Role:Security Analyst – L2
Location: Singapore (Onsite)
Duration: 12 Months (Renewable) Contract
Experience
4–6 Years
About the Role
We are seeking an experienced Security Engineer – L2 to manage and support enterprise identity security, Microsoft 365 security, PKI infrastructure, privileged access management, cloud security controls, and hybrid Zero Trust security architectures. This role is responsible for the operational management, monitoring, administration, and continuous improvement of security platforms across on-premises and cloud environments.
The ideal candidate will possess strong expertise in Microsoft Identity and Access Management technologies, Azure security services, Microsoft 365 security, CyberArk privileged access solutions, PKI lifecycle management, and cloud network security. The engineer will investigate medium-complexity security incidents, support compliance initiatives, and collaborate closely with Security Operations, Infrastructure, and Cloud Engineering teams.
Key Responsibilities
Identity & Access Management
- Administer and maintain Microsoft Active Directory and Active Directory Federation Services (ADFS).
- Manage Microsoft Entra ID configurations, identity governance controls, and directory policies.
- Monitor and troubleshoot Azure AD Connect synchronization and hybrid identity environments.
- Support Single Sign-On (SSO) integrations using SAML, OAuth, and OpenID Connect (OIDC).
- Configure, maintain, and troubleshoot Conditional Access policies.
- Manage Multi-Factor Authentication (MFA) solutions, including Microsoft MFA and Symantec VIP.
- Investigate authentication failures, access anomalies, and identity-related security events.
Microsoft 365 Security Administration
- Monitor and administer Microsoft 365 security controls and dashboards.
- Manage Exchange Online Protection policies and email security controls.
- Investigate phishing, malware, and email-based security incidents.
- Support implementation and maintenance of Microsoft security best practices.
Privileged Access Management
- Administer CyberArk Endpoint Privilege Manager (EPM) and Privileged Access Management (PAM) platforms.
- Manage privileged account onboarding, access approvals, credential rotation, and session monitoring.
- Investigate privileged access violations and suspicious administrative activities.
Azure Security & Cloud Infrastructure
- Monitor Azure Firewall logs, security alerts, and traffic patterns.
- Validate and maintain Azure ExpressRoute security configurations.
- Review and secure Azure Private Link and Private Endpoint deployments.
- Support Hub-and-Spoke network architecture security controls.
- Monitor cloud security posture and recommend remediation actions.
- Assist in implementing Zero Trust security principles across cloud and hybrid environments.
PKI & Certificate Lifecycle Management
- Manage DigiCert PKI infrastructure and SSL/TLS certificate lifecycle processes.
- Perform certificate issuance, renewal, revocation, and deployment activities.
- Troubleshoot SSL/TLS encryption and certificate trust issues.
- Monitor certificate expiration and ensure timely renewals.
- Support enterprise encryption and secure communication requirements.
Endpoint & Email Security
- Administer Trend Micro endpoint and email security platforms.
- Monitor alerts, investigate security incidents, and coordinate remediation activities.
- Tune security policies and improve threat detection effectiveness.
Incident Response & Security Operations
- Investigate and respond to medium-severity security incidents.
- Conduct root cause analysis and document findings.
- Escalate advanced threats, complex incidents, and security breaches to L3 Security Engineers.
- Support threat containment, eradication, and recovery activities.
Compliance, Governance & Documentation
- Prepare security reports, audit evidence, and compliance documentation.
- Support internal and external audits.
- Maintain security operational procedures, standards, and runbooks.
- Ensure security configurations comply with organizational policies and regulatory requirements.
Business Continuity & Security Validation
- Participate in Disaster Recovery (DR) exercises and security validation testing.
- Validate identity, cloud, and security controls during resilience testing activities.
- Support remediation of findings identified during testing exercises.
Required Skills & Competencies
Identity & Access Management
- Microsoft Active Directory (AD)
- Active Directory Federation Services (ADFS)
- Microsoft Entra ID (Azure AD)
- Azure AD Connect
- Microsoft Identity Manager (MIM)
- Identity lifecycle management
- Single Sign-On (SSO)
Authentication & Authorization
- SAML 2.0
- OAuth 2.0
- OpenID Connect (OIDC)
- Microsoft Multi-Factor Authentication (MFA)
- Symantec VIP
- Conditional Access Policies
Cloud Security
- Microsoft Azure Security Services
- Azure Firewall
- Azure ExpressRoute
- Azure Private Link
- Azure Private Endpoints
- Hub-and-Spoke Network Architecture
- Zero Trust Security Architecture
Microsoft 365 Security
- Microsoft 365 Security Center
- Exchange Online Protection (EOP)
- Microsoft Security Controls and Compliance Features
Privileged Access Management
- CyberArk Endpoint Privilege Manager (EPM)
- CyberArk Privileged Access Management (PAM)
Endpoint & Email Security
- Trend Micro Endpoint Security
- Trend Micro Email Security
- Threat Detection and Response
PKI & Encryption
- DigiCert Managed PKI
- SSL/TLS Certificate Management
- Public Key Infrastructure (PKI)
- Certificate Lifecycle Management
- Encryption Technologies
Security Operations
- Security Incident Investigation
- Security Monitoring and Alert Analysis
- Root Cause Analysis
- Threat Escalation Procedures
- Audit and Compliance Support
Preferred Qualifications
- Microsoft Certified: Identity and Access Administrator Associate.
- Microsoft Certified: Azure Security Engineer Associate.
- CyberArk Defender or CyberArk Administrator Certifications.
- Certified Information Systems Security Professional (CISSP) – Associate Level.
- CompTIA Security+ or equivalent security certification.
- Experience with Zero Trust security architecture implementation.
- Knowledge of security frameworks such as NIST, ISO 27001, CIS Controls, and Microsoft Security Best Practices.
Key Performance Indicators (KPIs)
- Successful management of identity and access security controls.
- Timely resolution of security incidents and service requests.
- Compliance with certificate renewal and lifecycle management timelines.
- Accuracy and effectiveness of Conditional Access and MFA implementations.
- Security posture improvements across Microsoft 365 and Azure environments.
- Audit readiness and documentation quality.
- Adherence to SLA and incident response objectives.
Interested candidates can connect on +6586533349 (WhatsApp chat only)