Security Engineer

Fujitsu

Singapore, SGonsitePosted Aug 6, 2026
Posting intelligenceActively listed

About the role

Job Description

Security Engineer

Job Location: Singapore

Location Flexibility: Primary Location Only

Req Id: 10977

Posting Start Date: 8/6/26

The Security Engineer is mainly responsible for the end-to-end implementation, integration, and operationalization of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on deployment, migration, onboarding, and integration of privileged access controls, certificates, and machine identities in line with security best practices.

The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver secure, scalable, and compliant PAM, CLM and 2FA solutions .

Key Responsibilities

1. CyberArk Deployment & Implementation

Install, configure, and harden CyberArk components:

Enterprise Password Vault (EPV)

Central Policy Manager (CPM)

Privileged Session Manager (PSM)

Password Vault Web Access (PVWA)

Privileged Threat Analytics (PTA)

Privilege Cloud Connector

CyberArk Adaptive Multi-Factor Authentication (MFA)

CyberArk Vendor Privileged Access Manager (Vendor PAM)

Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo

Develop and Maintain PSM and CPM connectors

Execute full-cycle deployment activities:

Infrastructure build

Installation & configuration

System validation and testing

Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing

2. Venafi Deployment & Machine Identity Management

Install, configure, and administer Venafi TLS Protect platform.

Design and document Venafi architecture.

Configure machine identity lifecycle management.

Implement:

Certificate discovery

Certificate inventory management

Certificate automation workflows

CA integrations

Enable:

Automated certificate issuance

Automated renewal

Certificate revocation processes

Self-service certificate requests

Configure network discovery and certificate intelligence capabilities.

Monitor certificate compliance and certificate expiry risks.

3. Migration & Upgrade Activities

Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)

Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)

Handle:

Vault data migration

Cutover planning and execution

Support post-migration stabilization and user acceptance testing

4. Account Onboarding & Policy Management

Onboard privileged accounts, systems, and applications into CyberArk

Configure:

Password policies

Rotation and reconciliation settings

Access controls and role-based permissions

Define and implement operational procedures (e.g., break-glass access, onboarding workflows)

5. Integration with Enterprise Systems

Integrate CyberArk with:

SIEM, ITSM, IAM platforms

Endpoint and network security tools

Enable session recording, monitoring, and audit logging across systems

6. Integration & Automation

Integrate CyberArk and Venafi with:

Active Directory / LDAP

Entra ID

SIEM platforms

Splunk

QRadar

ITSM platforms

ServiceNow

Identity and Access Management systems

Security monitoring platforms

Certificate Authorities

Microsoft CA

DigiCert

Entrust

GlobalSign

7. PAM Architecture & Design Support

Support solution architects in:

Gathering requirements

Reviewing technical architecture

Conducting technical workshops and design validation

Contribute to architecture documentation and solution design reviews

8. Operations Readiness & Knowledge Transfer

Develop and document:

Runbooks

SOPs

Operational procedures

Conduct knowledge transfer sessions for operations teams

Ensure readiness for ongoing PAM operations and support

9. Troubleshooting & Support

Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues

Certificate lifecycle failures

Discovery issues

Renewal failures

CA integration issues

Patch Management

Automation workflow failures

Perform root cause analysis for:

Access issues

Password rotation failures

Session management failures

Work with vendors and internal teams to resolve incidents

Technical Skill Requirements:

Mandatory

CyberArk Certified Delivery Engineer (CDE-PAM / Privilege Cloud)

Strong hands-on deployment experience with:

EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy

Solid understanding of:

Windows Server & Linux (RHEL)

Active Directory / LDAP

Networking (firewalls, ports, VPN)

Scripting

Knowledge in IAM, Security Best Practices and Zero Trust Methodologies

Preferred

Experience in large-scale enterprise deployments (500+ systems onboarding)

Venafi TLS Protect Certification

Venafi Machine Identity Management Certification

Familiarity with:

DevOps secrets (e.g., Conjur)

Cloud PAM (CyberArk Privilege Cloud)

Strong Expertise in PSM and CPM connector developments

Experience with PKI and certificate lifecycle management

TLS Protect

Certificate Lifecycle Management

Discovery & Monitoring

Machine Identity Management

Certificate Authority Integrations

Venafi

TLS Protect

Certificate Lifecycle Management

Discovery & Monitoring

Machine Identity Management

Certificate Authority Integrations

Integration experience with:

Splunk / QRadar other SIEMs

ServiceNow

MFA solutions

Soft Skills & Competencies

Strong stakeholder engagement & communication skills

Ability to lead technical workshops and discussions

Structured and documentation-driven mindset

Experience working in project-based delivery environments

Typical Deliverables

CyberArk deployment build (Vault, CPM, PSM, PVWA, PTA, CyberArk Cloud, Vendor PAM, MFA)

Migration and upgrade runbooks

System onboarding documentation

SOPs and operational guides

Integration configuration documents

Venafi TLS Protect implementation.

Certificate discovery and automation setup

Relocation Supported: No

Visa Sponsorship Approved: No

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in Singapore varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for Singapore medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.