Security Engineer

14 hours ago


Singapore User Experience Researchers Pte Ltd (Singapore) Full time

About The Security Engineer Role We’re looking for a Security Engineer to manage identity and access controls, conduct audits, and oversee privileged access to ensure compliance and protect enterprise systems. The role involves coordinating user access reviews, supporting IAM operations, and driving process improvements to strengthen security and regulatory compliance. Key Responsibilities User Access Review (UAR) ManagementOrchestrate and manage comprehensive user access review cycles, including monthly, quarterly, and annual certification processes to ensure compliance with organisational security policies and regulatory requirements. Oversee the complete UAR lifecycle from initial data extraction through to final certification, ensuring accuracy and timeliness of all access review activities. Compile and validate access data from multiple enterprise systems, cross‑referencing user permissions and validating accuracy of access rights across all applications and platforms. Coordinate extensively with stakeholders across the organisation to obtain timely responses and certifications, managing relationships to ensure review completion within required timeframes. Track and follow up on access exceptions, working closely with system owners to ensure prompt remediation of identified compliance issues and security risks. Maintain comprehensive documentation of UAR processes, findings, and remediation activities to support audit requirements and continuous improvement initiatives. Privileged Access ManagementManage privileged access reviews within CyberArk environment, ensuring appropriate oversight of high‑risk access permissions and maintaining security of critical systems. Conduct regular assessments of privileged accounts to ensure principle of least privilege is maintained and access remains appropriate for business requirements. IAM Audit and ComplianceConduct comprehensive IAM audits to assess the effectiveness of identity governance controls and identify gaps in access management processes. Perform detailed analysis of user access patterns, identifying anomalies, orphaned accounts, and potential security risks through systematic audit procedures. Prepare detailed audit reports documenting findings, risk assessments, and recommended remediation actions for management and external auditors. Support internal and external audit activities by providing evidence of IAM controls, access logs, and compliance documentation. Maintain audit trails for all identity management activities, ensuring comprehensive documentation for regulatory compliance and forensic analysis. Identity Management OperationsSupport identity management cleanup initiatives including process review, requirement documentation, user acceptance testing (UAT), and ongoing Day 2 IAM operations. Collaborate with technical teams to implement identity governance improvements and automation opportunities to enhance operational efficiency. Participate in the design and implementation of identity management solutions that align with enterprise security architecture and compliance requirements. Compliance and Risk ManagementEnsure all identity and access management activities comply with internal policies, regulatory requirements, and industry best practices. Identify and assess identity‑related risks, developing mitigation strategies and working with stakeholders to implement appropriate controls. Support internal and external audits by providing comprehensive documentation and evidence of access management controls and processes. Conduct risk‑based access assessments to prioritise remediation efforts and resource allocation. Process Improvement and DocumentationContinuously evaluate existing IAM processes to identify opportunities for automation, streamlining, and efficiency improvements. Develop and maintain detailed process documentation, standard operating procedures, and training materials for IAM activities. Collaborate with cross‑functional teams to implement process improvements and technology solutions that reduce manual effort whilst maintaining security and compliance standards. Requirements Technical ExperienceProven experience in Identity and Access Management, with particular expertise in user access reviews and privileged access management systems such as CyberArk. Hands‑on experience with enterprise identity management platforms and access governance tools. Strong understanding of identity governance principles, including role‑based access control (RBAC), segregation of duties, and principle of least privilege. Experience with identity management lifecycle processes including provisioning, de‑provisioning, and access certification. IAM Audit and Assessment SkillsDemonstrated experience in conducting IAM audits and access assessments across complex enterprise environments. Proficiency in audit methodologies and frameworks specific to identity and access management, including COBIT, COSO, and ITIL. Strong analytical skills with ability to identify patterns, anomalies, and potential security risks through data analysis and system reviews. Experience with audit tools and technologies for automated access analysis, reporting, and compliance monitoring. Knowledge of forensic analysis techniques for investigating access‑related security incidents and policy violations. Ability to develop and execute comprehensive audit programmes covering all aspects of identity lifecycle management. Process Management SkillsDemonstrated ability to manage complex, multi‑stakeholder processes with high attention to detail and accuracy. Experience in coordinating with diverse stakeholder groups to achieve compliance and operational objectives within tight timeframes. Strong project‑management skills with ability to handle multiple concurrent initiatives whilst maintaining quality standards. Experience in process documentation, improvement, and standardisation activities. Compliance and Risk ManagementKnowledge of regulatory compliance requirements related to access management and data protection, including GDPR, SOX, and industry‑specific regulations. Understanding of risk assessment methodologies and ability to identify and mitigate identity‑related security risks. Experience supporting audit activities and maintaining comprehensive audit trails for access management activities. Knowledge of compliance frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, and COBIT. Documentation and ReportingStrong technical writing skills with ability to produce clear, comprehensive audit reports and compliance documentation. Experience in creating executive‑level reporting and dashboards for IAM metrics and compliance status. Ability to translate complex technical findings into business impact assessments and actionable recommendations. Proficiency in data visualisation tools and techniques for presenting audit findings and compliance metrics. Communication and Stakeholder ManagementExcellent interpersonal and communication skills with ability to work effectively with stakeholders at all organisational levels. Strong problem‑solving abilities with experience in exception handling and issue resolution. Ability to translate technical concepts into business language for non‑technical stakeholders. Experience in managing audit relationships and coordinating with external auditors and regulatory bodies. Preferred Qualifications Relevant certifications such as CISSP, CISM, CISA, CGEIT, or vendor‑specific certifications. Professional audit certifications such as CIA or CISA. Experience with automation tools and scripting to improve operational efficiency. Knowledge of Singapore Government security standards and compliance frameworks. Familiarity with GRC platforms and audit management systems. Seniority Level Mid‑Senior level Employment Type Full‑time Job Function Information Technology Referrals increase your chances of interviewing at User Experience Researchers Pte Ltd (Singapore) by 2x We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI. #J-18808-Ljbffr



