Security Engineer – Project Advisory, Information Security Services
Singapore · Full Time
Be the first to apply
- Experience
- 3–6 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join the Information Security Services team within Group Technology to support comprehensive bank initiatives by performing threat modelling, security risk assessments, and designing information security solutions for critical projects. This role also focuses on assessing and advocating for new technologies to enhance the bank's security stance. The position requires collaboration with business units, technical teams, and suppliers to deliver impactful project advisory services.
Key Responsibilities
- Perform security risk analyses across business, application, and infrastructure projects.
- Conduct threat modelling exercises and suggest effective information security controls for pivotal initiatives.
- Provide consistent security advisory support throughout project life cycles.
- Execute information security due diligence on third-party providers, including conducting onsite assessments when necessary.
- Communicate identified security risks and control recommendations clearly to all stakeholders, including senior leadership.
- Lead the execution of endorsed information security solutions.
- Assess and encourage the use of innovative technologies and practices to reinforce security while balancing usability and risk.
Required Qualifications and Experience
- Demonstrated background in system security evaluations, security architecture reviews, or IT security audits.
- Extensive information technology knowledge with exposure to areas including artificial intelligence, application architectures, cloud environments, containerization, APIs, data platforms, and Microsoft 365.
- Hands-on capability and enthusiasm for exploring emerging technologies and evaluating their security controls.
- Professional certifications such as CISA, CISM, CISSP, or GIAC considered beneficial.
- Experience in conducting comprehensive system security and architecture reviews, as well as IT security audits.
- Readiness to travel as needed for assignments.
Technical Competencies
- In-depth understanding of enterprise information security risks and controls in product development and operational settings.
- Proficiency in carrying out security risk assessments and effectively communicating residual risks to stakeholders.
- Knowledge of diverse enterprise security controls, including endpoint, network, server, application, data, cloud, access control, and Microsoft 365 security measures.
- Familiarity with regulatory compliance requirements like MAS Technology Risk Management Guidelines, PCI DSS, and PDPA.
- Awareness of tactics and methods related to malicious insider threats, organized crime/fraud, and both state and non-state threat actors.
Location and Work Arrangement
The role is based onsite at the DBS Asia Hub in Singapore and is a full-time position under a regular work schedule.
Industry
Financial Services