Middleware Vulnerability Management Engineer

5 days ago


Singapore Sopra Steria I2S Full time

Company:

Sopra Steria is a listed European tech leader specializing in Consulting, Digital Services, and Software. With 60,000 employees worldwide across Europe, North America and Asia, Singapore serves as the HQ for our APAC operations. We focus on delivering Infrastructure, Cloud and Cybersecurity services across the region.

For this position, we are looking for a Middleware Vulnerability Consultant to assist one of our client - a leading investment bank.

Description:

This role is for a technical support position and he/she will be responsible to oversees Middleware Vulnerability Management. They must plan and rectify middleware products security vulnerabilities. He/she will help ensure the quality of Core Middleware services remains consistently high and Create Middleware management reporting and dashboard and adhere to all IT security policies to maintain system integrity and quality.

The candidate must have excellent technical knowledge matched by a "can do" hands-on attitude to develop automatic process to generate reports and dashboard and always work to minimize operational risk. Also capable of develop scripts to manage repetitive or mass deployment tasks. The successful candidate will be a member of a dynamic IT team and will work with other IT teams in Asia, Europe and Americas, so must possess strong organization skills, have good time management and excellent written and communication skills.

Responsibilities:

  • Responsible for the overall Middleware Vulnerability Management of Core Middleware systems in APAC (infrastructure in Singapore, Hong Kong, Japan and China) and regional oversight of the rest of APAC countries.
  • Must have a mindset to provide continuous team and service improvements, be risk adverse in change management, focus on mitigating middleware vulnerabilities and be eager to improve the monitoring, efficiency, reliability, capacity and quality of all IT services.
  • Strive to ensure 100% uptime for all Core Middleware systems infrastructure in APAC, taking into account business requirements.
  • Able to plan, test and execute Production changes successfully following a robust Change Management process.
  • Responsible for updating all live production documentation under their scope.
  • Has direct hands on experience managing to reduce hardware and software obsolescence across IT.

Business relationships:

  • Work closely with all major stakeholders of the Core Middleware Systems, and any team(s) with direct influence and dependencies.
  • Must build a strong relationship with our internal customers in APAC.
  • Have proven experience working collaboratively with all teams across all departments and refusing to work in silo mode.
  • Follow all Security policies
  • Contribute to management reports and dashboards
  • Report all variances from Norms and Standards
  • Ensure and practice all production Disaster Recovery and BCP processes are in place

Governance:

  • Follow Security policies
  • Contribute to management reports and dashboards
  • Report all variances from Norms and Standards
  • Ensure and practice all production Disaster Recovery and BCP processes are in place

Requirements

Essential Technical Knowledge/Skills:

  • At least years of technical experience in following middleware technologies listed below:
  1. Open source Apache HTTP Server (2.4.x)
  2. Open source Tomcat application Server (8.x, 9.x)
  3. Microsoft IIS server (IIS 8.5, 10)
  4. REDHAT Jboss EWS (Apache / Tomcat 5.x)
  5. REDHAT EAP application server (EAP 7.x)
  6. IBM WebSphere Application server BASE & ND (8.x, 9.x)
  7. IBM WebSphere MQ server (8.x, 9.0, 9.1, 9.2)
  8. Oracle WebLogic server (12.x, 14.x)
  • Analysis, remediation planning and execution for all overdue Vulnerabilities for IBM MQ, IBM WAS, Apache, Tomcat, Jboss EAP/EWS products.
  • Analysis, remediation planning and execution for all Critical Compliance deviations on Digital Platform assets, and ideally on High deviations for IBM MQ, IBM WAS, Apache, Tomcat, Jboss EAP/EWS.
  • Assess and implement Middleware technologies in line with compliance baseline and best practices, avoiding any disruptions to the business.
  • Understand the principles of vulnerability scoring, including CVE, to accurately assess and prioritize tasks according to potential impact.
  • Work with owners (system, network, application define realistic remediation timelines and verify patch applicability.
  • Draft remediation tickets, track progress in the ticketing system (e.g., ServiceNow) and close the loop with validation testing.
  • Ability to extract key details from large documents and take necessary action. Should be good with Excel built-in automation features.
  • Re‑scan remediated assets to confirm vulnerability closure.
  • Generate weekly, monthly, and quarterly dashboards (KPI: Mean Time to Remediate, % of assets compliant, open critical findings) using Tableau, Power BI, or Excel macros.
  • Present status and trend analysis to senior leadership and cross‑functional committees (e.g., Security Steering, Streeco, IT Governance).
  • Develop Ansible playbooks (Linux & Windows) and scripts (PowerShell, Python, Bash) to automate patch deployment, configuration hardening, and reporting.
  • Enhancement of the current processes for remediation for all APAC assets where the remediation owner is Digital Platform (including assets provided to and supported for CIB, WM, Cardif entities), on the vulnerability management and compliance management remits.
  • Continuous improvement of the security watch process for the products under APAC Digital Platform management, to proactively plan for patching.
  • Experience in creating and producing Weekly/Monthly reports and Dashboard KPI.
  • Obtain skill for reporting: Tableau / Power query / Excel Micro programing / Power BI / SQL query / Python / API.
  • Optional skill set: Prometheus / Grafana / Kibana / ELK
  • Obtain skill for automation: Ansible scripting + Ansible tower
  • Middleware Skill: IBM MQ, IBM WAS, Apache, Tomcat, Jboss EAP/EWS
  • To apply security vulnerability fixes on timely manner as per business needs.
  • To apply security hardening policies for middleware products on timely manner as per business needs.
  • Must have excellent written and verbal communication skills
  • Productive teamwork and strong analytical skills.
  • Demonstrate a systematic and logical approach to problem-solving.
  • Good presentation and documentation skills.
  • Ability to break down complex technical situations and adapt their language to all levels of discussion, from non-technical managers up to 3rd level System Experts.
  • Have knowledge and experience using agile methodologies and/or has been part of DevOps teams.
  • Be service oriented, customer focused, positive, committed and have an enthusiastic "can do" attitude.
  • Great time keeping skills and attention to detail is essential.
  • Flexibility to do shift work and some weekends or late after office hours at short notice.
  • Must be independent, organized, self-motivated, responsible, and able to complete tasks with little or no supervision.
  • Relishes taking ownership, being totally hands-on and comfortable directly interfacing with people at all levels of the organization.
  • Knows ITIL concepts and can apply them effectively

