Security Engineer Tenable
Unison Group Singapore, Singapore
Business Consulting and Services · 11-50 employees
About the role
The role involves leading vulnerability management, security compliance, and system hardening for critical infrastructure. You will also drive operational efficiency through automation and AI while managing vendor relationships and system upgrades.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant field and possess at least 5 years of experience in cybersecurity operations. A mandatory requirement is the Tenable Security Center Specialist certification along with 3 years of hands-on experience with Tenable platforms.
Full description
We are seeking a highly skilled and motivated Senior ICT Infrastructure Engineer (Cyber Security Tools) to join our Cyber Security Operations team. The ideal candidate will play a key role in maintaining and enhancing the organization’s cyber security technology stack, with a strong focus on security, compliance, operational efficiency, automation and service excellence.
The role will have a particular focus on the administration, engineering and continuous improvement of the Tenable Vulnerability Management and Compliance Management platform. This includes platform architecture, vulnerability assessment, CIS Benchmark compliance, audit file engineering, automation and the responsible application of AI to improve operational efficiency.
Key Responsibilities
This role ensures the security posture of critical systems through proactive monitoring, incident response, system maintenance, and implementation of security enhancements across the organization's technology stack.
Be part of a team that is responsible for managing and maintaining the cyber security operations of organization:
- Lead Vulnerability Management (VM) of assigned cyber security tools, including proactive monitoring of vulnerabilities, planning remediation schedules, adhering to vulnerability deadlines and seeking deviations via Risk Assessment (RA).
- Lead security compliance through regular system hardening, configuration management, and policy enforcement.
- Lead IT lifecycle management.
- Ensure timely and successful updates and upgrades whilst ensuring minimal disruption to business operations.
- Plan downtime and collaborate with cross-functional teams for system updates and upgrades.
- Support regular audits and perform remediation actions.
- Work closely with vendors.
- Provide operations support, in a multi-vendor network including Critical Information Infrastructure (CII).
- Participate in Disaster Recovery (DR) exercise and contribute to architectural planning for managed security tools in cloud environments.
- Manage tool setups and migrations.
- Create, maintain and review technical documentation, Standard Operating Procedures (SOP) as part of Knowledge Management (KM).
- Drive efficiencies through AI and automation.
- Proactive documentation as part of Knowledge Management (KM).
- Occasionally provide after-hours support including weekends as required.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
- Minimum 5 years of hands-on experience in cybersecurity operations and security tool management.
- Minimum 3 years of hands-on experience administering and maintaining the Tenable vulnerability management platform, including Tenable One, Tenable Security Center, Nessus Scanners, and related components.
- Minimum 3 years of experience in administering and troubleshooting the Tenable Nessus platform, including agent-based scans, credentialed scans, plugin updates, scan policies, and vulnerability assessment operations.
- Minimum 3 years of hands-on experience developing, maintaining, and optimizing Tenable Audit Files for CIS Benchmark compliance scans, including tailoring audit policies to organizational security standards and regulatory requirements.
- Hands-on ability in operating Privileged Access Management (PAM) tools such as CyberArk.
- Good vendor management skills.
- Good written and verbal communication skills with demonstrated ability to influence and communicate effectively with non-technical audiences including management.
- Applicants are expected to manage work in fast-paced environments, across heterogeneous networks including cloud environments, some of which are Critical Information Infrastructure (CII).
- Tenable Security Center Specialist or equivalent certification is a mandatory requirement for this role.
- Candidates who do not have the relevant certification are advised not to apply.
Similar roles
-
Lead Security Engineer, GRC
Anduril Industries Boston, Massachusetts, United States · $166K–$253K/yr
-
Information Security Engineer (R14207)
Oportun Mexico
-
Principal Application Security Specialist
Global Relay Vancouver, British Columbia, Canada · CA$125K–CA$160K/yr
-
HSM & PKI Security Engineer
CCDS Dammam, Eastern Province, Saudi Arabia
-
Security Engineer
Warp New York, New York, United States · $230K–$290K/yr
-
Product Security Engineer
YipitData (Alternative) United States · $180K/yr