Information Security Engineer
Singlife · Singapore, Singapore, Singapore
About The Role
Singlife is a leading homegrown financial services company, offering consumers a better way to financial freedom. Through innovative, technology-enabled solutions and a wide range of products and services, Singlife provides consumers control over their financial wellbeing at every stage of their lives. In addition to a comprehensive suite of insurance plans, employee benefits, partnerships with financial adviser channels and bancassurance, Singlife offers investment and advisory solutions through its GROW with Singlife platform. It also offers the Singlife Account, a mobile-first insurance savings plan. Singlife is the exclusive insurance provider for the Ministry of Defence, Ministry of Home Affairs and Public Officers Group Insurance Scheme. Singlife is also an official signatory of the United Nations Principles for Sustainable Insurance and the United Nations-supported Principles for Responsible Investment, affirming its commitment to finding a better way to sustainability. The merger of Aviva Singapore and Singlife was announced in September 2020 and created one of the largest homegrown financial services companies in Singapore in a deal valued at S$3.2 billion. It was the largest insurance deal in Singapore at the time. Singlife was subsequently acquired by Sumitomo Life in March 2024, one of Japan’s leading life insurers, which valued Singlife at S$4.6 billion, making the transaction one of the largest insurance deals in Southeast Asia. Purpose: Responsible for the operational delivery, continuous improvement, and performance oversight of Singlife’s Managed Security Services capability under the Cyber Fusion Centre. The role supports the implementation, operation, monitoring, and optimisation of security controls across enterprise platforms, infrastructure, cloud services, applications, and emerging technology environments. The incumbent is expected to provide hands-on engineering support, maintain effective security operations processes, strengthen preventive and detective controls, and contribute to the organisation’s cyber resilience, regulatory readiness, and threat response capabilities. Key Responsibilities Managed Security Services Operations · Operate, maintain, and continuously improve managed security services across the enterprise security technology stack. · Oversee service delivery, incident handling support, operational health, capacity, availability, and performance of assigned security platforms. · Maintain service documentation, runbooks, escalation paths, standard operating procedures, and operational metrics. Security Engineering and Control Implementation · Implement, configure, tune, troubleshoot, and maintain security controls across infrastructure, endpoint, network, cloud, application, and identity environments. · Support design and deployment of preventive, detective, and responsive security controls aligned to enterprise risk and regulatory expectations. · Validate control effectiveness through monitoring, testing, reporting, and continuous improvement activities. Security Tools and Technology Management · Provide hands-on support for security solutions including email security, intrusion detection and prevention, attack surface monitoring, anti-malware, web application firewall, certificate management, vulnerability monitoring, and related managed services. · Maintain platform configuration baselines, access controls, integration points, and operational readiness for assigned tools. · Work with vendors and managed service providers to resolve issues, track service improvements, and ensure agreed service levels are met. System Security Requirements and Documentation · Identify, document, and maintain system security requirements, operational procedures, configuration standards, and technical artefacts. · Support evidence collection, audit responses, control attestation, and compliance reporting where required. · Ensure operational documentation remains accurate, current, and usable by internal teams and service providers. AI Security Operations Support · Assist in implementing security controls for AI and machine learning environments, including data protection, model deployment, inference endpoints, logging, access control, and secure configuration. · Support identification and mitigation of AI-related risks such as data leakage, prompt injection, adversarial attacks, model abuse, and data poisoning. · Contribute to operational readiness for AI security monitoring and incident response. Post-Quantum Cryptography and Crypto-Agility Support · Support post-quantum cryptography readiness activities, including cryptographic inventory, certificate visibility, dependency tracking, and migration planning. · Track developments in quantum-resistant cryptographic standards and assess potential impacts on TLS, digital signatures, encryption services, and certificate management. · Contribute to hybrid cryptographic migration planning and crypto-agility improvements. Project Delivery, Risk Reduction, and Continuous Improvement · Support security projects, remediation initiatives, service improvements, and operational uplift activities from planning through delivery. · Track assigned actions, risks, dependencies, and milestones to ensure timely completion and transparent reporting. · Recommend practical improvements to strengthen resilience, reduce operational risk, and improve security outcomes. Experience · Minimum 3 years of relevant experience in cybersecurity operations, security engineering, managed security services, infrastructure security, or related technology risk functions. · Practical experience supporting security technologies such as email security, IDPS, WAF, anti-malware, attack surface monitoring, certificate management, vulnerability management, SIEM/SOAR, endpoint security, or cloud security controls. · Strong understanding of cybersecurity principles, secure configuration practices, incident response support, threat detection, vulnerability management, access control, logging, and security monitoring. · Ability to analyse complex security issues, identify root causes, assess risk, propose practical remediation options, and communicate findings clearly. · Working knowledge of scripting or automation using languages such as Python, PowerShell, Bash, or equivalent is preferred. · Strong stakeholder management, documentation, problem-solving, and collaboration skills, with the ability to operate effectively in a regulated financial services environment. Education · Academic: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline is preferred. · Professional Certification(s): CISSP, CISM, CCSP, Security+, GIAC, cloud security, network security, or relevant vendor certifications are preferred.
This listing was posted by a verified recruiter at Singlife. Report this listing
JobSpring