Cybersecurity Engineer (Automation)

🗓️ Posted 2026-08-14 Singapore Permanent ICT

Company shared salary

NA

Market rate

NA

Based on similar roles (title + domain + location).

About the Company

Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.

Responsibilities

  • Lead the Security Orchestration, Automation and Response (SOAR) of cyber security operations processes to improve efficiency and reduce response times for security incidents.
  • Develop workflow processes to automate manual cybersecurity tasks.
  • Develop and maintain automation scripts/playbooks to support the operational workflow, including reporting, monitoring and incident response.
  • Define and enforce playbook development standards (naming structure, parameterisation, logging).
  • Optimize sub-playbooks for performance, logic clarity, error handling and parameter flexibility.
  • Refactor legacy/existing playbooks for reusability, naming consistency and reduced duplication.
  • Support integration of SOAR platform with third party applications and systems (e.g. message bus and API gateway) based on the required workflow.
  • Conduct playbook testing, validation, regression and integration testing on the automated workflow and integration code for robustness and performance.
  • Implement and manage automation platforms and technologies across existing security frameworks.
  • Collaborate with cross-functional teams to ensure seamless integration of security automation initiatives.
  • Take the lead to work with third party system administrators or vendors to resolve integration issues and data flow issues.
  • Defining the interface testing scenarios and testing to ensure that the integration and interfacing testing is successful.
  • Monitor performance and reliability of automations, identify bottlenecks or failure points.
  • Document all workflows, decisions logic, sub-playbook dependencies and version changes.
  • Stay current with emerging security threats, technologies, and practices to propose automated solutions.
  • Provide training and support to team members on automated security processes and tools.

Requirements

  • At least 3 years of experience with security orchestration, automation, and response (SOAR) platforms, preferably with Cortex XSOAR.
  • Strong programming skills in languages such as Python, PowerShell, or Bash.
  • Proficiency in XSOAR components: playbooks, sub-playbooks, integrations, incident types, classifiers, layouts.
  • Experience with REST APIs, JSON, and data parsing.
  • Familiarity with incident response processes, MITRE ATT&CK framework, and SOC operations.
  • Comfortable with Git-based version control and code review workflows should XSOAR CI/CD be implemented.
  • Familiarity with various cybersecurity frameworks and compliance requirements.
  • Understanding of RBAC and case management customisation in XSOAR.
  • Ability to analyse API documentation and build custom integrations where needed.
  • Security Certifications such as GISA, GSEC, CISSP, or CEH is an advantage.
  • Ability to justify new initiatives and recommend new initiatives to stakeholder(s).
  • Effective communication skills to explain complex technical issues to non-technical audience.
  • Adept at working independently and as part of a team.
  • Strong problem-solving and analytical thinking skills.

Benefits

  • The remuneration package will commensurate with your qualifications and experience.