrs
Singapore
Skills:
beats , Kibana, RedHat, Logstash, Kafka, Bash, Ubuntu, Linux, Ansible, Elasticsearch, Python, Elastic Stack
3-5 yrs
Singapore
Skills:
Cryptography, security standards, Python-based test automation, secure boot, fips, NVMe command sets, update flows, PCIe NVMe protocols, SPDM, TCG NVMe security, firmware lifecycle, SSD architecture, hardware Root of Trust architectures, firmware validation, system-level debugging, Embedded Systems
5-7 yrs
SGD 6,500 - 7,500 per month
Middle Road, Singapore
Skills:
Linux, Shell scripting, Log Analysis, Siem, Windows, Python, Detection engineering, Event correlation, Security event investigation