- Location
- Singapore
- Workplace
- Onsite
- Type
- Full-time
- Department
- Engineering
- Closing date
- Today
- Source
- CareersPage
Description
Key Responsibilities:
Palo Alto Firewall Operations & Maintenance
- Perform comprehensive quarterly preventive maintenance of all onsite perimeter firewalls, including onsite visits to relevant sites, covering health checks, software patching and firmware updates, and diagnostic checks.
- Conduct quarterly log and account reviews to detect anomalies and ensure compliance with applicable cybersecurity policies.
- Perform patching and mitigations based on the applicable patch management timeline.
- Perform annual firewall configuration and rules reviews, annual review of hardware and software application lists, and other periodic security reviews as required by applicable cybersecurity policies.
- Perform ad-hoc onsite maintenance, including graceful shutdown of firewalls when required, and replacement of faulty devices or parts such as Ethernet cables.
- Perform configuration services for existing perimeter firewalls across critical infrastructure environments, including signature updates and CVE patching on an ad-hoc basis, log backup extraction, firewall shifting and cabling services, firewall rules whitelisting and configuration, and system configuration.
- Assist during cybersecurity assessments and audits related to the firewall infrastructure.
- Ensure firewall rules, configurations, and operations comply with applicable cybersecurity policies and requirements throughout the entire contract period.
- Raise change requests according to the applicable Change Management process for all maintenance works and system changes.
EDR Platform Operations & Maintenance
- Maintain and operate EDR servers, including OS, database, application, backup, health check, patching, and service maintenance activities.
- Monitor and troubleshoot EDR application services, database components, log forwarding services, and indexing or queue-related issues, including review of system, security, and audit logs.
- Monitor endpoint sensor health, connectivity, and deployment status; troubleshoot offline or faulty sensors, collect diagnostics, and support sensor recovery or redeployment.
- Support onboarding of new endpoints, validate sensor records against asset inventories, and coordinate with the OEM for advanced troubleshooting, configuration, integration, and professional support when required.
Cloudflare DMS Administration
- Serve as the first point of contact for all DMS-related enquiries from internal stakeholders.
- Perform monthly user access reviews, log reviews, and report reviews from the managed services vendor for the DMS platform.
- Manage onboarding of new websites onto the DMS platform and offboarding of websites when required, ensuring all changes are documented in the relevant enterprise documentation repository.
- Update and maintain DMS-related documentation, templates, and default configurations in the relevant enterprise documentation repository as required.
- Manage software and hardware maintenance and warranty tracking for DMS components.
- Process service requests and change requests, including security policy changes such as IP whitelisting and blacklisting, log extraction, and notification alert updates.
- Manage SSL certificate renewals for protected websites and update website maintenance pages as required.
- Review and optimize DMS rules and notifications in coordination with the vendor and relevant security stakeholders.
- Perform continuous monitoring and review of the DMS solution periodically to ensure ongoing effectiveness against an evolving threat landscape.
- Update the Business Impact Assessment (BIA) form annually and update privileged ID password expiry records.
CyberArk PAM Administration
- Serve as the first point of contact for all PAM-related enquiries from internal stakeholders and ad-hoc requests.
- Support investigation and incident response activities, as required.
- Perform monthly user access reviews to ensure only authorized personnel retain access to privileged accounts.
- Manage onboarding of new privileged accounts into CyberArk and offboarding of accounts when no longer required.
- Process service requests and change requests related to privileged account management.
- Update the BIA form annually and manage privileged ID password expiry in accordance with applicable cybersecurity policies.
Security & Compliance
- Ensure all three platforms comply with applicable cybersecurity policies, regulatory requirements, and industry standards.
- Comply with any written instructions on cybersecurity-related matters issued by relevant authorities and the organization from time to time.
- Ensure data and information across all platforms are protected from leakage, loss, destruction, and falsification in accordance with statutory, regulatory, contractual, and business requirements.
