Назад
Company hidden
1 час назад

Cybersecurity Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Singapore
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Engineer (Security Operations/DevSecOps): Implementing and improving security controls across servers, endpoints, cloud services, networks, identity systems, and engineering platforms with an accent on vulnerability management, monitoring, incident response, and access control. Focus on investigating alerts, hardening hybrid infrastructure, embedding security into CI/CD, and tracking remediation across distributed technical teams.

Location: Hybrid from the Singapore office

Company

hirify.global is a global digital distributor of electronic components that supports procurement across communications, consumer electronics, and automotive manufacturing.

What you will do

  • Implement, maintain, and improve security controls across servers, endpoints, cloud services, networks, identity systems, and engineering platforms.
  • Manage vulnerability scanning, validation, prioritization, remediation tracking, and security risk reporting.
  • Monitor and investigate security alerts from endpoint protection, SIEM, identity systems, firewalls, VPNs, and other security platforms.
  • Support incident response through evidence collection, containment, remediation tracking, and post-incident improvements.
  • Partner with Infrastructure, SysOps, DevOps, Software Engineering, DBA, and business technology teams on hardening, IAM, network security, secure SDLC, and DevSecOps.
  • Maintain practical security documentation and support compliance evidence collection, risk communication, and security awareness.

Requirements

  • 3+ years of hands-on experience in cybersecurity, information security, security engineering, infrastructure security, or a similar role.
  • Practical knowledge of vulnerability management, incident response, access control, endpoint security, network security, and secure system configuration.
  • Hands-on experience with EDR, SIEM or log management, vulnerability scanners, identity platforms, firewall or VPN tools, or cloud security tools.
  • Working knowledge of Windows and Linux server security, patching, hardening, logging, and troubleshooting.
  • Understanding of MFA, least privilege, privileged access, RBAC, access reviews, secure SDLC, dependency scanning, secrets management, and SAST/DAST concepts.
  • Strong written communication, structured troubleshooting, documentation, and cross-functional collaboration skills in a distributed, multi-time-zone environment.

Nice to have

  • Experience with Microsoft Defender, Microsoft Entra ID, Intune, Microsoft Sentinel, Azure, AWS, or GCP security services.
  • Experience securing hybrid environments with on-premise infrastructure, cloud services, VPNs, data centers, and distributed offices.
  • Familiarity with SOC 2, ISO 27001, NIST, CIS Controls, GDPR, CIS benchmarks, patch management, and configuration drift detection.
  • Experience with application security testing, dependency scanning, container scanning, or CI/CD security integrations.
  • Relevant certifications such as Security+, CySA+, SSCP, CISSP Associate, CEH, or Azure Security Engineer.

Culture & Benefits

  • Hybrid work from the Singapore office in a global and distributed environment.
  • Competitive salary.
  • Ongoing training and professional development opportunities.
  • Paid time off.
  • Collaborative work with Infrastructure & Security, SysOps, DevOps, Software Engineering, DBA, Product, Delivery, and business technology stakeholders.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →