368,634open jobs
9,437companies
50,578added this week
Browse all
Location
In office (Singapore)
Employment
Full-Time
Overview
Company
Impact
Profile match
Activate Interactive is a digital technology consultancy, software engineering, and healthtech solutions firm headquartered in Singapore, with regional offshore development centers (ODCs) in Malaysia, Indonesia, and Vietnam. Founded in 1997 and co-led by CEO Joel Ko, the privately held enterprise operates on a B2B and B2G IT consulting, custom software development, managed services, and digital transformation contract model.

Activate Interactive Pte Ltd (“Activate”) is a leading technology consultancy headquartered in Singapore with a presence in Malaysia and Indonesia. Our clients are empowered with quality, cost-effective, and impactful end-to-end application development, like mobile and web applications, and cloud technology that remove technology roadblocks and increase their business efficiency.

We believe in positively impacting the lives of people around us and the environment we live in through the use of technology. Hence, we are committed to providing a conducive environment for all employees to realise their full potential, who in turn have the opportunity to continuously drive innovation.

We are searching for our next team members to join our growing team.

If you love the idea of being part of a growing company with exciting prospects in mobile and web technologies that create positive impact on people’s lives, then we would love to hear from you.

Co-Development Business Unit is looking for Platform Operations Engineer.

This is a 1 - year contract role.

Internal Code: A26310

The Cyber Platform Engineer will be responsible for the operational administration, maintenance, and lifecycle management of the Board’s key cybersecurity platforms: Carbon Black EDR, Palo Alto Perimeter Firewalls deployed across the Board's Critical Information Infrastructure (CII) sites, the Cloudflare DDoS Mitigation Services (DMS) protecting the Board's internet-facing web assets, and the CyberArk Privileged Access Management (PAM) platform governing privileged account access across the Board's environment.

The engineer will execute routine and ad-hoc maintenance activities to ensure the continuous functioning, security compliance, and operational integrity of these platforms. This includes performing scheduled preventive maintenance, managing onboarding and offboarding of assets and accounts, conducting access and log reviews, supporting security assessments and audits, and coordinating with relevant contractors and internal teams. The engineer shall also produce maintenance reports according to Board requirements for every maintenance cycle.

This role requires strong discipline around cybersecurity, change management, and documentation, and the engineer shall ensure all activities are compliant with the Board's cybersecurity policies and the Cybersecurity Code of Practice (CCoP).

What will you do?

Palo Alto Firewall Operations & Maintenance

  • Perform comprehensive quarterly preventive maintenance of all onsite perimeter firewalls, meaning onsite visits to all Board's sites, covering health checks, software patching and firmware updates, and diagnostic checks.
  • Conduct quarterly log and account reviews to detect anomalies and ensure compliance with the Board's cybersecurity policies.
  • Perform patching and mitigations based on the Board's patch management timeline: Critical vulnerabilities within 45 days, High and Medium within 60 days, and Low within 90 days.
  • Perform annual firewall configuration and rules reviews, annual review of hardware and software application lists, and other periodic security reviews as required by the Board's cybersecurity policy.
  • Perform ad-hoc onsite maintenance including graceful shutdown of firewalls when required by the Board (not more than thrice per quarter), and replacement of faulty devices or parts such as ethernet cables.
  • Perform configuration services for existing perimeter firewalls across CII sites, including signature updates and CVE patching on an ad-hoc basis, log backup extraction, firewall shifting and cabling services, firewall rules whitelisting and configuration, and system configuration.
  • Assist the Board during cybersecurity assessments and audits related to the firewall infrastructure.
  • Ensure firewall rules, configurations, and operations comply with the Board's cybersecurity policies and requirements throughout the entire contract period.
  • Raise change requests according to the Board's Change Management process for all maintenance works and system changes

EDR Platform Operations & Maintenance

  • Maintain and operate Carbon Black EDR servers hosted on RHEL 8, including OS, database, application, backup, health check, patching, and service maintenance activities.
  • Monitor and troubleshoot Carbon Black application services, PostgreSQL/Solr components, log forwarding services, and indexing or queue-related issues, including review of system, security, and audit logs not centrally forwarded.
  • Monitor endpoint sensor health, connectivity, and deployment status; troubleshoot offline or faulty sensors, collect diagnostics, and support sensor recovery or redeployment.
  • Support onboarding of new endpoints, validate sensor records against asset inventories, and coordinate with the OEM for advanced troubleshooting, configuration, integration, and professional support when required.

