Lead, Security Engineering

Singapore, Singapore

Job Description


Lead, Security Engineering



We are seeking a highly motivated and experienced Cloud Security Hands-On Engineer to join our client. The Cloud Security Hands-on Engineer will be responsible for designing, developing, implementing, and maintaining information systems. This will include developing a deep understanding of our cloud architecture, identifying and mitigating potential security threats and vulnerabilities, and collaborating with other teams to ensure our security measures are effective.

Our Ideal Candidate

  • 8+ years of Information Security or engineering experience.
  • 2+ years of direct experience in at least one Public Cloud (AWS or Azure).
  • Hands-On Proficiency in scripting and coding using Bash, Python, IaC (Terraform, Cloud formation, Azure ARM).
  • Experienced in the SDLC, including requirements analysis, design, development, testing, deployment, and maintenance. (Tools like Junit, Postman, Burp, Terratest, Sentinel, Misconfig test, OPA,etc.,)
  • Experience with Azure technologies in general, such as Service Fabric, Application Service Environment, Azure Kubernetes Service, Azure DevOps, Azure Monitor, Azure Sentinel, Azure Defender Suite, Azure SQL, Cosmos, Azure APIM, Azure AD, Azure OMS/Application Insights, Global Traffic Manager, etc.
  • Experience with AWS technologies, such as CodePipeline, CodeBuild, CodeDeploy, CodeStar, Guardrails, Amazon ECS, AWS Lambda, etc.
  • Hands on experience in infrastructure provisioning, configuration of provisioned infrastructure. deployment of application and Plugins such as TFLint, Checkov, Docker Linter, docker-vulnerability-extension, Security Scan, Contrast Security, etc.,
  • Extensive knowledge in analyzing the contents and the build process of a container image in order to detect security issues, vulnerabilities or potential risks. Open-source tools such as Dagda, Clair, Trivy, Anchore, etc., can be leveraged for container image analysis.
  • Work closely with Product Security, Engineering, Operations, and Corporate Security to define security strategy and execute on it. Implementing automation to enable developers to easily consume security services.
  • Improve the accessibility of security through automation, continuous integration pipelines, and other means. Designing a secure application-release automation process to make security an integral part of the CI/CD pipelines.
  • Enforce standard methodologies, processes and tools and ensure compliance to enterprise architecture, global information security policies and engineering strategy
  • Validate adherence to AWS and Azure governance standards for policy definitions, role-based access controls, ARM Templates, resource groups and Azure Blueprints.
  • Identify security tools and lead operationalization of solutions from POC to Production, e.g. API Threat Protection, Container Security, etc. Streamline POC processes.
  • Work with SRE and Engineering to implement a chaos-testing methodology and toolkit. Integrating security tools issue tracking with Jira.
  • Implement automation to investigation and response workflows for Automated Incident Response.
  • Interview, hire, and create on-boarding plans for new or transferred employees.
  • Encourage others to seek opportunities for different and innovative approaches to addressing problems; facilitate the implementation and acceptance of change.
  • Produce and streamline audit evidence.
  • Stay current on threats, vulnerabilities, and controls.
  • Familiarity with SecOps processes i.e., detection, monitoring, alerting and threat intelligence.
  • Familiar with Open-source tools such as Jenkins, etc., can be leveraged to build the CI/CD pipelines, and DefectDojo and OWASP Glue can help in tying the checks together and visualizing the check results in a single dashboard.
  • Hands-On experience in Open-source tools such as truffleHog, git-secrets, GitGuardian and similar can be utilized to detect such vulnerable management of secrets.
  • Expert knowledge with integrating crucial security tasks into CI/CD pipelines.
  • Strong knowledge of software development methodologies and the software development lifecycle.
  • Strong knowledge of container security and secrets management.
  • Working experience with configuration management.
Role Specific Competencies
  • Public Cloud Engineering and Architecture
  • API Frameworks
  • IAM (RBAC, ABAC) and Secrets Management
  • Threat Modeling (Manual / Automation)
  • Threat Modeling Framework STRIDE, MITRE
  • Azure / AWS Public Cloud
  • Python, Go Lang, Java / .NET
  • Infrastructure as Code
  • PowerShell, Azure CLI
  • DevSecOps Capabilities (SAST, DAST, SCA, CodeSign)
Company Reg No.: 201131609D | License No.: 11C4684| EA Reg No.: R23114873 Danielle Tan

eFinancialCareers

Beware of fraud agents! do not pay money to get a job

MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Related Jobs

Job Detail

  • Job Id
    JD1354230
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    Singapore, Singapore
  • Education
    Not mentioned