Hiring.Camp

M01 - Cyber Platform Engineer

Fpt Asia Pacific Pte Ltd

·

Today

Location
Singapore
Workplace
Onsite
Type
Full-time
Department
Engineering
Closing date
Today
Source
CareersPage

Description

Responsibilities

  • Operate, maintain, and support enterprise cybersecurity platforms including Palo Alto Firewalls, Carbon Black EDR, Cloudflare DDoS/WAF, and CyberArk PAM.
  • Perform preventive maintenance, system health checks, patching, firmware upgrades, configuration changes, and troubleshooting for cybersecurity platforms.
  • Manage Palo Alto firewall policies, rules, NAT, routing, security profiles, logs, configuration backups, and vulnerability remediation.
  • Maintain and troubleshoot Carbon Black EDR, including servers, endpoint sensors, PostgreSQL/Solr components, application services, logs, and endpoint onboarding.
  • Administer Cloudflare DDoS/WAF services, including website onboarding/offboarding, security rules, IP whitelisting/blacklisting, SSL certificates, access reviews, and log reviews.
  • Administer CyberArk PAM, including privileged account onboarding/offboarding, access reviews, password management, service requests, and audit activities.
  • Monitor cybersecurity platforms and investigate system, security, application, and audit logs for anomalies or operational issues.
  • Support vulnerability management, security assessments, audits, incident investigations, and remediation activities.
  • Manage backup and restoration activities, including configuration backups, restoration testing, and maintenance of backup records.
  • Raise and manage change requests in accordance with established change management processes.
  • Maintain technical documentation including SOPs, asset inventories, configuration records, troubleshooting guides, security trackers, and maintenance reports.
  • Work closely with internal security teams, vendors, OEMs, and other technical stakeholders to resolve platform issues.
  • Ensure cybersecurity platforms comply with organisational security policies, the Cybersecurity Act, and Cybersecurity Code of Practice (CCoP).
  • Provide onsite support at secure premises when required for scheduled maintenance and ad-hoc troubleshooting.

Requirements

  • Strong knowledge of enterprise networking, including TCP/IP, VLANs, routing, NAT, DNS, network segmentation, firewall traffic flow, and network troubleshooting.
  • Hands-on experience with Palo Alto Networks Next-Generation Firewalls or equivalent enterprise firewall platforms.
  • Experience managing firewall policies, NAT, routing, security profiles, logs, firmware upgrades, patching, and configuration backup/restoration.
  • Hands-on experience with Carbon Black EDR or equivalent Endpoint Detection and Response platforms.
  • Experience with Cloudflare or equivalent DDoS mitigation/WAF solutions, including security rules, SSL certificates, IP whitelisting/blacklisting, and log management.
  • Experience with CyberArk PAM or equivalent privileged access management solutions.
  • Good understanding of vulnerability management, security hardening, patch management, change management, and cybersecurity incident response.
  • Understanding of highly secured network environments, including air-gapped networks, restricted connectivity, offline patch/file transfers, and data diodes/unidirectional gateways.
  • Familiarity with PKI and TLS/SSL certificate lifecycle management is advantageous.
  • Experience supporting cybersecurity platforms within CII, highly secured, segregated, or air-gapped environments is advantageous.
  • Able to provide onsite support and undergo the required security clearance.

Preferred Certifications

  • CCNA or equivalent networking certification.
  • Relevant Palo Alto Networks firewall certification.
  • CyberArk Defender – PAM; CyberArk Sentry – PAM is advantageous.
  • Relevant Cloudflare WAF/DDoS certification or training is advantageous.

Skills

PostgreSQLCybersecurityTCP/IPChange ManagementCCNA