Cybersecurity - DevSecOps

Singapore16 hours ago
Minimum experience:5+ years
Education:Bachelor’s degree
Apply Now

Job description

Role Description

The Cybersecurity DevSecOps Engineer at Thales plays an important role in integrating security into the system lifecycle, ensuring secure, compliant and resilient systems. This role focuses on vulnerability management, configuration audits, compliance monitoring, and threat detection to mitigate risks across Thales’ IT and OT environments.

The Cybersecurity DevSecOps Engineer will collaborate with cross-functional teams (DevOps, SOC, IT Operations) to automate security controls, enforce hardening standards and security audit log configuration, correlation and alert rules, ensuring adherence to global and regional compliance frameworks (e.g., ISO 27001, NIST, Singapore’s CCoP, ICT&SS).

Skills, Responsibilities and Activities

Vulnerability Management. Skills include: be able to understand vulnerability scan reports to be able to identify, assess and remediate security vulnerabilities to reduce exposure to cyber threats. Activities include:

· Vulnerability Analysis & Prioritization: Process scan reports (using tools such as Nessus, Nmap, Trivy) to identify critical/high-severity vulnerabilities.

· Assess risks using CVSS, EPSS, KEV, SSVC methodologies, prioritising remediation based on business impact and exploitability.

· Remediation Support: Collaborate with the relevant engineering teams to apply patches, workarounds, or mitigations.

· Validate fix effectiveness and track remediation progress

Reporting & Documentation.

Skills

be able to draft clear, actionable reports summarizing:

· Vulnerability details (CVE, affected systems, risk level).

· Recommended hardening rules or corrective actions.

· Risk analysis (likelihood, impact, business context).

· Present findings to stakeholders (IT, Security, Management).

Audit& Monitoring. Skills include ensuring systems are securely configured and monitored for threats. Activities include

· Configuration Compliance Reviews. Validation of host configurations (RHEL, Windows, Databases, Network Equipment) against:

· CIS Benchmarks

· Thales-specific hardening standards

· Other standards as required ie STIGs (Security Technical Implementation Guides)

· Identify misconfigurations and recommend corrective actions.

Integration and Hardening. Skills include ability to integrate, applying hardening benchmarks as well as customized hardening configurations to COTS products (Operating systems & network equipment) and verification of hardened configurations. Activities include:

· Selecting hardening frameworks CIS, defining custom configurations for the environment

· Application of customised hardening using automation tools

· Integration and verification of Cyber requirements for Cyber COTS (such as IAM, PAM, SIEM, EDR,EPP, Keys management, Firewall)

· Verification of hardening baseline during vulnerability scans and test campaigns

SIEM Log Enhancement and Analysis. Skills includes Audit log tuning, analysis and acknowledge of alert frameworks. Activities include:

· Advise on logging improvements for better threat detection (e.g.,missing logs, false positives/negatives).

· Support SIEM rule tuning, advising on the optimisation of correlation rules to enhance alert accuracy in QRadar/Splunk, reducing falsepositives and improving threat detection.

· Align rules with MITRE ATT&CK framework and threat intelligence feeds.

· Analysis of SIEM/SOC alerts to determine:

· Legitimacy (true positive vs. false positive).

· Severity (using MITRE ATT&CK for classification).

· Required actions (containment, remediation, escalation).

Governance & Compliance. Skills include knowledge of regulatory and internal security standards, ensuring their adherence. Activities include:

· Compliance Monitoring, tracking adherence to frameworks such as:

· Global: ISO 27001, NIST, ITIL

· Regional (Singapore): CCoP (Cybersecurity Code of Practice), ICT&SS (Infocomm Technology & Security Standards)

· Maintaining audit evidence for compliance assessments.

· Standards &Policy Support, assisting in security standards change analysis (e.g., updates to CIS, STIGs, or Thale’s policies).

· Ensuring DevSecOps practices align with corporate governance requirements.

· Risk & Gap Analysis, identifying gaps between current state and required compliance levels.

· Propose mitigation strategies to close gaps.

On-Call Support. Activities Include:

· Provide on-call support as required to the customer when restored.

Technical Skills, Qualifications & Experience

Technical Skills

Vulnerability Management : Nessus, Nmap, Trivy, CVSS, EPSS, KEV, SSVC

Configuration Auditing : STIGs, CIS Benchmarks, SCAP, OpenSCAP

SIEM & Monitoring : QRadar, Splunk, ELK, MITRE ATT&CK, Threat Intelligence

Scripting & Automation : Python, Bash, PowerShell (for report automation)

Compliance Frameworks : ISO 27001, NIST, ITIL, CCoP, ICT&SS

Cloud & Infrastructure : RHEL, Windows Server, Databases (Oracle, SQL), Network Devices

DevSecOps Tools : Jenkins, GitLab CI/CD, Ansible, Terraform (for IaC security)

Soft Skills

  • Analytical Thinking: Ability to interpret scan reports, logs, and compliance gaps.
  • Stakeholder Communication: Clear reporting and collaboration with non-security teams.
  • Problem-Solving: Proactive in identifying and mitigating risks.
  • Attention to Detail: Ensure accuracy in audits, reports, and remediation tracking.

· A positive attitude combined with excellent interpersonal and motivational skills.

· Sound judgement and independent decision-making capability where necessary

· Excellent written and oral communication skills in English

Qualifications

  • Degree in Engineering, Computer Science or related discipline majoring in Cybersecurity or relevant industry experience

Essential Experience

· 5+ years of proven experience in the Cybersecurity field

· Strong knowledge in Cybersecurity solutions (e.g. IAM, PAM, SIEM, EDR, Keys, Firewall)

· Demonstrated ability to achieve effective outcomes in a multidiscipline, multi-culture environment

· Experience in system hardening and hardening review based on CIS Benchmarks or DISA STIG frameworks.

Desirable:

  • Industry qualifications, such as CISSP

· Postgraduate studies in Cybersecurity

· Vulnerability Management: CVMP (Certified Vulnerability Management Professional)

· Compliance: ISO27001 Lead Auditor, CIS Controls, ITIL v4

· SIEM/Monitoring: Splunk Core Certified User, IBM QRadar SIEM

· Cloud/Infrastructure: RHCSA (Red Hat), Microsoft Certified: Security Administrator

· DevSecOps: Certified DevSecOps Professional (CDP), Practical DevSecOps

· Knowledge of ISO27001 foundational requirements.

· Experience in country security regulations (e.g. CCOP and IM(ICT&SS) for Singapore)

· Experience in ATM Domain and related standards eg. ICAO, Eurocontrol ,or safety critical systems.

· Experience in System Engineering tools eg. DOORs, Polarian, Jira

· Experience invulnerability management and threat modeling

· Experience inworking in a Scaled Agile Framework (SAFe)

General / Special Requirements

· Assist in ensuring a harmonious work environment in all departments that you are working with by upholding Thales' key values.

· An advocate for diversity and inclusion who will be actively involved in implementing change initiatives to achieve our diversity goals

· An advocate fora culture of continuous improvement

· An advocate for Accountability, transparency and curiosity

· Comply with all relevant company Occupational Health, Safety and Environmental policies and framework and work practices with the intent of preventing or minimising accidental exposures to self, colleagues, visitors and/or the environment and to ensure a safe work practises at all times.

· Comply with all relevant Company policies and procedures.

· Occasional international travel may be required

SPECIAL REQUIREMENTS

· Eligible to obtain Singapore CAT2 Clearance

Skills mentioned

Apply for this job

Use the application link supplied with this listing to apply to THALES SOLUTIONS ASIA PTE. LTD.. Check the destination before entering personal information.

Apply Now