Senior Cyber Security Engineer
Listed on 2025-11-26
-
IT/Tech
Cybersecurity, Systems Engineer
We are looking for a Senior Cyber Security Engineer to support the overall cybersecurity efforts will help protect our systems, applications, infrastructure, and data as we continue to grow across Singapore and Australia. Working closely with Developers and the Platform Teams (Dev Ops), you will embed security across every stage of the software development lifecycle and ensure our cloud environment remains secure and resilient.
If you are passionate about secure software delivery, threat detection, risk mitigation, and contributing to a strong security culture in a fast-moving, tech-driven environment.
Hi, we’re Flo, and we are on a mission to switch as many people and businesses as possible to clean, renewable energy. We do that by making clean energy as cheap as conventional energy, investing in smart technology to reduce our operating costs and passing the savings to our members. And yes, it's not impossible.
We are pushing boundaries and breaking conventions of the traditional electricity retailer. To do so we are looking for like-minded people who share our passion for technology and sustainability. You might be the one we are looking for!
Find out more about us on (Use the "Apply for this Job" box below)./about
What you will be doingAs a Cyber Security Officer, your primary focus will be on Application and Cloud Security, while also supporting the broader cybersecurity posture of the organization. You will work closely with Developers and the Platform Teams (Dev Ops) to embed security into all stages of software delivery and infrastructure operations. Ensuring Flo maintains a secure, compliant, and resilient environment as it grows.
SecureDevelopment & Cloud Practices
- Collaborate with developers to embed secure coding practices and conduct code reviews for high-risk features.
- Conduct threat modeling and security architecture reviews for cloud-native apps and microservices.
- Integrate security scanning tools (SAST, DAST, SCA) into CI/CD pipelines.
- Collaborate with the Platform Team (Dev Ops) to secure containerized workloads (e.g., Docker, Kubernetes), infrastructure-as-code, and serverless applications.
- Work with the Platform Team to secure configuration across AWS accounts, including IAM, encryption, and network controls.
- Implement and manage Web Application Firewalls (WAFs) to protect applications from OWASP Top 10 vulnerabilities and other common attacks.
- Support the IT Security Manager in maintaining and aligning with ISO 27001, SOC 2, and PDPA requirementsli>
- Assist with external audits and maintain documentation of security controls, asset inventory, and risk assessments.
- Work with the IT Security Manager to implement Zero Trust principles, including strong identity access management and least-privilege enforcement.
- Help define and maintain internal security policies, procedures, and training programs.
- Monitor and investigate alerts using SIEM platforms, IDS/IPS, and cloud-native security tools (e.g., AWS Guard Duty, Security Hub).
- Support response to security incidents, including containment, recovery, and post-incident analysis.
- Maintain incident response plans, develop playbooks, and contribute to tabletop exercises.
- Coordinate or assist with penetration testing and vulnerability assessments, both internally and with third-party vendors.
- Support Mobile Device Management (MDM) tools and endpoint protection to ensure device compliance.
- Enforce secure configurations on employee laptops and mobile devices through policy-based controls.
- Manage access controls across cloud services and SaaS tools using SSO, MFA, and RBAC.
- Support security awareness efforts and employee training to reduce human risk.
- Stay current with emerging threats, vulnerabilities, and cybersecurity technologies.
- Proactively identify areas for risk reduction and security automation.
- Collaborate across teams to build a culture of security-first thinking in everything we build and deploy.
- Bachelor’s degree in Cybersecurity, Computer Science,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).