Duration: 12 months (Subject to an additional 12 months extention)
Budget: SGD 7,000 - 9,000/ mth
DBiz is looking for a Cyber Platform Engineer (Consultant) to join the Singapore team to support cybersecurity platform operations, maintenance, and lifecycle management across various client projects. The role will collaborate with cross-functional teams and vendors to ensure secure, compliant, and resilient operations for key security platforms (EDR, perimeter firewalls, DDoS/WAF, PAM). The selected candidate will be hands-on, disciplined in change management/documentation, and able to support audits and incident response across client environments.
Primary Responsibilities
- Operate and maintain cybersecurity platforms across client environments, including:
- Endpoint Detection & Response (EDR), Perimeter Firewalls, DDoS/WAF services, and Privileged Access Management (PAM).
- Execute routine and ad-hoc maintenance to ensure continuous functioning, compliance, and operational integrity (preventive maintenance, onboarding/offboarding, access/log reviews).
- Perform firewall operations & maintenance:
- Quarterly preventive maintenance (health checks, patching/firmware upgrades, diagnostics; may require onsite visits).
- Log/account reviews; annual configuration/rules reviews; ad-hoc configuration and cabling/shifting support.
- Raise and manage change requests for maintenance and system changes.
- Perform EDR platform operations & maintenance:
- Maintain EDR servers on Linux (RHEL), including OS/app/database components, backups, patching, and health checks.
- Monitor/troubleshoot services and endpoint sensors; support endpoint onboarding and OEM coordination.
- Perform DDoS/WAF administration:
- Act as first point of contact; manage onboarding/offboarding of protected web assets; maintain documentation/templates.
- Conduct periodic access/log/report reviews; manage SSL certificate renewals and rule optimisation with vendors/SOC.
- Perform PAM administration:
- Act as first point of contact; manage privileged account onboarding/offboarding and access reviews.
- Support investigations/incident response and related service/change requests.
- Support security compliance, assessments, and audits:
- Ensure platforms adhere to client cybersecurity policies and required standards; maintain evidence and trackers.
- Support incident response:
- Report incidents promptly; retrieve logs/configurations; produce investigation reports; implement preventive measures.
- Maintain backup & restoration readiness:
- Keep backup/restoration plans updated; coordinate annual restoration tests; maintain records/evidence.
- Produce maintenance reports after each cycle and maintain SOPs, inventories, configuration notes, and troubleshooting guides.
Key Requirements
- Strong foundation in enterprise networking (TCP/IP, VLANs, routing, NAT, DNS, segmentation, troubleshooting).
- Hands-on experience with Next-Gen Firewalls (Palo Alto or equivalent): policy/rules, NAT/routing, security profiles, log analysis, patching/firmware upgrades, backup/restore.
- Hands-on experience with EDR (Carbon Black or equivalent): server administration, sensor health monitoring, endpoint onboarding, log review, basic OS/app services maintenance.
- Experience with DDoS mitigation / WAF platforms (Cloudflare or equivalent): WAF/security rules, IP allow/deny, SSL cert management, log review, onboarding/offboarding.
- Experience with PAM solutions (CyberArk or equivalent): privileged onboarding/offboarding, password rotation, session management, audit log review.
- Understanding of highly secured network environments (restricted connectivity, offline patch transfer, air-gapped patterns).
- Strong discipline in change management and documentation for security operations.
Preferred Skills
- Strong understanding of network security concepts (IPS, app-layer inspection, HA, secure admin access).
- Familiarity with vulnerability assessment, patch management, security hardening, and incident response processes.
- Experience supporting platforms in segregated/air-gapped enterprise environments.
- Familiarity with PKI and TLS/SSL certificate lifecycle management.
Certifications (Preferred / Advantageous)
- CCNA (or equivalent networking certification) — highly preferred.
- Palo Alto Networks firewall certification (or equivalent) — preferred.
- CyberArk PAM certification (Defender preferred; Sentry advantageous).
- Cloudflare WAF/DDoS certification or recognised training — advantageous.