Senior Security Engineer

1 day ago


Singapore F5 NETWORKS SINGAPORE PTE LTD Full time
Roles & Responsibilities

POSITION SUMMARY:

The Senior Security Engineer is a technical security position in the F5 Security Incident Response Team (F5 SIRT). Addressing security issues in F5 products is the responsibility of the F5 Security Incident Response Team (F5 SIRT). The F5 SIRT is a dedicated, global team that manages the receipt, investigation, and public reporting of security vulnerability information that is related to F5 products and networks.

The Senior Security Engineer position provides expert security technical leadership for F5 SIRT. This position requires complete Security Knowledge and an expert with regards to security threats, incident handling methodologies and offensive/defensive attack vectors. A Senior Security Engineer follows incident handling procedures to drive mitigation of security incidents and will be called to perform expert attack analysis, configuration suggestions, and potential onsite interaction. A Senior Security Engineer can handle multiple active issues of diverse scope simultaneously while maintaining good communication, particularly written communication to our customers, and accepts ownership of issues until a resolution is delivered or a business as usual state is returned, providing high customer satisfaction. When not engaged in incidents, a Senior Security Engineer will mentor other security related issues, researches emerging threats and both documents and presents their impact on F5 products and services. Advocates every single day for improving the security of F5 products and services.

A good candidate has a deep passion for security and a desire to help develop a security mindset in others. The role also requires a strong ability to work with incomplete information and to adapt to changing priorities.

PRIMARY RESPONSIBILITIES:

  • Responsible for upholding F5s business code of ethics & for promptly reporting violations of the code or other company policies
  • Monitors security issues in order to identify and act upon them as they occur
  • Participate in tier 2 and tier 3 security support
  • Provide expert incident handling and drives both attack analysis and mitigation options
  • Provides F5 customers with high-quality support experience
  • Manages multiple issues and prioritizes based upon customer and business needs, without direction
  • Effectively engages supporting escalation personnel, without direction
  • Ensure complete and clear incident documentation
  • Maintain incident documentation, participate in post-mortems, and write incident reports.
  • Continuous research into emerging threats and mitigation options
  • Independently develops and deliver security content and training based on research and testing within the security field and with F5 products to drive security mindset.
  • Perform general security awareness and specific security technology training
  • Engages in on-going training within the security field and with F5 products
  • Follows processes defined in F5's Quality Management System (QMS)
  • Work closely with others to develop incident response plans
  • Identify the gaps between the security incident response process and customers' needs, optimize/improve the workflow/process
  • Act as the technical lead, identify the knowledge/technical skill gaps in the team, develop a training plan for the team, mentor/train other members of the team
  • Identify trends and/or common knowledge gaps and ensure they are documented via the KCS Solve Loop
  • Ensure that security related knowledge is documented within KCS and represent Security within the KCS Evolve Loop, for example RCA feedback into product design & documentation
  • May lead projects and provide guidance/training to less experienced staff, mentoring.
  • Perform expert threat and vulnerability management, monitoring of CVE and vendor notifications
  • Evaluate and execute cross-functional security initiatives across the enterprise.
  • Work with cross functional Engineering teams to ensure all systems are properly remediated according to our policies and standards.
  • Lead steering committee(s) to analyze vulnerabilities and their impact to assess risk ratings
  • Provide strategic security analytics metrics and reports.
  • Provide security-related metrics for all levels including executive-level dashboards to demonstrate process effectiveness and remediation across the enterprise
  • Effectively communicate and document risks related to the vulnerability environment and appropriate levels of urgency to management and engineering staff
  • Represent Information Security on organizational project teams and ensure adherence to existing security policies and standards.
  • Work closely with Incident Response and Risk Management teams and leverage corporate tools to provide supporting documentation for remediation prioritization and emergency security coverage.
  • Ability to think with a security mindset. The successful candidate has a strong IT background with in depth knowledge of several key security practice areas: application security; network security, infrastructure security.

