Skip to content

Open nowPosted yesterday

Security Engineer

MyCareersFuture94,028 open roles

Pay
SGD 5,000 – SGD 6,500 a month
Where
West, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity EngineerMyCareersFuture · West, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.9%7 days
  4. 14.2%14 days
  5. 34.1%30 days
This job: posted yesterday

The posting

The Security Engineer is mainly responsible for the end-to-end implementation, integration, and operationalization of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on deployment, migration, onboarding, and integration of privileged access controls, certificates, and machine identities in line with security best practices.

The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver secure, scalable, and compliant PAM, CLM and 2FA solutions.

Key Responsibilities

1. CyberArk Deployment & Implementation

  • Install, configure, and harden CyberArk components: Enterprise Password Vault (EPV)Central Policy Manager (CPM)Privileged Session Manager (PSM)Password Vault Web Access (PVWA)Privileged Threat Analytics (PTA)Privilege Cloud ConnectorCyberArk Adaptive Multi-Factor Authentication (MFA)CyberArk Vendor Privileged Access Manager (Vendor PAM)
  • Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo
  • Develop and Maintain PSM and CPM connectors
  • Execute full-cycle deployment activities: Infrastructure build Installation & configuration System validation and testing
  • Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing

2. Venafi Deployment & Machine Identity Management

  • Install, configure, and administer Venafi TLS Protect platform.
  • Design and document Venafi architecture.
  • Configure machine identity lifecycle management.
  • Implement: Certificate discovery Certificate inventory management Certificate automation workflowsCA integrations
  • Enable: Automated certificate issuance Automated renewal Certificate revocation processes Self-service certificate requests
  • Configure network discovery and certificate intelligence capabilities.
  • Monitor certificate compliance and certificate expiry risks.

3. Migration & Upgrade Activities

  • Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)
  • Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)
  • Handle: Vault data migration Cutover planning and execution
  • Support post-migration stabilization and user acceptance testing

4. Account Onboarding & Policy Management

  • Onboard privileged accounts, systems, and applications into CyberArk
  • Configure: Password policies Rotation and reconciliation settings Access controls and role-based permissions
  • Define and implement operational procedures (e.g., break-glass access, onboarding workflows)

5. Integration with Enterprise Systems

  • Integrate CyberArk with: SIEM, ITSM, IAM platforms Endpoint and network security tools
  • Enable session recording, monitoring, and audit logging across systems

6. Integration & Automation

  • Integrate CyberArk and Venafi with:
  • Active Directory / LDAP
  • Entra ID
  • SIEM platforms
  • Splunk
  • QRadar
  • ITSM platforms
  • ServiceNow
  • Identity and Access Management systems
  • Security monitoring platforms
  • Certificate Authorities
  • Microsoft CA
  • DigiCert
  • Entrust
  • GlobalSign

7. PAM Architecture & Design Support

  • Support solution architects in: Gathering requirements
  • Reviewing technical architecture
  • Conducting technical workshops and design validation
  • Contribute to architecture documentation and solution design reviews

8. Operations Readiness & Knowledge Transfer

  • Develop and document: Runbooks SOPs Operational procedures
  • Conduct knowledge transfer sessions for operations teams
  • Ensure readiness for ongoing PAM operations and support

9. Troubleshooting & Support

  • Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues
  • Certificate lifecycle failures
  • Discovery issues
  • Renewal failures
  • CA integration issues
  • Patch Management
  • Automation workflow failures
  • Perform root cause analysis for: Access issues Password rotation failures xSession management failures
  • Work with vendors and internal teams to resolve incidents

Technical Skill Requirements:

Mandatory

  • CyberArk Certified Delivery Engineer (CDE-PAM / Privilege Cloud)
  • Strong hands-on deployment experience with:
  • EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy
  • Solid understanding of:
  • Windows Server & Linux (RHEL)
  • Active Directory / LDAP
  • Networking (firewalls, ports, VPN)
  • Scripting
  • Knowledge in IAM, Security Best Practices and Zero Trust Methodologies

Preferred

  • Experience in large-scale enterprise deployments (500+ systems onboarding)
  • Venafi TLS Protect Certification
  • Venafi Machine Identity Management Certification
  • Familiarity with:
  • DevOps secrets (e.g., Conjur)
  • Cloud PAM (CyberArk Privilege Cloud)
  • Strong Expertise in PSM and CPM connector developments
  • Experience with PKI and certificate lifecycle management
  • TLS Protect
  • Certificate Lifecycle Management
  • Discovery & Monitoring
  • Machine Identity Management
  • Certificate Authority Integrations
  • Venafi
  • TLS Protect
  • Certificate Lifecycle Management
  • Discovery & Monitoring
  • Machine Identity Management
  • Certificate Authority Integrations
  • Integration experience with:
  • Splunk / QRadar other SIEMs
  • ServiceNow
  • MFA solutions

Soft Skills & Competencies

  • Strong stakeholder engagement & communication skills
  • Ability to lead technical workshops and discussions
  • Structured and documentation-driven mindset
  • Experience working in project-based delivery environments

Typical Deliverables

  • CyberArk deployment build (Vault, CPM, PSM, PVWA, PTA, CyberArk Cloud, Vendor PAM, MFA)
  • Migration and upgrade runbooks
  • System onboarding documentation
  • SOPs and operational guides
  • Integration configuration documents
  • Venafi TLS Protect implementation.
  • Certificate discovery and automation setup
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.