jobs in DBiz.ai

DBiz.ai Hiring! Full Time Cyber Security Engineer in - Ricebowl

Cyber Security Engineer

DBiz.ai

Undisclosed

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

Duration: 12 months (Subject to an additional 12 months extention)

Budget: SGD 7,000 - 9,000/ mth


DBiz is looking for a Cyber Platform Engineer (Consultant) to join the Singapore team to support cybersecurity platform operations, maintenance, and lifecycle management across various client projects. The role will collaborate with cross-functional teams and vendors to ensure secure, compliant, and resilient operations for key security platforms (EDR, perimeter firewalls, DDoS/WAF, PAM). The selected candidate will be hands-on, disciplined in change management/documentation, and able to support audits and incident response across client environments.


Primary Responsibilities

  • Operate and maintain cybersecurity platforms across client environments, including:
  • Endpoint Detection & Response (EDR), Perimeter Firewalls, DDoS/WAF services, and Privileged Access Management (PAM).
  • Execute routine and ad-hoc maintenance to ensure continuous functioning, compliance, and operational integrity (preventive maintenance, onboarding/offboarding, access/log reviews).
  • Perform firewall operations & maintenance:
  • Quarterly preventive maintenance (health checks, patching/firmware upgrades, diagnostics; may require onsite visits).
  • Log/account reviews; annual configuration/rules reviews; ad-hoc configuration and cabling/shifting support.
  • Raise and manage change requests for maintenance and system changes.
  • Perform EDR platform operations & maintenance:
  • Maintain EDR servers on Linux (RHEL), including OS/app/database components, backups, patching, and health checks.
  • Monitor/troubleshoot services and endpoint sensors; support endpoint onboarding and OEM coordination.
  • Perform DDoS/WAF administration:
  • Act as first point of contact; manage onboarding/offboarding of protected web assets; maintain documentation/templates.
  • Conduct periodic access/log/report reviews; manage SSL certificate renewals and rule optimisation with vendors/SOC.
  • Perform PAM administration:
  • Act as first point of contact; manage privileged account onboarding/offboarding and access reviews.
  • Support investigations/incident response and related service/change requests.
  • Support security compliance, assessments, and audits:
  • Ensure platforms adhere to client cybersecurity policies and required standards; maintain evidence and trackers.
  • Support incident response:
  • Report incidents promptly; retrieve logs/configurations; produce investigation reports; implement preventive measures.
  • Maintain backup & restoration readiness:
  • Keep backup/restoration plans updated; coordinate annual restoration tests; maintain records/evidence.
  • Produce maintenance reports after each cycle and maintain SOPs, inventories, configuration notes, and troubleshooting guides.


Key Requirements

  • Strong foundation in enterprise networking (TCP/IP, VLANs, routing, NAT, DNS, segmentation, troubleshooting).
  • Hands-on experience with Next-Gen Firewalls (Palo Alto or equivalent): policy/rules, NAT/routing, security profiles, log analysis, patching/firmware upgrades, backup/restore.
  • Hands-on experience with EDR (Carbon Black or equivalent): server administration, sensor health monitoring, endpoint onboarding, log review, basic OS/app services maintenance.
  • Experience with DDoS mitigation / WAF platforms (Cloudflare or equivalent): WAF/security rules, IP allow/deny, SSL cert management, log review, onboarding/offboarding.
  • Experience with PAM solutions (CyberArk or equivalent): privileged onboarding/offboarding, password rotation, session management, audit log review.
  • Understanding of highly secured network environments (restricted connectivity, offline patch transfer, air-gapped patterns).
  • Strong discipline in change management and documentation for security operations.


Preferred Skills

  • Strong understanding of network security concepts (IPS, app-layer inspection, HA, secure admin access).
  • Familiarity with vulnerability assessment, patch management, security hardening, and incident response processes.
  • Experience supporting platforms in segregated/air-gapped enterprise environments.
  • Familiarity with PKI and TLS/SSL certificate lifecycle management.


Certifications (Preferred / Advantageous)

  • CCNA (or equivalent networking certification) — highly preferred.
  • Palo Alto Networks firewall certification (or equivalent) — preferred.
  • CyberArk PAM certification (Defender preferred; Sentry advantageous).
  • Cloudflare WAF/DDoS certification or recognised training — advantageous.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More