# Security Engineer

**Company:** [Pelago](null/companies/bf9LqjGgh7Q3hKjntjXAvJ.md)
**Location:** International Plaza, Singapore
**Workplace:** hybrid
**Employment type:** Full-time
**Department:** Technology

[Apply for this job](null/view/90ed7f12-bf59-4844-b378-3fb900fc2aae)

## Description

**WHO ARE WE?**

At Pelago, we’re reimagining how travelers explore the world, delivering curated rewarding experiences backed by the quality and trust of the Singapore Airlines Group. As a key part of the SIA ecosystem, we offer exclusive value, deals, and seamless KrisFlyer integration for travelers across Singapore Airlines, Scoot, and beyond. We are a fast-growing, high-ownership team looking for builders to scale our next phase of growth.

**WHAT WILL YOU BE DOING?**

As our Security Engineer, you will be responsible for building a robust, scalable, and proactive security program. You will work closely with engineering, operations, and leadership to secure our infrastructure, applications, and internal environments.

We’re seeking someone with strong hands-on expertise in SIEM, Security Policy development, Vulnerability Management, Security Operations (SOC), SAST/DAST testing, and Cloud Security.

## Requirements

**WHAT EXPERTISE ARE MUST HAVES FOR THIS ROLE?**

-   5+ years of experience in cybersecurity, security engineering, or related roles, preferably in a cloud-native environment.
-   Solid understanding of networking, authentication, encryption, and access control principles.
-   Comfortable building programs from scratch with minimal direction.
-   Strong written and verbal communication skills — especially in documenting security practices and working with engineering teams.
-   Knowledge of secure software development practices and OWASP principles
-   Good technical expertise in: SIEM solutions (e.g., Splunk, Crowdstrike, Datadog, Sentinel)
-   Developing and operationalising security policies and standards.
-   Running vulnerability management programs.
-   SOC monitoring and incident response workflows.
-   Implementing and integrating SAST/DAST tools (e.g., Snyk, Veracode, Checkmarx, Burp Suite).
-   Securing cloud infrastructure (AWS) using native and third-party security tools.

**WHAT EXPERTISE ARE GOOD TO HAVE FOR THIS ROLE?**

-   Security certifications (e.g., CISSP, OSCP, AWS Certified Security Specialty).
-   Experience with DevSecOps practices and securing containerized applications.
-   Previous experience scaling security programs in a startup or hypergrowth environment.
-   Familiarity with regulatory frameworks like SOC 2 or ISO 27001

_**Ready to apply?**_ _Submit your resume below, and our talent team will be in touch!_
