Cybersecurity Engineer

Summary

This fractional cybersecurity engineer role involves managing security operations, penetration testing, and AI-assisted automation across multiple client organizations simultaneously. The engineer will build detection rules, automate triage, and implement security tooling while ensuring compliance with regulatory frameworks.

JOB DESCRIPTION

Cybersecurity Engineer

Fractional Role — Automa%on, AI Tooling & Hands-On Security Operations

Location Singapore / Remote

Employment Type Frac@onal / contract — concurrent mul@-client engagements

Engagement Model 2–4 clients simultaneously; engagements run 3–4 weeks to 3 months per client

Experience 7+ years in cybersecurity; 2+ years hands-on automa@on

Reports To Client CISO or Head of Security (per engagement); internally to Engagement Lead

Security Clearance Subject to per-client background verifica@on and NDA

WHY THIS ROLE EXISTS

Security teams in Singapore are hiring at pace — approximately 245 genuine cyber roles were posted in Singapore

alone in the last 30 days. Most of these teams are s@ll running manual playbooks: copy-paste SIEM queries,

spreadsheet-driven risk registers, and penetra@on test reports assembled by hand. Many cannot jus@fy or fill a full-@me

senior hire, but the gap in their security posture is real and growing.

This is a frac@onal role. You will work across two to four client organisa@ons simultaneously, each with its own security

stack, regulatory context, and maturity level. Engagements range from 3–4 week targeted sprints to 3-month

programmes — you may be running a pentest at one client, building SOC automa@on at another, and closing out an AI

governance engagement at a third, all in the same fortnight. The work is hands-on: you build detec@on rules, run

penetra@on tests, deploy automa@on, and ship AI-assisted tooling — then hand over cleanly and move to the next

client. The advantage of the model is that paQerns and playbooks that work at one client transfer to the next. The

requirement is that you ramp fast, deliver within compressed @melines, manage your own schedule, and leave behind

documenta@on good enough that the client does not need to call you back.

WHAT YOU WILL DO

Security OperaBons & DetecBon Engineering

• Build, tune, and maintain detec@on rules across SIEM and EDR plaVorms (Splunk, Sen@nel, CrowdStrike, or

equivalent). Write detec@on-as-code, version-controlled and peer-reviewed — not point-and-click console rules.

• Automate alert triage using SOAR plaVorms (XSOAR, Shuffle, Tines, or custom Python). Target: reduce Tier-1 analyst

manual triage by at least 40% within six months.

• Design and run tabletop exercises and purple-team sessions quarterly. Document findings, track remedia@on to

closure.

• Integrate threat intelligence feeds into detec@on pipelines. Automate IOC enrichment, scoring, and blocking

workflows.

PenetraBon TesBng & Offensive Security

• Conduct network, web applica@on, and API penetra@on tests across on-premises and cloud environments (AWS,

Azure, GCP).

• Automate recurring vulnerability scans and build dashboards that track remedia@on SLAs by asset owner — not just a

list of CVEs dumped into a PDF.

• Script custom exploita@on and post-exploita@on tooling where off-the-shelf tools fall short. Python, Go, or Bash —

whatever gets the job done.

• Write penetra@on test reports that technical teams can act on. Execu@ve summaries that non-technical stakeholders

can read without a translator.

Cloud Security & DevSecOps

• Embed security checks into CI/CD pipelines: SAST, DAST, SCA, container scanning. If the pipeline does not break on a

cri@cal finding, fix the pipeline.

• Review and harden Infrastructure-as-Code (Terraform, CloudForma@on) before deployment. Automate policy-as-

code using OPA/Rego or equivalent.

• Monitor cloud posture using CSPM tooling (Prisma Cloud, Wiz, or Aqua). Automate drig detec@on and

misconfigura@on alerts.

AI Tooling & Intelligent AutomaBon

• Evaluate and deploy AI-assisted security tools for log analysis, anomaly detec@on, phishing classifica@on, and code

review. We expect you to test these tools against your own benchmarks before rolling them out — vendor demos are

not evidence.

• Build LLM-powered workflows for common security tasks: automated report genera@on from scan outputs, natural-language querying of SIEM data, policy document summarisa@on. Use local or API-hosted models with appropriate data

handling controls.

• Develop and maintain prompt libraries and evalua@on harnesses for security-specific AI use cases. Track accuracy,

false-posi@ve rates, and analyst @me saved.

