Principal Cybersecurity Engineer

3 weeks ago


Singapore SYSTEMS ON SILICON MANUFACTURING COMPANY PTE LTD Full time

SSMC (Systems on Silicon Manufacturing Company Pte. Ltd.), is a Joint Venture between NXP and TSMC. We offer flexible and cost effective semiconductor fabrication solutions by maintaining fully equipped SMIF cleanroom environment, 100% equipment automation and proven wafer-manufacturing processes.

At SSMC , every career journey is unique and rewarding. We're looking for innovative, passionate, and talented people like you to join our team.

We're searching for a Principal Cybersecurity Engineer to be part of our IT Department diverse team of talent. You will be responsible in Network Security and Systems Support. This is a 1-year contract role.

What you will be working on:

  • To support, manage security tools, provide solutions, identify, secure both enterprise IT applications, servers, and cloud environments) and operational technology (OT) systems.
  • Assess, deploy, and monitor cybersecurity tools across the manufacturing network.
  • Secure IT/OT infrastructure.
  • Network security.
  • Conduct vulnerability assessments and penetration tests on plant floor systems.
  • Configure and manage firewalls, IDS/IPS, and endpoint security.
  • Customize workflows, forms, and reports to meet business user needs.
  • Perform security assessments on web applications, APIs, and microservices (e.g., static and dynamic analysis, vulnerability scanning).
  • Identify and remediate application vulnerabilities such as SQL injection, XSS, CSRF, and insecure deserialization.
  • Work closely with development teams to integrate security into the software development lifecycle (SDLC) through secure coding practices and threat modeling.
  • Lead and conduct security code reviews, identifying vulnerabilities and recommending mitigation strategies.
  • Advise developers on secure coding practices, OWASP Top 10, and security requirements for application design.
  • Secure configuration of servers, databases, and web services to ensure they are hardened according to industry best practices (CIS benchmarks, NIST).
  • Work with DevOps teams to implement security controls such as Infrastructure-asCode (laC) and container security (e.g., Docker, Kubernetes).
  • Integrate security tools (e.g., SAST/DAST, vulnerability scanners) into CI/CD pipelines to ensure continuous security checks during development and deployment.
  • Strong scripting skills (Python, Bash, PowerShell, etc.) to automate security tasks such as patching, monitoring, and reporting.
  • Experience in responding to application and server security incidents, including incident detection, triage, and mitigation.
  • Familiarity with SIEM tools and log analysis for identifying potential security incidents.
  • Work with engineering to apply security patches and firmware updates safely.
  • Develop playbooks for incident response specific to OT environments.
  • Coordinate with IT Security to bridge IT/OT cybersecurity strategy.

More About You:

  • Bachelor's or Master's degree in Computer Science, Data Engineering, or a related field.
  • Certifications: Security+, GICSP, CISSP, or similar (preferred)
  • Certified Ethical Hacker (CEH)
  • Atleast 6 years of Cybersecurity experience.
  • Cybersecurity experience, including manufacturing or industrial IT
  • Experience with network & Security tools
  • Experience with web application security concepts, including secure coding practices, encryption, and secure communications.
  • Experience with tools for static and dynamic application security testing (SAST/DAST) such as Checkmarx, Veracode, or SonarQube.
  • Experience with vulnerability scanning tools such as Burp Suite, Nessus, and others.
  • Expertise in securing Linux/Unix and Windows servers, including hardening, patching, and configuring secure server environments.
  • Experience of configuration management and automation tools (e.g., Ansible, Terraform, Chef, Puppet).
  • Experience with firewalls, intrusion detection/prevention systems, and VPNs.
  • Strong scripting skills (Python, Bash, PowerShell, etc.) to automate security tasks such as patching, monitoring, and reporting.
  • Experience with CI/CD pipelines and integrating security into these pipelines.
  • Experience in responding to application and server security incidents, including incident detection, triage, and mitigation.
  • Experience with SIEM tools and log analysis for identifying potential security incidents.
  • Experience with industry security frameworks such as NIST 800-53, ISO 27001, ar CIS Controls.
  • Knowledge of industrial protocols (¢.g., Modbus, DNP3, OPC-UA, Ethernet/IP).
  • Monitor and analyze OT network traffic for anomalies and threats.
  • Strong understanding of OWASP Top 10 security risks and mitigation strategies.
  • Strong communication skills and the ability to work collaboratively with cross-functional teams.
  • A proactive, self-motivated individual who can identify risks and take the initiative to resolve them.
  • Ability to stay updated with the latest trends in cybersecurity, application security, and emerging threats.
  • Good team player
  • Must be able to work independently.

