- 9 RAFFLES PLACE Central Region (Singapore) Singapore

Working Location
Job Description
Responsibilities
JOB DESCRIPTION
Cybersecurity Engineer
Fractional Role — Automa%on, AI Tooling & Hands-On Security Operations
Location Singapore / Remote
Employment Type Frac@onal / contract — concurrent mul@-client engagements
Engagement Model 2–4 clients simultaneously; engagements run 3–4 weeks to 3 months per client
Experience 7+ years in cybersecurity; 2+ years hands-on automa@on
Reports To Client CISO or Head of Security (per engagement); internally to Engagement Lead
Security Clearance Subject to per-client background verifica@on and NDA
WHY THIS ROLE EXISTS
Security teams in Singapore are hiring at pace — approximately 245 genuine cyber roles were posted in Singapore
alone in the last 30 days. Most of these teams are s@ll running manual playbooks: copy-paste SIEM queries,
spreadsheet-driven risk registers, and penetra@on test reports assembled by hand. Many cannot jus@fy or fill a full-@me
senior hire, but the gap in their security posture is real and growing.
This is a frac@onal role. You will work across two to four client organisa@ons simultaneously, each with its own security
stack, regulatory context, and maturity level. Engagements range from 3–4 week targeted sprints to 3-month
programmes — you may be running a pentest at one client, building SOC automa@on at another, and closing out an AI
governance engagement at a third, all in the same fortnight. The work is hands-on: you build detec@on rules, run
penetra@on tests, deploy automa@on, and ship AI-assisted tooling — then hand over cleanly and move to the next
client. The advantage of the model is that paQerns and playbooks that work at one client transfer to the next. The
requirement is that you ramp fast, deliver within compressed @melines, manage your own schedule, and leave behind
documenta@on good enough that the client does not need to call you back.
WHAT YOU WILL DO
Security OperaBons & DetecBon Engineering
• Build, tune, and maintain detec@on rules across SIEM and EDR plaVorms (Splunk, Sen@nel, CrowdStrike, or
equivalent). Write detec@on-as-code, version-controlled and peer-reviewed — not point-and-click console rules.
• Automate alert triage using SOAR plaVorms (XSOAR, Shuffle, Tines, or custom Python). Target: reduce Tier-1 analyst
manual triage by at least 40% within six months.
• Design and run tabletop exercises and purple-team sessions quarterly. Document findings, track remedia@on to
closure.
• Integrate threat intelligence feeds into detec@on pipelines. Automate IOC enrichment, scoring, and blocking
workflows.
PenetraBon TesBng & Offensive Security
• Conduct network, web applica@on, and API penetra@on tests across on-premises and cloud environments (AWS,
Azure, GCP).
• Automate recurring vulnerability scans and build dashboards that track remedia@on SLAs by asset owner — not just a
list of CVEs dumped into a PDF.
• Script custom exploita@on and post-exploita@on tooling where off-the-shelf tools fall short. Python, Go, or Bash —
whatever gets the job done.
• Write penetra@on test reports that technical teams can act on. Execu@ve summaries that non-technical stakeholders
can read without a translator.
Cloud Security & DevSecOps
• Embed security checks into CI/CD pipelines: SAST, DAST, SCA, container scanning. If the pipeline does not break on a
cri@cal finding, fix the pipeline.
• Review and harden Infrastructure-as-Code (Terraform, CloudForma@on) before deployment. Automate policy-as-
code using OPA/Rego or equivalent.
• Monitor cloud posture using CSPM tooling (Prisma Cloud, Wiz, or Aqua). Automate drig detec@on and
misconfigura@on alerts.
AI Tooling & Intelligent AutomaBon
• Evaluate and deploy AI-assisted security tools for log analysis, anomaly detec@on, phishing classifica@on, and code
review. We expect you to test these tools against your own benchmarks before rolling them out — vendor demos are
not evidence.
• Build LLM-powered workflows for common security tasks: automated report genera@on from scan outputs, natural-language querying of SIEM data, policy document summarisa@on. Use local or API-hosted models with appropriate data
handling controls.
• Develop and maintain prompt libraries and evalua@on harnesses for security-specific AI use cases. Track accuracy,
false-posi@ve rates, and analyst @me saved.
• Contribute to the organisaBon's AI governance framework: model risk assessment templates, data classifica@on for
AI training inputs, and usage policies for genera@ve AI in security opera@ons.
