Skip to content

Open nowPosted today

Cybersecurity - DevSecOps

MyCareersFuture99,426 open roles

Pay
SGD 6,000 – SGD 10,000 a month
Where
West, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCybersecurity - DevSecOpsMyCareersFuture · West, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. MyCareersFuture postings stay open a median of 4 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted today

MyCareersFuture median: 4 days open

The posting

Role Description

The Cybersecurity DevSecOps Engineer at Thales plays an important role in integrating security into the system lifecycle, ensuring secure, compliant and resilient systems. This role focuses on vulnerability management, configuration audits, compliance monitoring, and threat detection to mitigate risks across Thales’ IT and OT environments.

The Cybersecurity DevSecOps Engineer will collaborate with cross-functional teams (DevOps, SOC, IT Operations) to automate security controls, enforce hardening standards and security audit log configuration, correlation and alert rules, ensuring adherence to global and regional compliance frameworks (e.g., ISO 27001, NIST, Singapore’s CCoP, ICT&SS).

Skills, Responsibilities and Activities

Vulnerability Management. Skills include: be able to understand vulnerability scan reports to be able to identify, assess and remediate security vulnerabilities to reduce exposure to cyber threats. Activities include:

· Vulnerability Analysis & Prioritization: Process scan reports (using tools such as Nessus, Nmap, Trivy) to identify critical/high-severity vulnerabilities.

· Assess risks using CVSS, EPSS, KEV, SSVC methodologies, prioritising remediation based on business impact and exploitability.

· Remediation Support: Collaborate with the relevant engineering teams to apply patches, workarounds, or mitigations.

· Validate fix effectiveness and track remediation progress

Reporting & Documentation. Skills: be able to draft clear, actionable reports summarizing:

· Vulnerability details (CVE, affected systems, risk level).

· Recommended hardening rules or corrective actions.

· Risk analysis (likelihood, impact, business context).

· Present findings to stakeholders (IT, Security, Management).

Audit& Monitoring. Skills include ensuring systems are securely configured and monitored for threats. Activities include

· Configuration Compliance Reviews. Validation of host configurations (RHEL, Windows, Databases, Network Equipment) against:

· CIS Benchmarks

· Thales-specific hardening standards

· Other standards as required ie STIGs (Security Technical Implementation Guides)

· Identify misconfigurations and recommend corrective actions.

Integration and Hardening. Skills include ability to integrate, applying hardening benchmarks as well as customized hardening configurations to COTS products (Operating systems & network equipment) and verification of hardened configurations. Activities include:

· Selecting hardening frameworks CIS, defining custom configurations for the environment

· Application of customised hardening using automation tools

· Integration and verification of Cyber requirements for Cyber COTS (such as IAM, PAM, SIEM, EDR,EPP, Keys management, Firewall)

· Verification of hardening baseline during vulnerability scans and test campaigns

SIEM Log Enhancement and Analysis. Skills includes Audit log tuning, analysis and acknowledge of alert frameworks. Activities include:

· Advise on logging improvements for better threat detection (e.g.,missing logs, false positives/negatives).

· Support SIEM rule tuning, advising on the optimisation of correlation rules to enhance alert accuracy in QRadar/Splunk, reducing falsepositives and improving threat detection.

· Align rules with MITRE ATT&CK framework and threat intelligence feeds.

· Analysis of SIEM/SOC alerts to determine:

· Legitimacy (true positive vs. false positive).

· Severity (using MITRE ATT&CK for classification).

· Required actions (containment, remediation, escalation).

Governance & Compliance. Skills include knowledge of regulatory and internal security standards, ensuring their adherence. Activities include:

· Compliance Monitoring, tracking adherence to frameworks such as:

· Global: ISO 27001, NIST, ITIL

· Regional (Singapore): CCoP (Cybersecurity Code of Practice), ICT&SS (Infocomm Technology & Security Standards)

· Maintaining audit evidence for compliance assessments.

