Security engineer (junior)
We are looking for an IT Security Engineer to support cybersecurity across both project implementation (Day 1) and production operations (Day 2) for mission-critical systems. You will work closely with Security Leads, infrastructure, system and software teams to identify vulnerabilities, monitor security posture, support remediation, and ensure compliance with government security requirements.
Key Responsibilities
- Perform vulnerability assessments, security reviews and risk analysis across applications and infrastructure.
- Monitor security alerts, vulnerabilities and compliance status, and coordinate remediation with technical teams.
- Support security implementation and hardening across operating systems, applications, middleware, containers and infrastructure.
- Support security testing activities including VA/PT, SAST/DAST and vulnerability scanning, tracking findings through closure.
- Assist with security incident investigation, log analysis, root cause analysis and remediation.
- Support IAM and access control activities including RBAC, MFA, PAM and access reviews.
- Prepare security dashboards, vulnerability reports, compliance metrics and management updates.
- Maintain security documentation and support audits, risk assessments and government security compliance activities.
Requirements
- Singapore Citizen with a Degree/Diploma in Cybersecurity, Computer Science, IT or related discipline.
- 3–7 years of experience in cybersecurity, infrastructure security or security operations.
- Hands-on experience with vulnerability assessment, remediation tracking and security monitoring.
- Good understanding of infrastructure, network, application and access security concepts.
- Experience supporting security compliance, audits and security risk assessments.
- Familiarity with Singapore Government security requirements, including IM8, is advantageous.
- Exposure to DevSecOps, containers, IAM, SIEM or CI/CD security is beneficial; no specific security tool expertise is required.
- Strong analytical, reporting and communication skills with the ability to work across technical and business teams.
Certifications such as Security+, CEH, CISSP Associate, GIAC or equivalent are advantageous.
