About the Client
Morgan McKinley is partnering with a global leader in IT services and consulting to seek for talents. This global IT organisation helps businesses modernize their operations through innovative technology solutions. It partners with clients across industries to drive digital transformation, offering services such as cloud migration, cybersecurity, data analytics, and enterprise applications. Known for managing complex IT ecosystems, it supports organizations in enhancing performance, improving customer experiences, and achieving sustainable growth.
Role Summary
The Security Engineer is responsible for the administration, operation, maintenance, troubleshooting, and continuous improvement of enterprise security technologies across vulnerability and configuration management, cloud security, identity and access management, network access control, and secure remote access.
The role requires strong cybersecurity fundamentals and demonstrable hands-on experience with Tenable, Microsoft Defender for Cloud, enterprise VPN technologies, Okta, Zero Trust Network Access (ZTNA), and Aruba ClearPass. The engineer will work closely with Security Operations, Network, Infrastructure, Cloud, Identity, and Application teams to maintain effective security controls and drive technical issues and security findings through remediation and closure.
Key Responsibilities
Vulnerability Management & Security Hardening – Tenable
- Administer and operate Tenable for vulnerability, compliance, configuration, and security hardening assessments.
- Configure and execute authenticated and unauthenticated scans across in-scope infrastructure.
- Assess systems against approved security baselines, including CIS Benchmarks and vendor-recommended hardening standards.
- Analyse and validate vulnerabilities and configuration findings, determine remediation requirements, and coordinate corrective actions with technology owners.
- Perform rescans and validation to confirm remediation and closure of findings.
- Troubleshoot scan coverage, credential, authentication, plugin, and related operational issues.
- Support vulnerability and hardening reporting, remediation tracking, risk acceptance, and exception processes.
Cloud Security – Microsoft Defender for Cloud
- Administer and monitor Microsoft Defender for Cloud across in-scope cloud resources and workloads.
- Review and manage Secure Score, security recommendations, cloud security posture findings, regulatory compliance views, and security alerts.
- Identify cloud security misconfigurations, vulnerabilities, and control gaps and coordinate remediation with Cloud and Infrastructure teams.
- Support configuration and optimisation of Defender for Cloud plans, policies, workload protection, and security posture capabilities.
- Investigate relevant cloud security alerts and support remediation and incident response activities.
- Maintain visibility of security coverage and track cloud security findings through closure.
Secure Remote Access – VPN & ZTNA
- Support the operation of enterprise VPN and ZTNA solutions.
- Assist with secure remote-access and identity-based access policies.
- Support investigation and troubleshooting of connectivity, authentication, authorisation, certificate, and application-access issues.
- Work with Network, Identity, Endpoint, and other technical teams to resolve secure-access issues.
- Support access reviews, configuration changes, upgrades, and continuous improvement activities.
- Apply Zero Trust and least-privilege principles when supporting remote-access requirements..
Identity & Access Management – Okta
- Support Okta-based identity and access management services.
- Assist with SSO, MFA, authentication policies, and application integrations.
- Support investigation and resolution of authentication, federation, MFA, and application-access issues.
- Work with relevant teams on identity federation and integration requirements using technologies such as SAML, OAuth 2.0, and OpenID Connect (OIDC).
- Support reviews of authentication and access configurations and recommend security improvements.
- Assist with integration of Okta with VPN, ZTNA, applications, and other enterprise technologies.
Network Access Control – Aruba ClearPass
- Support Aruba ClearPass Network Access Control (NAC) operations.
- Assist with authentication, authorisation, device profiling, and network-access policy activities.
- Support investigation and troubleshooting of endpoint authentication, connectivity, posture, and policy-enforcement issues.
- Work with Network and Identity teams on ClearPass integrations with wired and wireless infrastructure and directory services.
- Support reviews and improvements of network-access policies based on user, device, and security requirements.
Security Engineering & Operational Support
- Monitor the health, availability, coverage, and effectiveness of supported security technologies.
- Investigate security issues and coordinate resolution with internal technical teams, vendors, and product support where required.
