Security Engineer
About the role
Job Description
Security Engineer
Job Location: Singapore
Location Flexibility: Primary Location Only
Req Id: 10977
Posting Start Date: 8/6/26
The Security Engineer is mainly responsible for the end-to-end implementation, integration, and operationalization of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on deployment, migration, onboarding, and integration of privileged access controls, certificates, and machine identities in line with security best practices.
The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver secure, scalable, and compliant PAM, CLM and 2FA solutions .
Key Responsibilities
1. CyberArk Deployment & Implementation
Install, configure, and harden CyberArk components:
Enterprise Password Vault (EPV)
Central Policy Manager (CPM)
Privileged Session Manager (PSM)
Password Vault Web Access (PVWA)
Privileged Threat Analytics (PTA)
Privilege Cloud Connector
CyberArk Adaptive Multi-Factor Authentication (MFA)
CyberArk Vendor Privileged Access Manager (Vendor PAM)
Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo
Develop and Maintain PSM and CPM connectors
Execute full-cycle deployment activities:
Infrastructure build
Installation & configuration
System validation and testing
Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing
2. Venafi Deployment & Machine Identity Management
Install, configure, and administer Venafi TLS Protect platform.
Design and document Venafi architecture.
Configure machine identity lifecycle management.
Implement:
Certificate discovery
Certificate inventory management
Certificate automation workflows
CA integrations
Enable:
Automated certificate issuance
Automated renewal
Certificate revocation processes
Self-service certificate requests
Configure network discovery and certificate intelligence capabilities.
Monitor certificate compliance and certificate expiry risks.
3. Migration & Upgrade Activities
Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)
Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)
Handle:
Vault data migration
Cutover planning and execution
Support post-migration stabilization and user acceptance testing
4. Account Onboarding & Policy Management
Onboard privileged accounts, systems, and applications into CyberArk
Configure:
Password policies
Rotation and reconciliation settings
Access controls and role-based permissions
Define and implement operational procedures (e.g., break-glass access, onboarding workflows)
5. Integration with Enterprise Systems
Integrate CyberArk with:
SIEM, ITSM, IAM platforms
Endpoint and network security tools
Enable session recording, monitoring, and audit logging across systems
6. Integration & Automation
Integrate CyberArk and Venafi with:
Active Directory / LDAP
Entra ID
SIEM platforms
Splunk
QRadar
ITSM platforms
ServiceNow
Identity and Access Management systems
Security monitoring platforms
Certificate Authorities
Microsoft CA
DigiCert
Entrust
GlobalSign
7. PAM Architecture & Design Support
Support solution architects in:
Gathering requirements
Reviewing technical architecture
Conducting technical workshops and design validation
Contribute to architecture documentation and solution design reviews
8. Operations Readiness & Knowledge Transfer
Develop and document:
Runbooks
SOPs
Operational procedures
Conduct knowledge transfer sessions for operations teams
Ensure readiness for ongoing PAM operations and support
9. Troubleshooting & Support
Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues
Certificate lifecycle failures
Discovery issues
Renewal failures
CA integration issues
Patch Management
Automation workflow failures
Perform root cause analysis for:
Access issues
Password rotation failures
Session management failures
Work with vendors and internal teams to resolve incidents
Technical Skill Requirements:
Mandatory
CyberArk Certified Delivery Engineer (CDE-PAM / Privilege Cloud)
Strong hands-on deployment experience with:
EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy
Solid understanding of:
Windows Server & Linux (RHEL)
Active Directory / LDAP
Networking (firewalls, ports, VPN)
Scripting
Knowledge in IAM, Security Best Practices and Zero Trust Methodologies
Preferred
Experience in large-scale enterprise deployments (500+ systems onboarding)
Venafi TLS Protect Certification
Venafi Machine Identity Management Certification
Familiarity with:
DevOps secrets (e.g., Conjur)
Cloud PAM (CyberArk Privilege Cloud)
Strong Expertise in PSM and CPM connector developments
Experience with PKI and certificate lifecycle management
TLS Protect
Certificate Lifecycle Management
Discovery & Monitoring
Machine Identity Management
Certificate Authority Integrations
Venafi
TLS Protect
Certificate Lifecycle Management
Discovery & Monitoring
Machine Identity Management
Certificate Authority Integrations
Integration experience with:
Splunk / QRadar other SIEMs
ServiceNow
MFA solutions
Soft Skills & Competencies
Strong stakeholder engagement & communication skills
Ability to lead technical workshops and discussions
Structured and documentation-driven mindset
Experience working in project-based delivery environments
Typical Deliverables
CyberArk deployment build (Vault, CPM, PSM, PVWA, PTA, CyberArk Cloud, Vendor PAM, MFA)
Migration and upgrade runbooks
System onboarding documentation
SOPs and operational guides
Integration configuration documents
Venafi TLS Protect implementation.
Certificate discovery and automation setup
Relocation Supported: No
Visa Sponsorship Approved: No
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.