Senior Security Engineer
Senior Security Engineer
anext bank8-10 Years
- Posted 5 days ago
- Be among the first 10 applicants
Job Description
About the Role
This role is accountable for building and operating the platforms that underpin ANEXT Bank's security posture, while providing day-to-day operational support to Platform Security Operations. You will design, deploy, and maintain secure infrastructure, applications, and cloud environments, and work hand-in-hand with the SOC, IT, DevOps, and business teams to detect, protect, and respond to emerging threats across the Bank.
Key Responsibilities:
Platform Engineering
- Design, build, and maintain stable, secure platforms across the Bank's infrastructure, applications, and cloud environments
- Engineer and automate platform components to enable secure, reliable, and scalable service delivery
- Implement and manage platform security controls across network, endpoint, identity, and application layers
- Support secure configuration management and hardening initiatives (e.g., CIS Benchmarks)
- Evaluate and recommend security technologies and platform improvements to address emerging threats
- Ensure platforms are designed and maintained to meet regulatory requirements (e.g., MAS TRM, PDPA)
Platform Security Operations Support
- Support the monitoring, response, and resolution of security alerts, incidents, and threats across the Bank's platforms
- Assist with triage, investigation, and escalation of security incidents in coordination with the SOC and IT teams
- Support the maintenance and tuning of security tools (SIEM, EDR, WAF, vulnerability scanners, etc.) for optimal detection and response
- Provide Level 2 support for platform-related security and operational issues
- Assist with security assessments, vulnerability scans, and penetration testing coordination
Policy & Governance
- Support the development, review, and update of cybersecurity policies, standards, and procedures aligned with regulatory requirements (e.g., MAS TRM, PDPA)
- Conduct policy compliance assessments and report gaps to relevant stakeholders
- Maintain audit-ready documentation for audit and regulatory examinations
- Support risk assessment activities and maintain the risk register
- Coordinate with internal audit and external regulators during assessments
Awareness & Collaboration
- Deliver security awareness support to staff on policies, threats, and best practices
- Collaborate with IT, DevOps, and business teams to embed security into processes
- Act as the platform security point of contact for operational queries and escalations
Requirements:
- Bachelor's degree in Computer Science, Information Security, or related field
- 8+ years of experience in cybersecurity, with at least 2 years in a financial services or regulated environment
- Relevant certifications (e.g., CISSP, CISM, CEH, GSEC, Security+, CCSP, OSCP)
- Hands-on experience with security operations (SIEM, SOAR, incident response)
- Familiarity with cloud security and containerised environments
- Experience implementing and maintaining security policies in a regulated industry
- Knowledge of vulnerability management and patching processes
- Understanding of network security, identity & access management, and endpoint protection
Competencies
- Analytical Thinking: Ability to assess complex security scenarios and prioritise risks
- Communication: Clear written and verbal communication for technical and non-technical audiences
- Attention to Detail: Rigorous approach to documentation, compliance, and operational accuracy
- Collaboration: Works effectively across teams and builds strong stakeholder relationships
- Adaptability: Thrives in a fast-paced digital bank environment with evolving priorities
Preferred Qualifications
- Experience in a digital bank, fintech, or start-up environment
- Knowledge of Singapore regulatory requirements (MAS, PDPA)
- Hands-on experience with DevSecOps practices and CI/CD security integration
- Familiarity with AI/ML security considerations and emerging technology risks
More Info
Key Skills
GSEC
containerised environments
patching processes