Governance, Risk & Compliance (SupporBng Role)
• Provide technical input for regulatory audits and compliance assessments under MAS TRM (Singapore), PDPA (both
jurisdic@ons), and ISO 27001.
• Automate evidence collec@on for audit cycles — pull configura@ons, access reviews, and control states directly from
systems rather than asking teams to fill spreadsheets.
• Maintain and update risk registers with real vulnerability and incident data, not theore@cal risk ra@ngs disconnected
from opera@onal reality.
WHAT YOU BRING
Non-NegoBable
• 7+ years in cybersecurity across at least two of: SOC/detec@on engineering, penetra@on tes@ng, cloud security, or
DevSecOps. We will verify this with technical assessment, not just resume keywords.
• ProducBon experience wriBng automaBon: Python scrip@ng, API integra@ons, SOAR playbook development, or CI/
CD security pipeline configura@on. Show us the code or the pipeline, not just the concept.
• Working knowledge of at least one major cloud plaVorm (AWS, Azure, or GCP) at the security configura@on level, not
just user-level console access.
• Familiarity with Singapore regulatory frameworks for technology risk (MAS TRM, BNM RMiT). You do not need to be
a compliance specialist, but you need to understand what auditors ask for and why.
• WriQen communica@on strong enough to produce a penetra@on test report or an incident post-mortem without
heavy edi@ng.
• Demonstrated ability to work across mul@ple concurrent engagements or projects. Consul@ng, frac@onal, or mul@-
client contract experience is a direct signal. If your en@re career has been single-employer, single-team, tell us how you
managed compe@ng workstreams.
• Self-directed @me management. No one will build your weekly schedule across clients. You allocate your own hours,
hold yourself to deadlines, and escalate conflicts before they become problems.
Strong Preference
• Hands-on experience with AI/ML tools applied to security: anomaly detec@on models, LLM-based automa@on, or
AI-driven threat hun@ng. We care about what you built and what it replaced, not which course you completed.
• Cer@fica@ons in OSCP, GPEN, GCIH, CISSP, or AWS/Azure security specialty. These support your candidacy but do not
subs@tute for demonstrated technical ability.
• Experience in financial services, fintech, or other regulated industries in Southeast Asia.
• Exposure to AI governance frameworks (NIST AI RMF, Singapore's Model AI Governance Framework, or ISO 42001).
This area is early-stage — prac@cal exposure maQers more than deep exper@se.
TOOLS & PLATFORMS (TYPICAL, NOT EXHAUSTIVE)
SIEM: Splunk, Microsog Sen@nel, Elas@c Security. EDR: CrowdStrike Falcon, Sen@nelOne, Defender for Endpoint. SOAR:
Palo Alto XSOAR, Tines, Shuffle. Vulnerability Management: Tenable, Qualys, Rapid7 InsightVM. Cloud Security: Prisma
Cloud, Wiz, AWS Security Hub, Azure Defender. Penetra@on Tes@ng: Burp Suite, Metasploit, Cobalt Strike, Nuclei,
custom tooling. DevSecOps: Snyk, Semgrep, Trivy, Checkov, GitHub Advanced Security. AI/ML: Python (scikit-learn,
pandas), LLM APIs (OpenAI, Anthropic, local models via Ollama), Jupyter notebooks for security data analysis.
HOW WE MEASURE SUCCESS
Engagements range from 3–4 week sprints (a targeted pentest, a detec@on-rule audit, an automa@on build) to 3-month
programmes (SOC capability uplig, full cloud security posture review, AI governance framework rollout). The metrics
below scale to the engagement length — a 3-week sprint has a @ghter delivery window and a narrower scope than a 3-
month programme, but the discipline is the same: agree the outcome upfront, deliver it, document what you leave
behind.
Short Engagements (3–4 weeks)
• Day 1–3: Complete environment access, stakeholder introduc@ons, and scope confirma@on. Produce a one-page
engagement plan with deliverables, owners, and deadlines before the first working week ends.
• Week 1–2: Execute primary deliverable — penetra@on test, detec@on rule audit, automa@on build, or vulnerability
assessment. Preliminary findings shared verbally with the client CISO by the end of week 2 so there are no surprises inthe final report.