- Maintain confidentiality and ensure that security-classified or sensitive information is not disclosed unless specifically authorized.
Security Incident & Response
- Report all security incidents such as virus infections, security compromises, unauthorized access, and security vulnerabilities to the relevant stakeholders immediately.
- Support investigations and incident response activities by retrieving relevant logs, configurations, and platform data as required.
- Generate detailed incident investigation reports for each incident and submit them to the relevant stakeholders.
- Implement preventive measures to thwart the recurrence of security incidents.
Backup & Restoration
- Maintain and update the backup and restoration plan for the platforms, including backup scope, frequency, type, storage location, access controls, restoration procedures, verification, and protection measures.
- Ensure system configuration backups are completed before and after system changes and verify that scheduled backups are completed successfully.
- Ensure backups are stored securely and separately from the corresponding production systems in accordance with applicable cybersecurity policies.
- Coordinate and document annual backup restoration testing, track remediation of any restoration issues, and review the backup and restoration plan at least once every 12 months.
- Maintain backup records and evidence, including backup status, restoration test results, exceptions, and outstanding actions, for cybersecurity assessments and audits.
Reporting & Documentation
-
Produce maintenance reports for applicable platforms after every maintenance cycle. The report shall minimally include:
- Summary status report of completed jobs, ad-hoc support, and outstanding jobs.
- Platform health checklists for firewall, DMS, and PAM.
- System, security, and audit log review findings.
- Software security patch status and tracking.
- Updated backup records and evidence, if applicable.
- Tracking of software license subscription expiry.
- Action items on outstanding matters with relevant stakeholders.
- Maintain SOPs, asset inventories, system configuration notes, and troubleshooting guides for all three platforms.
- Maintain and update the relevant enterprise documentation repository with the latest documentation, templates, and status records.
- Maintain security dashboards or trackers for vulnerabilities, deviations, access reviews, and audit items across all platforms.
Technical Requirements:
Mandatory Technical Skills
- Strong foundation in enterprise networking, including TCP/IP, VLANs, routing, NAT, DNS, network segmentation, firewall traffic flow, and network troubleshooting.
- Hands-on experience with Palo Alto Networks Next-Generation Firewalls or equivalent firewall platforms, including firewall policy and rule management, NAT, routing, security profiles, log analysis, patching, firmware upgrades, and configuration backup/restoration.
- Hands-on experience with Carbon Black EDR or equivalent endpoint detection and response platforms, including server administration, sensor health monitoring and troubleshooting, log review, endpoint onboarding, and basic maintenance of supporting OS and application services.
- Experience with Cloudflare or equivalent DDoS mitigation and Web Application Firewall platforms, including WAF/security rules, IP whitelisting and blacklisting, SSL certificate management, log review, and website onboarding/offboarding.
- Experience with CyberArk PAM or equivalent privileged access management solutions, including privileged account onboarding/offboarding, access management, password rotation, session management, and audit log review.
- Understanding of secure network environments, including air-gapped networks, restricted network connectivity, controlled offline transfer of patches/files, and the use of data diodes or unidirectional gateways.
Good-to-Have
- Strong understanding of network security concepts including firewall policies, IPS, application-layer inspection, high availability, and secure administrative access.
- Familiarity with vulnerability assessment, patch management, security hardening, change management, and cybersecurity incident response processes.
- Experience supporting cybersecurity platforms within highly secured, segregated, or air-gapped enterprise network environments.
- Familiarity with PKI and TLS/SSL certificate lifecycle management.
Certifications
- Cisco Certified Network Associate (CCNA) or equivalent networking certification — highly preferred.
- Palo Alto Networks Certified Next-Generation Firewall Engineer or equivalent current Palo Alto Networks firewall certification — preferred.
- CyberArk Defender – PAM certification — preferred; CyberArk Sentry – PAM will be advantageous.
- Relevant Cloudflare technical certification, accreditation, or recognised training in WAF/DDoS administration will be advantageous.