QUALIFICATIONS:

  • Minimum of 15 years experience in a technical security role such as support, monitoring or consulting (e.g. pen testing) working with relevant technologies
  • Information security subject matter expert
  • Expert understanding of industry standards such as CVE, CPE, and CVSS
  • Strong understanding of security frameworks and NIST standards
  • Appropriate security based qualification; CISSP, GCIH (or demonstrated skills and ability to obtain certification) – more than one certification preferred.
  • Public cloud certifications (or demonstrated skills and ability to obtain certification)
  • Expert experience with security incident handling processes, procedures and methodologies.
  • Expert technical experience with identifying and mitigating a breadth of attacks such as DDoS, web application, DNS and other network attacks.
  • Expert knowledge with common security vulnerabilities and the ability to judge their severity
  • Expert experience with working security incidents at corporate production environments
  • Experience working with network and packet analysis tools
  • BA/BS degree or equivalent experience
  • Expert knowledge with Web Application Firewalls, Firewalls and IPS/IDS
  • Expert experience with network vulnerability scanners
  • Expert OS hardening and security best practices
  • Knowledge of common Malware types and infection vectors

KNOWLEDGE, SKILLS AND ABILITIES

  • Hands on technical experience with and very knowledgeable on LAN/WAN operations, and/or networking hardware required
  • CVE and CERT experience
  • Expert knowledge of security offensive/defensive techniques and methodologies.
  • Expert understanding of security attack/defense methodologies (e.g. DNS, network TCP/IP, SSL and HTTP)
  • Intermediate understanding and working knowledge of TCP/IP, SSL, DNS, HTTP and common protocols.
  • Coding experience – having, in addition to Python, knowledge in other scripting languages
  • Understanding of the underlying mechanisms for security vulnerabilities at a code and assembly level, e.g. buffer overflows, input sanitisation
  • Knowledge of network and security monitoring tools
  • Familiarity with load balancers, WAF's and common network architectures
  • Working knowledge of standard UNIX/Linux command line tools
  • Hands-on technical experience with public clouds (e.g. AWS, Azure or GCP), and container-based deployments and orchestration tools (e.g. Kubernetes, Docker, Terraform and Ansible)
  • Knowledge of microservice architecture, modern application architecture and API security
  • Ability to generate new training and knowledge sharing content via various delivery method
  • Able to work with moderate supervision
  • Proven track record in a team environment
  • Analytical thinker with strong attention to detail
  • Must be able to read, write and speak English fluently, including technical concepts and terminology.
  • Must be able to relay technical information to customers with varying skill levels
  • Ability to create attack Proof of Concepts
  • Experience with incident tracking software, Seibel experience a plus
Tell employers what skills you have

Information Security
Remediation
Application Security
Azure
Hardware
Vulnerability Management
Investigation
Scripting
Networking
Python
Packet Analysis
API
Network Security
DNS
Security Awareness
CISSP

  • Singapore VANTAGE POINT SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesLocation: SingaporeRole Purpose:We are seeking an accomplished and proactive Senior Penetration Tester to lead our offensive security and penetration testing projects. The successful candidate will possess extensive practical experience, hold multiple industry-recognised certifications, and demonstrate strong leadership qualities. You...


  • Singapore PRO-TEC SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesJob ScopeMonitoring of Closed-Circuit Television (CCTV) for access control. Issuance of access pass. Security concierge service. Perform patrols to check for security lapses. Protect life, property and information. Generate and submit daily reports.RequirementsMin Senior Security Officer (SSO) grade Min GCE N/O levels or NTC...


  • Singapore PRO-TEC SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesJob Scope Monitoring of Closed-Circuit Television (CCTV) for access control. Issuance of access pass. Security concierge service. Perform patrols to check for security lapses. Protect life, property and information. Generate and submit daily reports.Requirements Min Senior Security Officer (SSO) grade Min GCE N/O levels or NTC...

  • SECURITY EXECUTIVE

    1 week ago


    Singapore HENDERSON SECURITY SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description & Requirements· Responsible and accountable for effectively managing the day-to-day operations/allocated contract sites and staffs by providing highest quality to employees and Clients· Conduct security and safety risk assessment surveys of the assignments allocated· Conduct investigations and vet incident reports...

  • security executive

    1 week ago


    Singapore HENDERSON SECURITY SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description & Requirements· Responsible and accountable for effectively managing the day-to-day operations/allocated contract sites and staffs by providing highest quality to employees and Clients· Conduct security and safety risk assessment surveys of the assignments allocated· Conduct investigations and vet incident reports...


  • Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    Roles & Responsibilities*HIRING PERMANENT SENIOR SECURITY OFFICERS (FLOATER)*Location: IslandwideBasic Salary: $3350.00Requirements Able to commit rotation shift ⁠Able to travel islandwideAdditional Benefits 13th Month AWS Comprehensive Medical Coverage Above MOM stipulated number of annual leave days*Interested applicant kindly call/Whatsapp to ...


  • Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    Roles & Responsibilities*HIRING PERMANENT SENIOR SECURITY OFFICERS (FLOATER)*Location: IslandwideBasic Salary: $3350.00Requirements Able to commit rotation shift ⁠Able to travel islandwideAdditional Benefits 13th Month AWS Comprehensive Medical Coverage Above MOM stipulated number of annual leave days*Interested applicant kindly call/Whatsapp to ...


  • Singapore RAPSYS TECHNOLOGIES PTE. LTD. Full time

    Roles & ResponsibilitiesAbout the RoleWe are seeking a highly skilled and experienced Senior Security Engineer with 5–7 years of experience in security operations. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions, with a primary focus on...


  • Singapore OPENSOURCE TECHNOLOGIES PTE. LTD. Full time

    Roles & ResponsibilitiesWe are seeking a highly skilled and experienced Senior Security Engineer with 5 to 7 years of experience in a security team. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions, with a primary focus on Trend Micro Apex One,...


  • Singapore OPENSOURCE PTE. LTD. Full time

    Roles & ResponsibilitiesAbout the RoleWe are seeking a highly skilled and experienced Senior Security Engineer with 5–7 years of experience in security operations. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions, with a primary focus on...


  • Singapore OPENSOURCE PTE. LTD. Full time

    Roles & ResponsibilitiesAbout the RoleWe are seeking a highly skilled and experienced Senior Security Engineer with 5–7 years of experience in security operations. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions, with a primary focus on...


  • Singapore HORIZON GLOBAL SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesAbout the RoleWe are seeking a highly skilled and experienced Senior Security Engineer with 5 to 7 years of experience in a security team. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions. The primary focus will be on...


  • Singapore HORIZON GLOBAL SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesAbout the RoleWe are seeking a highly skilled and experienced Senior Security Engineer with 5 to 7 years of experience in a security team. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions. The primary focus will be on...


  • Singapore U3 INFOTECH PTE. LTD. Full time

    Roles & ResponsibilitiesRole: Senior Network Security EngineerLocation: Central, Singapore Duration: 24 months ( extendable)We are seeking a highly skilled Senior Network Security Engineer with deep expertise in Network Security technologies. This is a technical, hands-on role within the Network Security Engineering & Deployment team. The ideal...


  • Singapore OPENSOURCE TECHNOLOGIES PTE. LTD. Full time

    Roles & ResponsibilitiesWe are seeking a highly skilled and experienced Senior Security Engineer with 5 to 7 years of experience in a security team. This role is critical in maintaining and enhancing the security posture of our organization by engineering, optimizing, and supporting enterprise security solutions, with a primary focus on Trend Micro Apex One,...


  • Singapore U3 INFOTECH PTE. LTD. Full time

    Roles & ResponsibilitiesRole: Senior Network Security EngineerLocation: Central, Singapore Duration: 24 months ( extendable)We are seeking a highly skilled Senior Network Security Engineer with deep expertise in Network Security technologies. This is a technical, hands-on role within the Network Security Engineering & Deployment team. The ideal...


  • Singapore PEOPLESEARCH PTE. LTD. Full time

    Roles & ResponsibilitiesSenior Engineer – Cyber SecurityOur client is looking for an experienced Cyber Security Engineer to maintain and improve their cybersecurity posture by implementing security solutions as well as monitoring, detecting and containing incidents to minimize impact.Responsibilities:Identify security gaps, perform threat risk assessments...


  • Singapore Security & Risk Solutions Pte Ltd Full time

    At Security & Risk Solutions Pte Ltd, we are seeking a highly skilled professional to fill the role of ASCC Design & Delivery Supervisor. This position plays a critical role in maintaining the operational integrity of our central security operations centre, the ASCC.The ideal candidate will have a robust technical background, coupled with exceptional...


  • Singapore METROPOLIS SECURITY SYSTEMS PTE. LTD. Full time

    Roles & ResponsibilitiesJob Responsibilities:Regulating Traffic Operate Security & Safety Systems Security Command Centre, Fire Command Centre (FCC) Monitoring Key Press Management Assist Ministries, Statutory Boards or Government Departments in law enforcement duties monitoring which may include anti-littering and anti-smoking enforcements Perform...


  • Singapore METROPOLIS SECURITY SYSTEMS PTE. LTD. Full time

    Roles & ResponsibilitiesJob Responsibilities: Regulating Traffic Operate Security & Safety Systems Security Command Centre, Fire Command Centre (FCC) Monitoring Key Press Management Assist Ministries, Statutory Boards or Government Departments in law enforcement duties monitoring which may include anti-littering and anti-smoking enforcements Perform...