- Support security incidents, technical investigations, and remediation activities.
- Implement approved security changes in accordance with established change-management processes.
- Maintain technical documentation, configuration records, operational procedures, and knowledge articles.
- Prepare operational reports covering security posture, vulnerabilities, control health, trends, and remediation status.
- Identify opportunities for security process improvement, automation, and operational efficiency.
- Provide technical evidence and support for security assessments, audits, and compliance activities.
- Collaborate with Security Operations, Network, Infrastructure, Cloud, Identity, and Application teams to improve the overall security posture.
Required Experience
- 2-3 years of relevant hands-on experience in cybersecurity engineering, security operations, network security, cloud security, identity and access management, or related security engineering roles.
- Demonstrated experience supporting security technologies in medium to large enterprise environments.
- Ability to independently administer, configure, troubleshoot, and support enterprise security technologies.
- Experience working across Security, Network, Infrastructure, Cloud, Identity, and Application teams.
- Strong problem-solving skills with the ability to investigate technical issues and drive them through resolution.
Mandatory Technical Experience
Candidates must have practical, hands-on experience with all of the following:
- Tenable – vulnerability scanning, authenticated scanning, compliance/configuration assessment, security hardening, finding analysis, remediation validation, and scan troubleshooting.
- Microsoft Defender for Cloud – Cloud Security Posture Management (CSPM), Secure Score, security recommendations, workload protection, alerts, security policies, and remediation.
Foundational Technical Knowledge
- Networking & Network Security – TCP/IP, DNS, DHCP, routing, VLANs, network segmentation, firewalls, and common network protocols.
- Operating System Security – Windows and Linux security, system hardening, patching, and secure configuration concepts.
- Identity & Access Management – Active Directory, Microsoft Entra ID, IAM, SSO, MFA, RBAC, SAML, OAuth 2.0, and OpenID Connect.
- Vulnerability & Configuration Management – vulnerability management lifecycle, security configuration management, CIS Benchmarks, and secure configuration baselines.
- Cloud Security – Microsoft Azure security fundamentals, including identity, networking, access control, security posture, and workload security.
- Cryptography & Secure Communications – TLS, digital certificates, encryption, and PKI fundamentals.
- Security Monitoring & Incident Response – security logging, monitoring, alert investigation, and incident response fundamentals.
- Zero Trust Security – Zero Trust principles, least-privilege access, identity-based access, and secure-access concepts.
- Enterprise VPN – understanding of VPN architecture, secure remote-access policies, authentication, connectivity, and common troubleshooting concepts.
- Okta – understanding of SSO, MFA, authentication policies, identity federation, application integration, and access-management concepts.
- Zero Trust Network Access (ZTNA) – understanding of policy-based secure access, identity- and context-based access, application access, and ZTNA architecture.
- Aruba ClearPass – understanding of Network Access Control (NAC), authentication and authorisation, device profiling, policy enforcement, and network-access concepts.
Preferred / Additional Skills
- Microsoft Defender for Endpoint / Microsoft Defender XDR.
- Microsoft Sentinel or another enterprise SIEM platform.
- Privileged Access Management (PAM) technologies.
- Firewall and network-security platforms.
- Azure Policy and other Azure-native security controls.
- PowerShell or Python scripting for automation, reporting, or operational tooling.
- Experience integrating security platforms using APIs.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent relevant professional experience.
- Relevant industry or product certifications are advantageous, such as Microsoft Security/Azure, Tenable, Okta, Aruba ClearPass, CompTIA Security+, or networking certifications.
By sending us your personal data and curriculum vitae (CV), you are deemed to consent to Morgan McKinley Pte Ltd and its affiliates to collect, use and disclose your personal data for the purposes set out in the Privacy Policy available at https://www.morganmckinley.com/sg/privacy-policy. You acknowledge that you have read, understood, and agree with the Privacy Policy.
Morgan McKinley Pte Ltd
EA Name: Neethu Jose
EA Licence No.: 11C5502
EA: Registration Number: R1110012