Back to search
Bond Financial Group Linkedin · Posted 14d ago

Senior Security Engineer

Singapore

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Role Overview

The Senior Security Engineer is a hands-on security engineer responsible for implementing and operating the organisation's security controls and tooling. Reporting to the Information Security Lead, this roleexecutes security operations, supports IAM administration, and produces control evidence for the ISO 27001:2022 certification programme.


Key Responsibilities

Security Operations

  • Operate and tune security monitoring, detection, and alerting; triage and investigate security events, escalating per defined runbooks.
  • Lead technical containment and remediation during security incidents; draft post-mortem findings and track remediation to closure.
  • Coordinate day-to-day with the SoC team and MSSP; validate findings from penetration tests and vulnerability scans and drive remediation.


Identity, Access and Platform Security

  • Administer IAM controls including SSO, MFA, and PAM; execute user provisioning, deprovisioning, and periodic access reviews.
  • Operate and maintain email security gateways and endpoint protection platforms.
  • Support secure development reviews against OWASP standards and assist with security architecture reviews and threat modelling.


Compliance and Support

  • Implement ISO 27001:2022 controls and collect audit evidence; maintain control documentation and support surveillance audits.
  • Contribute to policy reviews with findings from operations and the evolving threat landscape.
  • On-call availability is required to support 24x7 incident response coverage.


Requirements

Experience

  • 8+ years of progressive information security experience with hands-on security operations in a production environment.
  • Proven experience in incident response, containment, and post-incident reviews.
  • Experience administering IAM platforms (SSO, MFA, PAM) and security tooling.
  • Experience working with MSSPs and penetration testing firms; ISO 27001:2022 and regulated industry exposure preferred.
  • Familiarity with MAS Technology Risk Management (TRM) Guidelines is a bonus.


Technical Skills

  • IAM platforms: SSO (e.g. Okta, Azure AD or equivalent), MFA, PAM (e.g. CyberArk, BeyondTrust, or equivalent)
  • Cloud security: security hardening, configuration review, and monitoring of cloud environments (AWS preferred)
  • Security monitoring, SIEM, and detection/alerting operations
  • Email security gateways and endpoint protection platforms
  • Vulnerability management and remediation tracking
  • Secure development frameworks: OWASP, SANS CWE Top 25; threat modelling fundamentals
  • ISO 27001:2022 control implementation and evidence collection


Qualifications

  • Bachelor's degree or higher in Information Security, Computer Science, or a related discipline.
  • CISSP, CISM, or GIAC certifications preferred.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search