Information Security Engineer - Security Operations
Singapore · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 7 hours ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Summary
We are seeking an Information Security Engineer to oversee and advance the security operations of Xiaomi’s international business portfolio. The role involves managing critical security systems, enhancing API security frameworks, handling vulnerability management, and ensuring regulatory compliance in a global setting.
Key Responsibilities
- Manage complete lifecycle of security protection systems including Web Application Firewall (WAF), MiShield, and Host-based Intrusion Detection Systems (HIDS). This includes policy configuration, rule optimization, and expanding security coverage to defend against prevalent threats like those listed in OWASP Top 10.
- Develop real-time monitoring and alert mechanisms, analyze security logs to identify suspicious traffic and attack patterns, produce root cause analysis reports, and improve defensive measures.
- Lead creation of API security frameworks to ensure comprehensive protection for APIs within international operations. Establish models for abnormal behavior detection and access control policies to counter unauthorized data access and API misuse.
- Integrate API security with gateways and microservices, utilize Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools to promote early detection of vulnerabilities, and formulate secure development guidelines for developers.
- Oversee vulnerability management from scanning to risk evaluation and remediation. Implement mechanisms to respond rapidly to high-risk vulnerabilities, collaborating closely with research and development teams on code-level fixes.
- Monitor global threat intelligence and zero-day vulnerabilities, coordinate regular red team/blue team exercises, and refine emergency response protocols.
- Maintain compliance with regional data protection laws such as GDPR and Singapore's Personal Data Protection Act (PDPA). Prepare and support audits for compliance verification.
- Work collaboratively with international business units, compliance teams, and external vendors to provide security technical assistance and conduct training sessions.
Qualifications and Experience
- Bachelor’s degree or higher in Computer Science, Information Security, or a related discipline.
- Proven experience operating security solutions like WAF and Intrusion Detection Systems (IDS).
- Advanced understanding of API security concepts including OWASP API Top 10 vulnerabilities and practical experience with gateway security policy implementation.
- Experience with vulnerability management tools such as Nessus and Burp Suite; skilled in reproducing vulnerabilities and validating remediation.
- Proficiency in scripting languages including Python and Shell, with additional experience in developing security automation tools considered advantageous.
- Thorough knowledge of international data security regulations and compliance requirements, with demonstrated capability in cross-regional collaboration.
- Excellent communication skills in English and Mandarin, both written and spoken; relevant certifications like CISSP or CSSLP are preferred.
- Strong responsibility ethic and problem-solving skills with an ability to react effectively to unplanned security incidents.
Minimum education
Bachelor's Degree
Skills
How they work
Communication
Problem Solving
Accountability
Languages
English
Mandarin