• Week 3–4: Deliver final report or artefact. Include a handover document: what was done, what was not in scope,
what the client team needs to maintain or monitor going forward. The engagement is not complete un@l the handover
is accepted.
• Close-out: Client feedback collected within one week of delivery. One reusable artefact (template, playbook,
detec@on rule set, or script) contributed to the shared library from each short engagement.
Longer Engagements (2–3 months)
• Week 1–2 (Onboarding): Complete environment access, tool stack inventory, and stakeholder mapping. Deliver a
wriQen security posture snapshot — current detec@on coverage, automa@on gaps, and three priori@sed quick wins —
within the first 10 working days.
• Month 1: Deploy at least one automa@on workflow that measurably reduces manual effort. Target: 30–40%
reduc@on in a specific manual process (Tier-1 triage, evidence collec@on, scan-to-report cycle). The metric is agreed
with the client CISO at onboarding.
• Month 2: Complete at least one penetra@on test or purple-team exercise. Deliver findings with remedia@on owners
and SLA deadlines. Ship one AI-assisted tool or workflow into produc@on use — track analyst hours saved or detec@on
coverage gained, not adop@on.
• Month 3: Deliver final engagement report with measurable before-and-ager metrics. Conduct handover sessions
with the client's internal team. Document all automa@on, detec@on rules, and AI workflows with enough detail that the
client can maintain them independently.
Across the Porbolio (measured monthly by Engagement Lead)
• Client saBsfacBon: Post-engagement feedback scores and renewal or referral rate. If a client is dissa@sfied, we want
to know during the engagement, not ager the final invoice.
• UBlisaBon: Maintain 80–90% billable alloca@on across concurrent clients. Below 80% is a pipeline problem; above
90% typically means quality or context-switching is suffering. Flag either direc@on early.
• Throughput: With variable-length engagements, you will cycle through more clients per quarter than a fixed-
alloca@on model. Target: 4–6 completed engagements per quarter across the porVolio, depending on mix of short and
long.
• Playbook reuse: Document repeatable artefacts that transfer across clients. Target: at least two reusable playbooks,
detec@on rule sets, or assessment templates contributed to the shared library per quarter.
• Cross-client pacern recogniBon: Present a monthly internal brief — five slides, no padding — on common gaps,
misconfigura@ons, or regulatory blind spots you are seeing across engagements (sani@sed, no client-aQributable data).
• Scope discipline: Deliver within the contracted scope and hours. Scope creep absorbed silently erodes margins and
sets expecta@ons we cannot sustain. Flag overruns to the Engagement Lead within the week they occur, not at invoice
@me.
What Good Looks Like at Month 6
You have completed 8–12 client engagements of varying lengths without dropping context or quality on any of them. At
least three clients have either renewed, extended, or referred a new engagement. Every engagement has a handover
document the client team can act on without calling you back. You have contributed six or more reusable artefacts to
the shared library. Your monthly cross-client briefs contain paQerns the sales team can use in new conversa@ons — not
because you are selling, but because the observa@ons are genuinely useful. You manage your own schedule across
overlapping engagements, and your Engagement Lead hears about problems early, not late.
WHAT THIS ROLE IS NOT
This is not a staff-augmenta@on seat. You will not sit inside one client's team full-@me doing whatever they assign. You
own specific outcomes across mul@ple clients, manage your own schedule, and deliver against agreed metrics. That
requires more autonomy than a typical contract role — and more discipline.
This is not a pure compliance or audit role. If your career has been primarily policy wri@ng, risk register management,
or audit coordina@on without hands-on technical work, this is not the right fit.
This is not a tool-administra@on role. We need someone who builds and automates, not someone who maintains
vendor dashboards and generates scheduled reports. And it is not a management role — you will influence technical
direc@on at each client, but you will not manage their teams or ours.
TO APPLY
Send your CV and a short note (under 300 words) covering two things: one security automa@on or AI-assisted workflow
you built, what it replaced, and what it saved in @me or risk reduc@on; and one example of how you managed
overlapping client or project commitments without dropping quality. Generic cover leQers will not be read.
Technical assessment is part of the process. Expect a hands-on exercise — not a mul@ple-choice quiz. We will also
discuss how you structure your week across concurrent engagements.Equal Opportunity Employer. We evaluate candidates on ability and fit, regardless of race, gender, age, na%onality, or disability status. Reasonable
accommoda%ons provided on request.
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.