• Contribute to the organisaBon's AI governance framework: model risk assessment templates, data classifica@on for

AI training inputs, and usage policies for genera@ve AI in security opera@ons.

Governance, Risk & Compliance (SupporBng Role)

• Provide technical input for regulatory audits and compliance assessments under MAS TRM (Singapore), PDPA (both

jurisdic@ons), and ISO 27001.

• Automate evidence collec@on for audit cycles — pull configura@ons, access reviews, and control states directly from

systems rather than asking teams to fill spreadsheets.

• Maintain and update risk registers with real vulnerability and incident data, not theore@cal risk ra@ngs disconnected

from opera@onal reality.

WHAT YOU BRING

Non-NegoBable

• 7+ years in cybersecurity across at least two of: SOC/detec@on engineering, penetra@on tes@ng, cloud security, or

DevSecOps. We will verify this with technical assessment, not just resume keywords.

• ProducBon experience wriBng automaBon: Python scrip@ng, API integra@ons, SOAR playbook development, or CI/

CD security pipeline configura@on. Show us the code or the pipeline, not just the concept.

• Working knowledge of at least one major cloud plaVorm (AWS, Azure, or GCP) at the security configura@on level, not

just user-level console access.

• Familiarity with Singapore regulatory frameworks for technology risk (MAS TRM, BNM RMiT). You do not need to be

a compliance specialist, but you need to understand what auditors ask for and why.

• WriQen communica@on strong enough to produce a penetra@on test report or an incident post-mortem without

heavy edi@ng.

• Demonstrated ability to work across mul@ple concurrent engagements or projects. Consul@ng, frac@onal, or mul@-

client contract experience is a direct signal. If your en@re career has been single-employer, single-team, tell us how you

managed compe@ng workstreams.

• Self-directed @me management. No one will build your weekly schedule across clients. You allocate your own hours,

hold yourself to deadlines, and escalate conflicts before they become problems.

Strong Preference

• Hands-on experience with AI/ML tools applied to security: anomaly detec@on models, LLM-based automa@on, or

AI-driven threat hun@ng. We care about what you built and what it replaced, not which course you completed.

• Cer@fica@ons in OSCP, GPEN, GCIH, CISSP, or AWS/Azure security specialty. These support your candidacy but do not

subs@tute for demonstrated technical ability.

• Experience in financial services, fintech, or other regulated industries in Southeast Asia.

• Exposure to AI governance frameworks (NIST AI RMF, Singapore's Model AI Governance Framework, or ISO 42001).

This area is early-stage — prac@cal exposure maQers more than deep exper@se.

TOOLS & PLATFORMS (TYPICAL, NOT EXHAUSTIVE)

SIEM: Splunk, Microsog Sen@nel, Elas@c Security. EDR: CrowdStrike Falcon, Sen@nelOne, Defender for Endpoint. SOAR:

Palo Alto XSOAR, Tines, Shuffle. Vulnerability Management: Tenable, Qualys, Rapid7 InsightVM. Cloud Security: Prisma

Cloud, Wiz, AWS Security Hub, Azure Defender. Penetra@on Tes@ng: Burp Suite, Metasploit, Cobalt Strike, Nuclei,

custom tooling. DevSecOps: Snyk, Semgrep, Trivy, Checkov, GitHub Advanced Security. AI/ML: Python (scikit-learn,

pandas), LLM APIs (OpenAI, Anthropic, local models via Ollama), Jupyter notebooks for security data analysis.

HOW WE MEASURE SUCCESS

Engagements range from 3–4 week sprints (a targeted pentest, a detec@on-rule audit, an automa@on build) to 3-month

programmes (SOC capability uplig, full cloud security posture review, AI governance framework rollout). The metrics

below scale to the engagement length — a 3-week sprint has a @ghter delivery window and a narrower scope than a 3-

month programme, but the discipline is the same: agree the outcome upfront, deliver it, document what you leave

behind.

Short Engagements (3–4 weeks)

• Day 1–3: Complete environment access, stakeholder introduc@ons, and scope confirma@on. Produce a one-page

engagement plan with deliverables, owners, and deadlines before the first working week ends.

• Week 1–2: Execute primary deliverable — penetra@on test, detec@on rule audit, automa@on build, or vulnerability

assessment. Preliminary findings shared verbally with the client CISO by the end of week 2 so there are no surprises inthe final report.