Cloudflare DMS Administration

  • Serve as the first point of contact for all DMS-related enquiries from internal stakeholders.
  • Perform monthly user access reviews, log reviews, and report reviews from the managed services vendor for Cloudflare DMS platform.
  • Manage onboarding of new websites onto the DMS platform and offboarding of websites when required, ensuring all changes are documented in the Board’s enterprise cloud repository.
  • Update and maintain DMS-related documentation, templates, and default configurations in the Board’s enterprise cloud repository as required.
  • Manage software and hardware maintenance and warranty tracking for DMS components.
  • Process service requests and change requests including security policy changes such as IP whitelisting and blacklisting, log extraction, and notification alert updates.
  • Manage SSL certificate renewals for protected websites and update website maintenance pages as required.
  • Review and optimise DMS rules and notifications in coordination with the vendor and PUB SOC team.
  • Perform continuous monitoring and review of the DMS solution every six months to ensure ongoing effectiveness against an evolving threat landscape.
  • Update the Business Impact Assessment (BIA) form annually and update privileged ID password expiry records.

CyberArk PAM Administration

  • Serve as the first point of contact for all PAM-related enquiries from internal stakeholders and ad-hoc requests.
  • Support investigation and incident response activities, as required
  • Perform monthly user access reviews to ensure only authorised personnel retain access to privileged accounts.
  • Manage onboarding of new privileged accounts into CyberArk and offboarding of accounts when no longer required.
  • Process service requests and change requests related to privileged account management.
  • Update the BIA form annually and manage privileged ID password expiry in accordance with the Board's cybersecurity policy.

Security & Compliance

  • Ensure all three platforms comply with the Board's cybersecurity policies, the Cybersecurity Act requirements by the Cyber Security Agency (CSA), and the Cybersecurity Code of Practice (CCoP).
  • Comply with any written instructions on cybersecurity-related matters issued by the Government and the Board from time to time.
  • Ensure data and information across all platforms are protected from leakage, loss, destruction, and falsification in accordance with statutory, regulatory, contractual, and business requirements.
  • All personnel shall sign confidentiality agreements prescribed by the Board and shall not disclose security-classified or sensitive information unless specifically authorised in writing by the Board.

Security Incident & Response

  • Report all security incidents such as virus infections, security compromises, unauthorised access, and security vulnerabilities to the Board immediately.
  • Support investigations and incident response activities by retrieving relevant logs, configurations, and platform data as required.
  • Generate detailed incident investigation reports for each incident and submit to the Board.
  • Implement preventive measures to thwart the recurrence of security incidents.

Backup & Restoration

  • Maintain and update the backup and restoration plan for the platforms, including backup scope, frequency, type, storage location, access controls, restoration procedures, verification, and protection measures.
  • Ensure system configuration backups are completed before and after system changes and verify that scheduled backups are completed successfully.
  • Ensure backups are stored securely, separately from the corresponding production systems in offline storage where required by the Board's cybersecurity policy.
  • Coordinate and document annual backup restoration testing, track remediation of any restoration issues, and review the backup and restoration plan at least once every 12 months.
  • Maintain backup records and evidence, including backup status, restoration test results, exceptions, and outstanding actions, for cybersecurity assessments and audits.

Reporting & Documentation

  • Produce maintenance reports for applicable platforms after every maintenance cycle. The report shall minimally include:
  • Summary status report of completed jobs, ad-hoc support, and outstanding jobs;
  • Platform health checklists for firewall, DMS, and PAM;
  • System, security, and audit log review findings;
  • Software security patch status and tracking;
  • Update backup records and evidence if applicable;
  • Tracking of software licence subscription expiry;
  • Action items on outstanding matters with the Board.
  • Maintain SOPs, asset inventories, system configuration notes, and troubleshooting guides for all three platforms.
  • Maintain and update the Board’s enterprise cloud repository with the latest documentation, templates, and status records.
  • Maintain security dashboards or trackers for vulnerabilities, deviations, access reviews, and audit items across all platforms.

Requirements

What are we looking for?

