Start Your Search Here

Job Search

Fujitsu

Singapore / Global

Security Engineer

Job Description

Certificate revocation processes

Password policies

Networking (firewalls, ports, VPN)

Job Location: Singapore

Location Flexibility: Primary Location Only

The Security Engineer is mainly responsible for the

end-to-end implementation, integration, and operationalization

of CyberArk (On-Prem and Cloud) Privileged Access Management (PAM), Venafi Machine Identity Management and 2FA (such as RSA, SecurEnvoy, Cisco Duo) solutions across enterprise environments. This role focuses on

deployment, migration, onboarding, and integration

of privileged access controls, certificates, and machine identities in line with security best practices.

The Security Engineer will work closely with architects, project managers, and customer stakeholders to deliver

secure, scalable, and compliant PAM, CLM and 2FA solutions .

Key Responsibilities

CyberArk Deployment & Implementation

Install, configure, and harden CyberArk components:

Enterprise Password Vault (EPV)

Central Policy Manager (CPM)

Privileged Session Manager (PSM)

Password Vault Web Access (PVWA)

Privileged Threat Analytics (PTA)

Privilege Cloud Connector

CyberArk Adaptive Multi-Factor Authentication (MFA)

CyberArk Vendor Privileged Access Manager (Vendor PAM)

Install, configure 2FA solutions such as RSA, SecurEnvoy, Cisco Duo

Develop and Maintain PSM and CPM connectors

Execute full-cycle deployment activities:

Infrastructure build

Installation & configuration

System validation and testing

Ensure adherence to CyberArk as well as RSA/SecurEnvoy best practices for installation, configuration, and testing

Venafi Deployment & Machine Identity Management

Install, configure, and administer Venafi TLS Protect platform.

Design and document Venafi architecture.

Configure machine identity lifecycle management.

Implement:

Certificate discovery

Certificate inventory management

Certificate automation workflows

CA integrations

Enable:

Automated certificate issuance

Automated renewal

Certificate revocation processes

Self-service certificate requests

Configure network discovery and certificate intelligence capabilities.

Monitor certificate compliance and certificate expiry risks.

Migration & Upgrade Activities

Perform CyberArk environment migrations (on-prem to on-prem / cloud / SaaS)

Execute version upgrades and platform transitions (e.g., legacy OS to modern OS)

Handle:

Vault data migration

Cutover planning and execution

Support post-migration stabilization and user acceptance testing

Account Onboarding & Policy Management

Onboard privileged accounts, systems, and applications into CyberArk

Configure:

Password policies

Rotation and reconciliation settings

Access controls and role-based permissions

Define and implement operational procedures (e.g., break-glass access, onboarding workflows)

Integration with Enterprise Systems

Integrate CyberArk with:

SIEM, ITSM, IAM platforms

Endpoint and network security tools

Enable session recording, monitoring, and audit logging across systems

Integration & Automation

Integrate CyberArk and Venafi with:

Active Directory / LDAP

Entra ID

SIEM platforms

Splunk

QRadar

ITSM platforms

ServiceNow

Identity and Access Management systems

Security monitoring platforms

Certificate Authorities

Microsoft CA

DigiCert

Entrust

GlobalSign

PAM Architecture & Design Support

Support solution architects in:

Gathering requirements

Reviewing technical architecture

Conducting technical workshops and design validation

Contribute to architecture documentation and solution design reviews

Operations Readiness & Knowledge Transfer

Develop and document:

Runbooks

SOPs

Operational procedures

Conduct knowledge transfer sessions for operations teams

Ensure readiness for ongoing PAM operations and support

Troubleshooting & Support

Provide L2/L3 support for CyberArk PAM, Venafi and MFA platform issues

Certificate lifecycle failures

Discovery issues

Renewal failures

CA integration issues

Patch Management

Automation workflow failures

Perform root cause analysis for:

Access issues

Password rotation failures

Session management failures

Work with vendors and internal teams to resolve incidents

Technical Skill Requirements

Mandatory

CyberArk Certified Delivery Engineer (CDE-PAM / Privilege Cloud)

Strong hands-on deployment experience with:

EPV, CPM, PSM, PVWA, PTA, Privilege Cloud Connector, CyberArk Vendor Privileged Access Manager (Vendor PAM), Cyberark MFA, RSA Authentication Manager, SecurEnvoy

Solid understanding of:

Windows Server & Linux (RHEL)

Active Directory / LDAP

Networking (firewalls, ports, VPN)

Scripting

Knowledge in IAM, Security Best Practices and Zero Trust Methodologies

Preferred

Experience in large-scale enterprise deployments (500+ systems onboarding)

Venafi TLS Protect Certification

Venafi Machine Identity Management Certification

Familiarity with:

DevOps secrets (e.g., Conjur)

Cloud PAM (CyberArk Privilege Cloud)

Strong Expertise in PSM and CPM connector developments

Experience with PKI and certificate lifecycle management

TLS Protect

Certificate Lifecycle Management

Discovery & Monitoring

Machine Identity Management

Certificate Authority Integrations

Venafi

TLS Protect

Certificate Lifecycle Management

Discovery & Monitoring

Machine Identity Management

Certificate Authority Integrations

Integration experience with:

Splunk / QRadar other SIEMs

ServiceNow

MFA solutions

Soft Skills & Competencies

Strong stakeholder engagement & communication skills

Ability to lead technical workshops and discussions

Structured and documentation-driven mindset

Experience working in project-based delivery environments

Typical Deliverables

CyberArk deployment build (Vault, CPM, PSM, PVWA, PTA, CyberArk Cloud, Vendor PAM, MFA)

Migration and upgrade runbooks

System onboarding documentation

SOPs and operational guides

Integration configuration documents

Venafi TLS Protect implementation.

Certificate discovery and automation setup

Relocation Supported: No

Visa Sponsorship Approved: No

#J-18808-Ljbffr

Apply Now

Similar Opportunities

View all jobs