• Week 3–4: Deliver final report or artefact. Include a handover document: what was done, what was not in scope,

what the client team needs to maintain or monitor going forward. The engagement is not complete un@l the handover

is accepted.

• Close-out: Client feedback collected within one week of delivery. One reusable artefact (template, playbook,

detec@on rule set, or script) contributed to the shared library from each short engagement.

Longer Engagements (2–3 months)

• Week 1–2 (Onboarding): Complete environment access, tool stack inventory, and stakeholder mapping. Deliver a

wriQen security posture snapshot — current detec@on coverage, automa@on gaps, and three priori@sed quick wins —

within the first 10 working days.

• Month 1: Deploy at least one automa@on workflow that measurably reduces manual effort. Target: 30–40%

reduc@on in a specific manual process (Tier-1 triage, evidence collec@on, scan-to-report cycle). The metric is agreed

with the client CISO at onboarding.

• Month 2: Complete at least one penetra@on test or purple-team exercise. Deliver findings with remedia@on owners

and SLA deadlines. Ship one AI-assisted tool or workflow into produc@on use — track analyst hours saved or detec@on

coverage gained, not adop@on.

• Month 3: Deliver final engagement report with measurable before-and-ager metrics. Conduct handover sessions

with the client's internal team. Document all automa@on, detec@on rules, and AI workflows with enough detail that the

client can maintain them independently.

Across the Porbolio (measured monthly by Engagement Lead)

• Client saBsfacBon: Post-engagement feedback scores and renewal or referral rate. If a client is dissa@sfied, we want

to know during the engagement, not ager the final invoice.

• UBlisaBon: Maintain 80–90% billable alloca@on across concurrent clients. Below 80% is a pipeline problem; above

90% typically means quality or context-switching is suffering. Flag either direc@on early.

• Throughput: With variable-length engagements, you will cycle through more clients per quarter than a fixed-

alloca@on model. Target: 4–6 completed engagements per quarter across the porVolio, depending on mix of short and

long.

• Playbook reuse: Document repeatable artefacts that transfer across clients. Target: at least two reusable playbooks,

detec@on rule sets, or assessment templates contributed to the shared library per quarter.

• Cross-client pacern recogniBon: Present a monthly internal brief — five slides, no padding — on common gaps,

misconfigura@ons, or regulatory blind spots you are seeing across engagements (sani@sed, no client-aQributable data).

• Scope discipline: Deliver within the contracted scope and hours. Scope creep absorbed silently erodes margins and

sets expecta@ons we cannot sustain. Flag overruns to the Engagement Lead within the week they occur, not at invoice

@me.

What Good Looks Like at Month 6

You have completed 8–12 client engagements of varying lengths without dropping context or quality on any of them. At

least three clients have either renewed, extended, or referred a new engagement. Every engagement has a handover

document the client team can act on without calling you back. You have contributed six or more reusable artefacts to

the shared library. Your monthly cross-client briefs contain paQerns the sales team can use in new conversa@ons — not

because you are selling, but because the observa@ons are genuinely useful. You manage your own schedule across

overlapping engagements, and your Engagement Lead hears about problems early, not late.

WHAT THIS ROLE IS NOT

This is not a staff-augmenta@on seat. You will not sit inside one client's team full-@me doing whatever they assign. You

own specific outcomes across mul@ple clients, manage your own schedule, and deliver against agreed metrics. That

requires more autonomy than a typical contract role — and more discipline.

This is not a pure compliance or audit role. If your career has been primarily policy wri@ng, risk register management,

or audit coordina@on without hands-on technical work, this is not the right fit.

This is not a tool-administra@on role. We need someone who builds and automates, not someone who maintains

vendor dashboards and generates scheduled reports. And it is not a management role — you will influence technical

direc@on at each client, but you will not manage their teams or ours.

TO APPLY

Send your CV and a short note (under 300 words) covering two things: one security automa@on or AI-assisted workflow

you built, what it replaced, and what it saved in @me or risk reduc@on; and one example of how you managed

overlapping client or project commitments without dropping quality. Generic cover leQers will not be read.

Technical assessment is part of the process. Expect a hands-on exercise — not a mul@ple-choice quiz. We will also

discuss how you structure your week across concurrent engagements.Equal Opportunity Employer. We evaluate candidates on ability and fit, regardless of race, gender, age, na%onality, or disability status. Reasonable

accommoda%ons provided on request.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available