  • Strong foundation in enterprise networking, including TCP/IP, VLANs, routing, NAT, DNS, network segmentation, firewall traffic flow, and network troubleshooting.
  • Hands-on experience with Palo Alto Networks Next-Generation Firewalls or equivalent firewall platforms, including firewall policy and rule management, NAT, routing, security profiles, log analysis, patching, firmware upgrades, and configuration backup/restoration.
  • Hands-on experience with Carbon Black EDR or equivalent endpoint detection and response platforms, including server administration, sensor health monitoring and troubleshooting, log review, endpoint onboarding, and basic maintenance of supporting OS and application services.
  • Experience with Cloudflare or equivalent DDoS mitigation and Web Application Firewall platforms, including WAF/security rules, IP whitelisting and blacklisting, SSL certificate management, log review, and website onboarding/offboarding.
  • Experience with CyberArk PAM or equivalent privileged access management solutions, including privileged account onboarding/offboarding, access management, password rotation, session management, and audit log review.
  • Understanding of secure network environments, including air-gapped networks, restricted network connectivity, controlled offline transfer of patches/files, and the use of data diodes or unidirectional gateways.
  • Strong understanding of network security concepts including firewall policies, IPS, application-layer inspection, high availability and secure administrative access.
  • Familiarity with vulnerability assessment, patch management, security hardening, change management, and cybersecurity incident response processes.
  • Experience supporting cybersecurity platforms within highly secured, segregated, or air-gapped enterprise network environments.
  • Familiarity with PKI and TLS/SSL certificate lifecycle management.
  • Cisco Certified Network Associate (CCNA) or equivalent networking certification - highly preferred.
  • Palo Alto Networks Certified Next-Generation Firewall Engineer or equivalent current Palo Alto Networks firewall certification - preferred.
  • CyberArk Defender - PAM certification - preferred; CyberArk Sentry - PAM will be advantageous.
  • Relevant Cloudflare technical certification, accreditation, or recognised training in WAF/DDoS administration will be advantageous.

Working Arrangement

  • Onsite at designated PUB secure premises across Singapore, as required for quarterly preventive maintenance or ad-hoc works.
  • Expected to complete scheduled quarterly maintenance windows and ad-hoc response for onsite troubleshooting. Time off will be given for work performed after office hours.
  • Must comply with all security and safety protocols of PUB premises.

Benefits

What do we offer in return?

Competitive Compensation: Market competitive salary and variable performance bonus aligned to your skills, impact, and contribution.

Benefits: Outpatient medical, specialist medical coverage and generous customisable flexi benefits, or flexi allowance; life and health insurance, thoughtful perks like special occasions “red packet” and CNY goodies, etc.

Employee Wellness: Support for your physical, mental, and overall well-being through year-round initiatives.

Growth & Development: Learning programmes, certification support, and a dedicated staff development budget. (We are a “SHRI 2025 Gold winner” in “Learning & Development; Coaching & Mentoring”)

Career Progression: Structured career pathways that enable you to grow along a technical/domain expert track or a leadership track.

Competency Framework: A structured and practical framework to support you to develop, perform, and succeed.

Flexible Work Arrangement: Staff may choose to work flexi-place, flexi-time, and flexi-load based on existing framework

Why you'll love working with us?

If you are looking for opportunities to collaborate with leading industry experts and be surrounded by highly motivated and talented peers, we welcome you to join us. We provide all employees with equal opportunities to grow and develop with us. We believe your success is our success.

Does it sound like something you are interested in exploring further? Please be in touch with our team for an initial chat.

Activate Interactive Singapore is an equal opportunity employer. Employment decisions will be based on merit, qualifications and abilities. Activate Interactive Pte Ltd does not discriminate in employment opportunities or practices on the basis of race, colour, religion, gender, sexuality, national origin, age, disability, marital status or any other characteristics protected by law.

Protecting your privacy and the security of your data are longstanding top priorities for Activate Interactive Pte Ltd.

Your personal data will be processed for the purposes of managing Activate Interactive Pte Ltd’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results, and as is otherwise needed in the recruitment and hiring processes.