  • Singapore Menlo Security Inc. Full time

    A global cybersecurity firm in Singapore is seeking a Senior Sales Engineer to support customers by articulating the benefits of security solutions. This full-time role requires 8+ years in pre-sales and a strong knowledge of IT security technologies. The ideal candidate is proactive, accountable, and possesses exceptional communication skills. This position...


  • Singapore INSYGHTS SECURITY PTE. LTD. Full time

    **Key Responsibilities** As a Cyber Security Engineer, your primary role will be, but are not limited to: 1) Incident Investigation - Perform in-depth analysis of security alerts escalated by L1 analysts. - Investigate suspicious activity using SIEM, EDR, NDR, firewall and other logs.Use threat intelligence to enrich investigations and identity attacker...


  • Singapore Security Xchange LLP Full time

    **Job Title** - Inhouse Security Executive- **Job Type** - Full time**Required Position** - OE**Location** - Island Wide**Nearest MRT** **Job Site Type** **Shift** - Day**Salary** - 2500 - 3500**Pay** - Basic**Payment Rate** - Monthly**Requirements**: **PRIMARY DUTIES AND RESPONSIBILITIES** 1. Direct and administer all security programmes within Group. 2....


  • Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    **General Summary - The APAC security project engineer is responsible for providing project and program management for all aspects of APAC security projects and programs. - The primary focus of the role will be in managing the deployment of technology driven physical security solutions such as access control, CCTV and intrusion detection. - The role will...


  • Singapore Orca Security Full time

    A leading cloud security company in Singapore is seeking a Customer Success Engineer for Strategic Accounts. You will serve as a technical quarterback for major clients, ensuring they maximize the value of the platform while driving cloud security strategies. Ideal candidates have over 7 years in technical customer-facing roles and fluency in English and...

  • IT Engineer

    2 weeks ago


    Singapore Allinton Engineer & Trading Pte Ltd Full time $96,000 - $180,000 per year

    CompanyAllinton Engineer & Trading Pte LtdDesignationIT EngineerDate Listed27 Oct 2025Job TypeEntry Level / Junior ExecutiveIntern/TSJob PeriodImmediate Start, For At Least 3 MonthsProfessionIT / Information TechnologyIndustryComputer and ITLocation Name331 Jalan Besar, SingaporeAddress331 Jln Besar, Singapore 208983MapAllowance / Remuneration$800 - 1,500...

  • Software Engineer 1

    5 days ago


    Singapore Abnormal Security Full time

    About the Role This position exists to support the development and maintenance of SEG displacement products delivered by the Critical Email Products (CEP)team, within the Message Security Products Organisation. The role plays a critical part in shaping and executing the technical direction, ensuring quality and timely delivery, and collaborating with...


  • Singapore Menlo Security, Inc. Full time

    A leading cybersecurity firm in Singapore is seeking a Senior Sales Engineer to provide technical sales support and guidance to customers. The ideal candidate will have over 8 years of pre-sales experience in networking or security, excellent communication skills, and a strong sense of accountability. Responsibilities include leading Proof of Concept...


  • Singapore Astrol Security Engineering Pte Ltd Full time

    A security engineering firm in Singapore is seeking candidates for hands-on roles involving the installation and maintenance of security systems. The ideal candidate should possess an ITE/Diploma in relevant fields and a Class 3 driving license is preferred. Responsibilities include conducting site surveys, troubleshooting, and preparing technical reports....


  • Singapore Abnormal Security Full time

    About the Role Abnormal AI is seeking an experienced and technically strong Machine Learning Engineer (MLE) to join the Misdirected Email Prevention (MEP) team. The MEP team plays a critical role in preventing accidental data loss by detecting and blocking misdirected outbound emails, delivering protection at scale without adding operational burden to...