Job Description
Security Engineer
Job Location:  Singapore
Location Flexibility:  Primary Location Only
Req Id:  10977
Posting Start Date:  8/6/26

The Security Engineer is mainly responsible for the end-to-end implementation, integration, and operationalization of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on deployment, migration, onboarding, and integration of privileged access controls, certificates, and machine identities  in line with security best practices.

The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver secure, scalable, and compliant PAM, CLM and 2FA solutions.

Key Responsibilities

1. CyberArk Deployment & Implementation

  • Install, configure, and harden CyberArk components:
    • Enterprise Password Vault (EPV)
    • Central Policy Manager (CPM)
    • Privileged Session Manager (PSM)
    • Password Vault Web Access (PVWA)
    • Privileged Threat Analytics (PTA)
    • Privilege Cloud Connector
    • CyberArk Adaptive Multi-Factor Authentication (MFA)
    • CyberArk Vendor Privileged Access Manager (Vendor PAM)
  • Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo
  • Develop and Maintain PSM and CPM connectors
  • Execute full-cycle deployment activities:
    • Infrastructure build
    • Installation & configuration
    • System validation and testing
  • Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing

 

2. Venafi Deployment & Machine Identity Management

  • Install, configure, and administer Venafi TLS Protect platform.
  • Design and document Venafi architecture.
  • Configure machine identity lifecycle management.
  • Implement:
    • Certificate discovery
    • Certificate inventory management
    • Certificate automation workflows
    • CA integrations
  • Enable:
    • Automated certificate issuance
    • Automated renewal
    • Certificate revocation processes
    • Self-service certificate requests
  • Configure network discovery and certificate intelligence capabilities.
  • Monitor certificate compliance and certificate expiry risks.


3. Migration & Upgrade Activities

  • Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)
  • Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)
  • Handle:
    • Vault data migration
    • Cutover planning and execution
  • Support post-migration stabilization and user acceptance testing


4. Account Onboarding & Policy Management

  • Onboard privileged accounts, systems, and applications into CyberArk
  • Configure:
    • Password policies
    • Rotation and reconciliation settings
    • Access controls and role-based permissions
  • Define and implement operational procedures (e.g., break-glass access, onboarding workflows)


5. Integration with Enterprise Systems

  • Integrate CyberArk with:
    • SIEM, ITSM, IAM platforms
    • Endpoint and network security tools
  • Enable session recording, monitoring, and audit logging across systems

 

6. Integration & Automation

  • Integrate CyberArk and Venafi with:
  • Active Directory / LDAP
  • Entra ID
  • SIEM platforms
  • Splunk
  • QRadar
  • ITSM platforms
  • ServiceNow
  • Identity and Access Management systems
  • Security monitoring platforms
  • Certificate Authorities
  • Microsoft CA
  • DigiCert
  • Entrust
  • GlobalSign


7. PAM Architecture & Design Support

  • Support solution architects in:
    • Gathering requirements
    • Reviewing technical architecture
    • Conducting technical workshops and design validation
  • Contribute to architecture documentation and solution design reviews


8. Operations Readiness & Knowledge Transfer

  • Develop and document:
    • Runbooks
    • SOPs
    • Operational procedures
  • Conduct knowledge transfer sessions for operations teams
  • Ensure readiness for ongoing PAM operations and support


9. Troubleshooting & Support

  • Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues
  • Certificate lifecycle failures
  • Discovery issues
  • Renewal failures
  • CA integration issues
  • Patch Management
  • Automation workflow failures
  • Perform root cause analysis for:
    • Access issues
    • Password rotation failures
    • Session management failures
  • Work with vendors and internal teams to resolve incidents


Technical Skill Requirements:

Mandatory

  • CyberArk Certified Delivery Engineer (CDE-PAM / Privilege Cloud)
  • Strong hands-on deployment experience with:
    • EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy
  • Solid understanding of:
    • Windows Server & Linux (RHEL)
    • Active Directory / LDAP
    • Networking (firewalls, ports, VPN)
    • Scripting
  • Knowledge in IAM, Security Best Practices and Zero Trust Methodologies

 


Preferred

  • Experience in large-scale enterprise deployments (500+ systems onboarding)
  • Venafi TLS Protect Certification
  • Venafi Machine Identity Management Certification
  • Familiarity with:
    • DevOps secrets (e.g., Conjur)
    • Cloud PAM (CyberArk Privilege Cloud)
    • Strong Expertise in PSM and CPM connector developments
    • Experience with PKI and certificate lifecycle management
    • TLS Protect
    • Certificate Lifecycle Management
    • Discovery & Monitoring
    • Machine Identity Management
    • Certificate Authority Integrations
    • Venafi
    • TLS Protect
    • Certificate Lifecycle Management
    • Discovery & Monitoring
    • Machine Identity Management
    • Certificate Authority Integrations

 

  • Integration experience with:
    • Splunk / QRadar other SIEMs
    • ServiceNow
    • MFA solutions

Soft Skills & Competencies

  • Strong stakeholder engagement & communication skills
  • Ability to lead technical workshops and discussions
  • Structured and documentation-driven mindset
  • Experience working in project-based delivery environments

Typical Deliverables

  • CyberArk deployment build (Vault, CPM, PSM, PVWA, PTA, CyberArk Cloud, Vendor PAM, MFA)
  • Migration and upgrade runbooks
  • System onboarding documentation
  • SOPs and operational guides
  • Integration configuration documents
  • Venafi TLS Protect implementation.
  • Certificate discovery and automation setup
Relocation Supported:  No
Visa Sponsorship Approved:  No