Job Openings
ICT Infrastructure Engineer REQ90
About the job ICT Infrastructure Engineer REQ90
We are seeking a highly skilled and motivated Senior ICT Infrastructure Engineer to join our cyber security operations team. The ideal candidate will play a key role in maintaining our organisation's technology stack. The role involves focusing on security and compliance, operational efficiency, and service excellence – keeping organisation cyber safe.
Key Responsibilities:
- Lead Vulnerability Management (VM) of assigned cyber security tools, including proactive monitoring of vulnerabilities, planning remediation schedules, adhering to vulnerability deadlines and seeking deviations via Risk Assessment (RA).
- Lead security compliance through regular system hardening, configuration management, and policy enforcement.
- Lead IT lifecycle management.
- Ensure timely and successful updates and upgrades whilst ensuring minimal disruption to business operations.
- Plan downtime and collaborate with cross-functional teams for system updates and upgrades.
- Support regular audits and perform remediation actions.
- Work closely with vendors.
- Provide operations support, in a multi-vendor network including Critical Information Infrastructure (CII).
- Participate in Disaster Recovery (DR) exercise and contribute to architectural planning for managed security tools in cloud environments.
- Manage tool setups and migrations.
- Create, maintain and review technical documentation, Standard Operating Procedures (SOP) as part of Knowledge Management (KM).
- Drive efficiencies through automation.
- Proactive documentation as part of Knowledge Management (KM).
- Occasionally provide after-hours support including weekends as required.
What we are looking for
Requirements
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
- Minimum 5 years of hands-on experience in cybersecurity operations and security tool management.
- Excellent knowledge and proven hands-on ability in operating Privileged Access Management (PAM) tools such as CyberArk.
- Good vendor management skills.
- Good written and verbal communication skills with demonstrated ability to influence and communicate effectively with non-technical audiences including management.
- Applicants are expected to manage work in fast-paced environments, across heterogeneous networks including cloud environments, some of which are Critical Information Infrastructure (CII).
- CyberArk CDE is a mandatory requirement for this role. Candidates who do not have the CDE are advised not to apply.
Preferred Qualifications, Knowledge and Experience
- Proven ability to manage and maintain cyber security operations.
- Good fundamental knowledge and familiarity with Security Incident Event Management (SIEM) and Vulnerability Management (VM) tools including Splunk and Nessus (by Tenable), respectively.
- Experience with automation tools and scripting (Ansible, Python, PowerShell) to automate repetitive tasks.
- Experience with Singapore Government security standards and compliance frameworks (IM8, CSA guidelines).
- Experience in harnessing AI solutions to continuously improve cyber security operations efficiency, including processes and service delivery, is advantageous.
- Experience in demonstrating AI literacy with the ability to use AI tools responsibly, ethically, and securely, ensuring compliance with organisational policies, data privacy, confidentiality, and governance requirements.
- Understanding of financial sector security requirements and regulations.
- Understanding in Identity and Access Management (IAM) concepts.