

Search by job, company or skills

Location: Ang Mo Kio, Singapore
Experience Required: 3+ years
The IT Security Engineer will be responsible for implementing, operating, and supporting security controls for mission-critical systems within a secured environment. The role spans both project/implementation security (Day 1) and operations/production support (Day 2), working closely with Security Leads, Infrastructure, System, and Software teams to ensure compliance with government security policies and standards.
Key Responsibilities
Security Implementation & Engineering
• Implement security architecture and controls as designed by Security Leads/Architects
• Support system, application, and infrastructure security configurations
• Assist in threat modelling and risk assessment activities
• Translate security requirements into technical implementation across platforms
Compliance Support
• Support compliance with IM8/Government security policies, Whole-of-Government (WOG) requirements, and PDPA (where applicable)
• Assist in preparing and documenting Security Risk Assessments (SRA), Vulnerability Assessments (VA), and Penetration Testing (PT)
• Maintain security documentation and evidence for audits
DevSecOps & Secure Development
• Implement and maintain security tools in CI/CD pipelines (SAST, DAST, SCA, container scanning)
• Monitor and triage findings, working with developers on remediation
• Support secure coding practices and DevSecOps adoption
• Assist with API security, secrets management, and secure communications setup
Security Testing Support
• Support coordination and execution of VA/PT activities
• Track vulnerabilities and ensure timely remediation
• Assist in documenting findings and closure evidence
System & Platform Hardening
• Implement and maintain security hardening for operating systems, middleware, databases, and Kubernetes/containers (RBAC, secrets, network policies)
• Support configuration of API Gateways, WAF, and authentication/authorization mechanisms (OAuth2, mTLS)
Operations & Incident Response
• Support investigation, containment, and remediation of security incidents; perform log analysis and root cause analysis
• Monitor alerts from SIEM and security tools, and assist in tuning detection rules and dashboards
• Perform vulnerability scans, track patching, and escalate high-risk findings
• Support audit preparation, evidence collection, and remediation tracking
• Support access control administration (RBAC, MFA, Privileged Access Management) and periodic user access reviews
Requirements
• Degree in Computer Science, Cybersecurity, Information Security, or equivalent
• 3-7 years of IT experience in cybersecurity or infrastructure security
• Experience supporting security in projects or production environments
• Familiarity with Singapore Government security policies (IM8 preferred)
• Hands-on experience with Kubernetes/Docker security, IAM and access control, security tools (SAST, DAST, SIEM, vulnerability scanners), and CI/CD/DevSecOps practices
• Basic knowledge of network, application, and cloud security
• Preferred certifications: CEH, CompTIA Security+, or equivalent; CISSP Associate, GIAC, AWS/Azure Security certifications are advantageous
• Strong technical troubleshooting and problem-solving skills, good communication with technical and non-technical teams, and detail-oriented documentation skills
Eligibility
Due to government security clearance requirements for this role, only Singapore Citizens are eligible to apply.
Unisoft is a dynamic recruitment firm connecting top talent with businesses through data-driven hiring solutions. With 30 years of expertise, we specialize in seamless and strategic placements across industries. At Unisoft, we don’t just fill roles—we build careers.
Job ID: 152517511
Skills:
Antivirus, PowerShell, Ips, Encryption, Firewalls, Gcp, Vpn, Ids, Siem, Azure, Python, AWS, vulnerability scanner, routing basics
Skills:
DAST, Vulnerability Assessments, Siem, Vulnerability Scanning, DevSecOps, Iam, Containers, Security Documentation, PAM, security reviews, risk assessments, hardening, Pt, MFA, IM8, SAST, Security Implementation, Security Monitoring, audits, security dashboards, va, Risk Analysis, compliance metrics, rbac
Skills:
Patch Management, Iso 27001, Gcp, Siem, Azure, AWS, firmware updates, firewall rules, XDR, certification management, SOAR, security configurations, M365 ecosystem, EDR, UEBA, nist, endpoint security agent management
Skills:
IT Security, Cism, Security Risk Assessments, Video Recording Systems, Audit, Access Control, Cissp, Cisa, Vulnerability Scan
Skills:
Cism, IT Security, Security Configuration Reviews, Penetration Test, Access Control, Firewall Rules, Video Recording Systems, Cissp, Cisa, Audit, Vulnerability Scan, Security Risk Assessments