JOB DESCRIPTION
Date: 2026-08-07
Location: Singapore, , Singapore
Company: NCS
Job Requisition ID: REF1781O
Company Description
NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse workforce of 15,000 has delivered large-scale, mission-critical, and multi-platform projects for governments and enterprises in Singapore and the APAC region.
Job Description
We are looking for an engineer who will own the end-to-end evaluation, design, and implementation of security and observability solutions for a container-based private cloud platform. This role spans the full lifecycle — from architectural research and tool selection through production deployment and ongoing operations — across unified telemetry, security detection, vulnerability management, supply chain security, and automated incident response.
You will be the technical owner of the platform's observability and security monitoring stack, working across platform engineering, security operations, and SRE teams to deliver a unified telemetry-first architecture.
What will you do?
Evaluation & Research
Conduct structured evaluation of candidate tools against criteria including licence compliance, community governance, vendor independence, and technical fitness
Perform proof-of-concept exercises to validate architectural decisions (e.g. ingestion throughput, storage efficiency, query latency, operational complexity)
Assess and track governance posture of selected tools; maintain contingency paths for vendor-led dependencies
Engage with upstream open-source communities and foundations to stay current on project maturity and roadmap changes
Design & Architecture
Design unified telemetry pipelines using open standards to serve both SRE observability and security operations from a single data layer
Architect security detection workflows using vendor-neutral detection languages to ensure portability of detection content across backends
Design vulnerability aggregation and management workflows spanning container scanning, software composition analysis, static analysis, infrastructure vulnerability scanning, and software bill of materials generation
Design supply chain security controls including image signing, provenance attestation, and registry policy enforcement
Design exposure path analysis using graph-based tooling to map relationships across compute orchestration, identity, source control, and vulnerability data
Design automated remediation and orchestration workflows integrated with alerting, ChatOps, and ticketing
Produce and maintain architecture decision records documenting design rationale, trade-offs, and change history
Implementation & Operations
Deploy and operate the observability stack: telemetry collection, columnar storage, dashboarding, metrics scraping, alerting, and log routing
Deploy and operate the security monitoring stack: endpoint/host-based detection, detection rule evaluation, vulnerability aggregation, and infrastructure scanning
Deploy and operate CI pipeline security scanning: container image scanning, dependency scanning, SBOM generation, static analysis, infrastructure-as-code scanning, and secrets detection
Implement image registry security with integrated vulnerability scanning and admission policy enforcement
Implement identity, directory, secrets management, and certificate lifecycle infrastructure
Implement collaboration and incident management tooling (ChatOps, ticketing)
Build and maintain detection rules, alerting rules, and automation playbooks
Operate all components on a container orchestration platform with fleet-wide deployment tooling
Process & Governance
Define and document operational runbooks for each capability area
Establish and maintain vendor-independence contingency entries for all vendor-led tools
Conduct periodic licence and governance re-assessment of selected tools
Collaborate with legal/compliance on copyleft licence reviews before deployment
Define SLOs for telemetry pipeline availability, ingestion latency, and detection coverage
Participate in security incident response using the tooling you build and operate
Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
Relevant certifications are a plus but not required (e.g. Kubernetes security, Linux administration, offensive security, or cloud security specialisations)
5+ years in platform engineering, SRE, or security engineering roles
Strong hands-on experience with at least 3 of the following:
Telemetry collection frameworks and instrumentation standards
Columnar or analytical databases for log/trace/event storage
Metrics scraping and alerting ecosystems
SIEM operations and detection engineering (vendor-neutral detection rule formats preferred)
Search-based log analytics platforms (to understand migration context)
Production experience deploying and operating on Kubernetes or equivalent container orchestration platforms
Experience with container security scanning and software composition analysis tooling
Familiarity with supply chain security concepts: SBOM, image signing, provenance attestation, admission control
Experience with at least one SOAR or automation/orchestration platform
Solid understanding of log collection and routing architectures
Experience writing detection rules or correlation logic for security monitoring
Ability to evaluate open-source projects for governance health, licence risk, and production readiness
Strong Linux systems fundamentals
Experience with host-based intrusion detection or endpoint detection and response tooling
Experience with graph databases and asset/infrastructure relationship mapping
Familiarity with vulnerability management and aggregation platforms
Experience with identity providers, directory services, and secrets management
Contributions to open-source security or observability projects
Experience operating in government or regulated environments with strict vendor-independence or sovereignty requirements
Familiarity with enterprise Linux and container platform ecosystems
Experience with GitOps workflows for deploying infrastructure services
Static/dynamic application security testing tooling experience
Additional Information
We are driven by our AEIOU beliefs—Adventure, Excellence, Integrity, Ownership, and Unity—and we seek individuals who embody these values in both their professional and personal lives. We are committed to our Impact: Valuing our clients, Growing our people, and Creating our future.
Together, we make the extraordinary happen.
Learn more about us at ncs.co and visit our LinkedIn career site.
Scam Alert
We are aware of fraudulent job offers and impersonations of NCS recruiters. Phishing emails using convincing-looking but fake addresses are also commonly used to trick you into thinking that they come from official NCS sources.
Please note that all official communications from NCS Group will only be sent from verified corporate email addresses. Always check that the sender’s email address ends with the genuine NCS domain, @ncs.com.sg and beware of extra letters, symbols or misspellings. When in doubt, verify the sender’s identity by contacting us at reachus@ncs.com.sg.
.jobdetail-video-Uz5Uk8RANNs { background-image: url(https://img.youtube.com/vi/Uz5Uk8RANNs/default.jpg) }
.jobdetail-video-MRD9fnMYzdE { background-image: url(https://img.youtube.com/vi/MRD9fnMYzdE/default.jpg) }