Search by job, company or skills

Senior Security Engineer

5-7 Years
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

Job Summary

We are looking for a Workplace Security Engineer to design, implement, and continuously improve corporate security controls across identity, endpoint, network access (VPN/ZTNA), and data protection. You will be the technical owner for key security platforms and work with IT, Cloud, and Compliance teams to meet financial industry security requirements.

Key Responsibilities

1) Identity & Access Engineering

  • Own secure identity architecture across Google Workspace and AWS IAM Identity Center:
  • Design group/role models, least privilege, and access governance processes.
  • Improve SSO posture (SAML/OAuth), session policies, MFA enforcement, conditional access patterns where applicable.
  • Lead onboarding of new SaaS apps into SSO and define standard patterns (SAML attributes, role mapping, break-glass access).

2) Zero Trust / Remote Access Engineering

  • Own and optimize enterprise remote access and ZTNA/SASE through: Prisma Access / GlobalProtect; Prisma ZTNA / Prisma SASE; Google BeyondCorp (where applicable)
  • Work with network teams on policy design, segmentation, and logging requirements.

3) Endpoint Security Engineering

  • Define and enforce endpoint security baselines and compliance through: Jamf Pro + Apple Business Manager; Google Endpoint Management; Palo Alto Cortex XDR
  • Drive improvements in device posture: encryption, OS baseline, EDR coverage, hardening, local admin controls.

4) Data Security & DLP Engineering

  • Design and tune data protection controls through: Google Workspace DLP, Prisma Cloud DLP
  • Define data classification patterns, DLP rules/exception workflows, and measurable reduction in risky exfiltration events.

5) Vulnerability & Patch Governance

  • Own vulnerability scanning results triage, risk rating, remediation tracking, and verification.
  • Define patch SLAs, exception workflows, and reporting; coordinate with IT/Ops/R&D teams (execution may be performed by owning teams).

6) Security Monitoring, Incident Response & Continuous Improvement

  • Improve alerting quality and detection coverage across IAM/endpoint/network/DLP telemetry.
  • Lead investigations for escalated incidents, produce incident reports and post-incident improvements (runbooks, control changes).

7) Security Automation & Tooling

  • Design, develop, and maintain custom security tools, scripts, and API integrations to bridge gaps between disparate security platforms.
  • Automate routine engineering tasks, compliance checks, and incident response workflows using SOAR tools or custom code (Python/Go).

8) Documentation & Audit Readiness

  • Build security standards, runbooks, and audit evidence pipelines for access control, remote access, endpoint protection, and DLP.

Qualifications

  • 5+ years in security engineering / IT security with strong hands-on implementation experience.
  • - Proficient in at least one programming/scripting language (Python, Go, or PowerShell/Bash) with a track record of building tools or automation.
  • Solid understanding of RESTful APIs, JSON/YAML processing, and version control systems (Git).
  • Experience with Infrastructure as Code (Terraform) applied to security architecture is a strong plus.
  • Deep experience in at least two of the following:

-- IAM/SSO (Google Workspace / AWS IAM Identity Center, SAML/OAuth)

-- Endpoint security (Jamf/ABM, EDR—Cortex XDR)

-- Zero Trust / VPN / SASE (Prisma Access/GlobalProtect, Prisma ZTNA/SASE, BeyondCorp)

-- DLP engineering (Google Workspace DLP / Prisma Cloud DLP)

-- Strong troubleshooting skills across Windows/macOS, and solid networking fundamentals.

-- Experience supporting audits and producing evidence in regulated environments is a strong plus.

Nice to Have

  • Scripting/automation (Python, Bash), IaC mindset, good operational excellence.
  • Relevant certs: Palo Alto (PCNSA/PCNSE), Jamf certs, Google Workspace admin, AWS security.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 153583735

Similar Jobs

Singapore

Skills:

threat modeling SqlAPI securityJavascriptTopologiesNetworking ConceptsPythonEncryptionGoSecurity ProtocolsSecurity control implementationsComputer and network securitySecurity design reviewsSecurity AssessmentsTechnical security assessmentsAuthentication and access controlSaaS securityProtocolssecurity engineering

Singapore

Skills:

security automation ApisPowerShellBashGcpSiemScriptingPythonSOAR toolsn8norchestration toolsXDRsecurity data pipelinesCrowdStrikeElasticEDR

Singapore

Skills:

Cryptographysecurity standardsPython-based test automationsecure bootfipsNVMe command setsupdate flowsPCIe NVMe protocolsSPDMTCG NVMe securityfirmware lifecycleSSD architecturehardware Root of Trust architecturesfirmware validationsystem-level debuggingEmbedded Systems

Singapore

Skills:

IpsecCloud ComputingIT securityPowerShellNetwork securityIso27001SSLSiemApplication SecurityPythonUnified Threat Management systemsHoney NetworksSOAREnd Point securityHoney PotsPCI-DSSOpen Threat IntelligenceCobit

Singapore

Skills:

PowerShellGcpSplunkAzurePythonAWSEDRsKQLMITRE ATT CKElasticSIEM platformsSPLYARAJupyter NotebooksSigmaCyber Kill Chainnist

Beware of Scammers

We don’t charge money for job offers