Please consult our Privacy Notice (https://www.activate.sg/privacy-policy) to know more about how we collect, use, and transfer the personal data of our candidates. Here you can find how you can request for access, correction and/or withdrawal of your Personal Data.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Singapore
$80k – $169k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Go
Python
Databases
PostgreSQL
RabbitMQ
DevOps
Alertmanager
Ansible
Atlantis
Backstage
Chef
CI/CD
containerd
Docker
GCP
GitOps
Google GKE
Grafana
Helm
Incident Management
Kubernetes
Loki
Platform Engineering
Prometheus
Puppet
Terraform
Thanos
IAM
Cybersecurity
Checkov
SOC 2
Least Privilege
Apply
$112k – $217k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Go
Python
Databases
PostgreSQL
RabbitMQ
DevOps
Alertmanager
Ansible
Atlantis
Backstage
Chef
CI/CD
containerd
Docker
GCP
GitOps
Google GKE
Grafana
Helm
Incident Management
Kubernetes
Loki
Platform Engineering
Prometheus
Puppet
Terraform
Thanos
IAM
Cybersecurity
Checkov
SOC 2
Least Privilege
Apply
$42k – $106k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Go
Python
Databases
PostgreSQL
RabbitMQ
DevOps
Alertmanager
Ansible
Atlantis
Backstage
Chef
CI/CD
containerd
Docker
GCP
GitOps
Google GKE
Grafana
Helm
Incident Management
Kubernetes
Loki
Platform Engineering
Prometheus
Puppet
Terraform
Thanos
IAM
Cybersecurity
Checkov
SOC 2
Least Privilege
Apply
Tech Lead 1 day ago
$49k – $128k per year (Estimated) • Equity • Remote • Full-Time
Ruby
Ruby
Ruby on Rails
Databases
ElasticSearch
PostgreSQL
Redis
AI/ML
NLP
Apply
Tech Lead 1 day ago
$89k – $235k per year (Estimated) • Equity • Remote • Full-Time
Ruby
Ruby
Ruby on Rails
Databases
ElasticSearch
PostgreSQL
Redis
AI/ML
NLP
Apply
$134k – $263k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Singapore
DevOps
CI/CD
Management
Jira
QA
Playwright
Postman
Selenium
Apply
$104k – $345k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
JavaScript
Python
SQL
TypeScript
AI/ML
Model Context Protocol
RAG
Frontend
React.js
DevOps
AWS
CI/CD
Git
Rest API
Analytics
Tableau
Apply
In office • Full-Time • Bachelor's Degree • Singapore
Apex
JavaScript
Python
TypeScript
Apex
Lightning Web Components
AI/ML
Model Context Protocol
RAG
Frontend
Web Components
DevOps
AWS
CI/CD
Git
Rest API
Marketing
Salesforce
Apply
$75k – $212k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Singapore
Node JS
TypeScript
JavaScript
Databases
DynamoDB
PostgreSQL
AI/ML
Copilot
OpenAI
Frontend
Next.js
React.js
Mobile
PWA
Twilio
DevOps
Amazon EC2
AWS
AWS Lambda
CI/CD
Docker
Kubernetes
Terraform
GitHub
Apply
$107k – $355k per year (Estimated) • In office • Full-Time • Singapore
Go
Python
TypeScript
JavaScript
AI/ML
AI Agents
Claude
Claude Code
LLM Guardrails
Frontend
Next.js
React.js
DevOps
ArgoCD
AWS
CI/CD
GitLab CI
GitOps
Kubernetes
Progressive Delivery
Prometheus
Terraform
GitLab
Apply
$117k – $251k per year (Estimated) • Remote/Hybrid • Full-Time • Singapore
Apply
$74k – $126k per year (Estimated) • In office • Full-Time • Singapore
Python
Apply
$88k – $191k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Singapore
C++
Java
Kotlin
Python
Mobile
JUnit
DevOps
Git
gRPC
Jenkins
JFrog Artifactory
Shift-Left
Cybersecurity
Shift-Left Security
QA
Pytest
Robot Framework
TestNG
Apply
Senior AI Architect 5 hours ago
$138k – $304k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Singapore
Python
SQL
Databases
Databricks
AI/ML
AI Agents
LangGraph
OpenAI
RAG
Spark
LangChain
DevOps
Azure
Apply
$64k – $189k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Singapore
Python
SQL
Databases
Apache Kafka
AI/ML
Amazon SageMaker
Kubeflow
MLFlow
Spark
Vertex AI
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
GCP
GitLab
GitLab CI
Jenkins
Kubernetes
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.