SSMC is committed to equal employment opportunities and abides by the Tripartite Guidelines on Fair Employment Practices (TGFEP). All qualified applicants will receive non-discriminatory consideration for employment on the basis of merit and regardless of age, race, gender, religion, marital status and family responsibilities, or disability, or any other attributes as protected by the relevant laws.

#J-18808-Ljbffr

  • Singapore DSO National Laboratories Full time $120,000 - $240,000 per year

    JOB DESCRIPTIONDSO National Laboratories (DSO) is Singapore's largest defence research and development (R&D) organisation, with the critical mission to develop technological solutions to sharpen the cutting edge of Singapore's national security. At DSO, you will develop more than just a career. This is where you will make a real impact and shape the future...


  • Singapore ANTINA PTE. LTD. Full time

    PURPOSE The role entails managing the security of the company's IT and 5G networks by ensuring the infrastructure is adequately protected through the adherence and implementation of regulatory and industry best practices, identifying and mitigating risks through the establishment of robust security policies and controls. MAJOR DUTIES AND RESPONSIBILITIES...


  • Singapore Singapore Technologies Engineering Ltd Full time

    Job ID: 19878 - Location: Aero - 600 West Camp Road, SG - Description: - We are seeking a talented and motivated Assistant Principal Engineer / Principal Engineer with strong communication skills to join our dynamic team, to drive cybersecurity product innovation. **Key Responsibilities**: - Lead strategic cybersecurity projects and product development...


  • Singapore NodeFlair Full time

    **Job Summary**: **Job Type** Permanent **Seniority** Principal **Years of Experience** At least 10 years **Tech Stacks** Swift - In this role, you will not only act as a coach and thought leader but also serve as a mentor to your colleagues, showcasing leadership and consulting skills. Your ability to navigate Asian markets and engage with clients from...

  • [lta-itcd] Lead

    7 days ago


    Singapore LTA Land Transport Authority Full time

    [What the role is] LEAD / PRINCIPAL ENGINEER, CYBERSECURITY OPERATIONS [What you will be working on] You will join the Cybersecurity Operations team to strengthen cybersecurity readiness, detection and incident management capabilities of Land Transport CIIs, digital IT systems against cyber threats and to ensure the continuity of the essential services....


  • Singapore Ministry of Defence Singapore Full time

    Land Transport Authority Fixed Terms Closing on 17 Sep 2025 What the role is PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER, CYBERSECURITY MONITORING & INCIDENT RESPONSE What you will be working on You will be responsible for: Perform monitoring and analyse security alerts from various security tools and threat intelligence sources ...


  • Singapore Ministry of Defence Singapore Full time $150,000 - $200,000 per year

    Land Transport AuthorityFixed TermsClosing on 17 Sep 2025What the role isPRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER, CYBERSECURITY MONITORING & INCIDENT RESPONSEWhat you will be working onYou will be responsible for:Perform monitoring and analyse security alerts from various security tools and threat intelligence sourcesLead incident response...


  • Singapore ST Engineering Group Full time $150,000 - $250,000 per year

    We are seeking a talented and motivated Assistant Principal Engineer / Principal Engineer with strong communication skills to join our dynamic team, to drive cybersecurity product innovation.Key Responsibilities:Lead strategic cybersecurity projects and product development teams, overseeing the full software development lifecycle from ideation to...


  • Singapore ANTINA PTE. LTD. Full time

    PURPOSE The role entails managing the security of the company's IT and 5G networks by ensuring the infrastructure is adequately protected through the adherence and implementation of regulatory and industry best practices, identifying and mitigating risks through the establishment of robust security policies and controls.MAJOR DUTIES AND RESPONSIBILITIES OF...


  • Singapore ST Engineering Full time $150,000 - $250,000 per year

    Job ID: 19878Location:Aero - 600 West Camp Road, SGDescription:We are seeking a talented and motivated Assistant Principal Engineer / Principal Engineer with strong communication skills to join our dynamic team, to drive cybersecurity product innovation.Key Responsibilities:Lead strategic cybersecurity projects and product development teams, overseeing the...