· Standards &Policy Support, assisting in security standards change analysis (e.g., updates to CIS, STIGs, or Thale’s policies).

· Ensuring DevSecOps practices align with corporate governance requirements.

· Risk & Gap Analysis, identifying gaps between current state and required compliance levels.

· Propose mitigation strategies to close gaps.

On-Call Support. Activities Include:

· Provide on-call support as required to the customer when restored.

Technical Skills, Qualifications & Experience

Technical Skills

Vulnerability Management : Nessus, Nmap, Trivy, CVSS, EPSS, KEV, SSVC

Configuration Auditing : STIGs, CIS Benchmarks, SCAP, OpenSCAP

SIEM & Monitoring : QRadar, Splunk, ELK, MITRE ATT&CK, Threat Intelligence

Scripting & Automation : Python, Bash, PowerShell (for report automation)

Compliance Frameworks : ISO 27001, NIST, ITIL, CCoP, ICT&SS

Cloud & Infrastructure : RHEL, Windows Server, Databases (Oracle, SQL), Network Devices

DevSecOps Tools : Jenkins, GitLab CI/CD, Ansible, Terraform (for IaC security)

Soft Skills

  • Analytical Thinking: Ability to interpret scan reports, logs, and compliance gaps.
  • Stakeholder Communication: Clear reporting and collaboration with non-security teams.
  • Problem-Solving: Proactive in identifying and mitigating risks.
  • Attention to Detail: Ensure accuracy in audits, reports, and remediation tracking.

· A positive attitude combined with excellent interpersonal and motivational skills.

· Sound judgement and independent decision-making capability where necessary

· Excellent written and oral communication skills in English

Qualifications

  • Degree in Engineering, Computer Science or related discipline majoring in Cybersecurity or relevant industry experience

Essential Experience

· 5+ years of proven experience in the Cybersecurity field

· Strong knowledge in Cybersecurity solutions (e.g. IAM, PAM, SIEM, EDR, Keys, Firewall)

· Demonstrated ability to achieve effective outcomes in a multidiscipline, multi-culture environment

· Experience in system hardening and hardening review based on CIS Benchmarks or DISA STIG frameworks.

Desirable:

  • Industry qualifications, such as CISSP

· Postgraduate studies in Cybersecurity

· Vulnerability Management: CVMP (Certified Vulnerability Management Professional)

· Compliance: ISO27001 Lead Auditor, CIS Controls, ITIL v4

· SIEM/Monitoring: Splunk Core Certified User, IBM QRadar SIEM

· Cloud/Infrastructure: RHCSA (Red Hat), Microsoft Certified: Security Administrator

· DevSecOps: Certified DevSecOps Professional (CDP), Practical DevSecOps

· Knowledge of ISO27001 foundational requirements.

· Experience in country security regulations (e.g. CCOP and IM(ICT&SS) for Singapore)

· Experience in ATM Domain and related standards eg. ICAO, Eurocontrol ,or safety critical systems.

· Experience in System Engineering tools eg. DOORs, Polarian, Jira

· Experience invulnerability management and threat modeling

· Experience inworking in a Scaled Agile Framework (SAFe)

General / Special Requirements

· Assist in ensuring a harmonious work environment in all departments that you are working with by upholding Thales' key values.

· An advocate for diversity and inclusion who will be actively involved in implementing change initiatives to achieve our diversity goals

· An advocate fora culture of continuous improvement

· An advocate for Accountability, transparency and curiosity

· Comply with all relevant company Occupational Health, Safety and Environmental policies and framework and work practices with the intent of preventing or minimising accidental exposures to self, colleagues, visitors and/or the environment and to ensure a safe work practises at all times.

· Comply with all relevant Company policies and procedures.

· Occasional international travel may be required

SPECIAL REQUIREMENTS:

· Eligible to obtain Singapore CAT2 Clearance

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.