Other Value-Added Competencies:

  • A professional certification in any of the application server technology listed.
  • Analytical thinking and strong diagnostic information gathering
  • Client-oriented, strong communication and organization skills
  • Initiative and multitasking
  • Ability to work under pressure
  • Detail‑oriented with solid time‑keeping and multitasking skills.
  • Familiarity with Agile/Scrum, DevOps pipelines, and ITIL.

Benefits

  • Regular team buildings
  • 18 leave days / year
  • Insurance: GP, Hospitalisation, Dental and Optical
  • Annual bonus
  • Working hours: from 9am to 6pm, Monday to Friday
  • Training and certifications paths


  • Singapore Sopra Steria Full time

    Middleware Vulnerability Management Engineer Company: Sopra Steria is a listed European tech leader specializing in Consulting, Digital Services, and Software. With 60,000 employees worldwide across Europe, North America and Asia, Singapore serves as the HQ for our APAC operations. We focus on delivering Infrastructure, Cloud and Cybersecurity services...


  • Singapore NEWTONE CONSULTING PTE. LTD. Full time

    We are seeking an experienced Middleware Vulnerability Consultant to oversee vulnerability and compliance management for core middleware systems. This role involves planning and executing remediation for security vulnerabilities, ensuring compliance with industry standards, and developing automated processes for reporting and dashboard...


  • Singapore NEWTONE CONSULTING PTE. LTD. Full time

    We are seeking an experienced Middleware Vulnerability Consultant to oversee vulnerability and compliance management for core middleware systems. This role involves planning and executing remediation for security vulnerabilities, ensuring compliance with industry standards, and developing automated processes for reporting and dashboard creation....


  • Singapore Newtone Consulting Full time $90,000 - $120,000 per year

    We are seeking an experienced Middleware Vulnerability Consultant to oversee vulnerability and compliance management for core middleware systems. This role involves planning and executing remediation for security vulnerabilities, ensuring compliance with industry standards, and developing automated processes for reporting and dashboard...


  • Singapore Neurones IT Asia Full time

    Direct message the job poster from Neurones IT Asia Job Title: Middleware Vulnerability Consultant Position Purpose This role is for a technical support position and he/she will be responsible to oversee Middleware Vulnerability & compliance Management . They must plan and rectify middleware products security vulnerabilities and compliance deviation. He/she...


  • Singapore Newtone consulting Full time

    We’re looking for a Middleware Vulnerability Consultant to lead vulnerability and compliance management for core middleware systems. You’ll plan and execute remediation for security vulnerabilities, automate reporting, and ensure compliance with industry standards. If you have a hands‐on approach, strong technical expertise in middleware, and enjoy...


  • Singapore MALTEM ASIA PTE. LTD. Full time

    Maltem Asia is seeking a Middleware Vulnerability Consultant for an Investment Banking Client based in Singapore. This role is for a technical support position and he/she will be responsible to oversees Middleware Vulnerability & compliance Management. They must plan and rectify middleware products security vulnerabilities and compliance deviation. He/she...


  • Singapore Argyll Scott Singapore Full time

    Company / Role Overview This position offers an opportunity to join a high-performing regional IT operations team responsible for securing and maintaining critical middleware infrastructure across multiple APAC locations. The Middleware Vulnerability Consultant will play a central role in managing security compliance, patching, and remediation across a range...


  • Singapore JMA Global IT Solutions Sdn. Bhd Full time $120,000 - $156,000 per year

    Middleware Vulnerability Consultant (Permanent Role – Singapore)Location: Mapletree busines centre, SingaporeCompany: JMA Global IT Solutions (on behalf of our enterprise client)Employment Type: Permanent (Starts with 12 months contract to gauge performance)Eligibility: Open only to Singa.poreans (No quota for expats)Key Skills:Hands-on experience with IBM...


  • Singapore ARGYLL SCOTT CONSULTING PTE. LTD. Full time

    Vulnerability Analyst (Contract)Location: Singapore Contract Type: 12-months (Extendable & Convertible)Keywords: Vulnerability Management, Middleware, Compliance, Automation, Ansible, PowerShell, Python, IBM MQ, WebSphere, JBoss, Tomcat, Power BI Company / Role Overview This position offers an opportunity to join a high-performing regional IT operations team...