Security and IT Operations Engineer
About Hydra X
Hydra X operates regulated market infrastructure for tokenised capital markets. Our clients include banks, exchanges, asset managers and other financial institutions building and operating institutional digital asset markets across Asia.
We hold licences in Singapore and other jurisdictions, and operate production systems that support regulated financial market activity. The systems our engineers build and maintain must meet high standards of reliability, security, auditability and operational resilience.
The Role
We are looking for an Associate Engineer to support our security and IT operations in Singapore. You will run internal IT administration, maintain the technical control records our regulatory obligations require, and support our infrastructure security and key management operations.
This is a hands-on role suited to an engineer early in their career who wants to build a career in security engineering inside a regulated financial institution. You will be trained on our infrastructure, key management procedures and audit requirements, and you will work under supervision on anything touching production and cryptographic material. You will work with engineering teams across Singapore, Vietnam, China and Indonesia, and with Risk, Compliance and Operations in Singapore.
Responsibilities
- Run internal IT administration for the Singapore office, including account provisioning, onboarding and offboarding, endpoint security and IT asset inventory.
- Administer internal systems and access controls, and prepare records for periodic access reviews by authorised reviewers.
- Provide IT support to staff, escalating or coordinating with service providers where appropriate.
- Collect and maintain technical control evidence for ISO 27001, SOC 2, MAS TRM-aligned reviews and other regulatory reviews, including access records, change records and vulnerability remediation records.
- Implement agreed remediation on systems within scope, including patching, configuration changes and access control fixes.
- Track open remediation items, follow up with action owners and report status, and report status for review and closure.
- Prepare security and control metrics for ISMS and other committee reporting.
- Support infrastructure security work, including patching, vulnerability remediation, secure configuration and access control changes.
- Support security monitoring, log management and incident investigation alongside the engineering team.
- Support cryptographic key management operations under supervision, following documented procedures, dual control and segregation of duties.
- Maintain runbooks, operational records and supporting documentation to a standard that withstands audit.
- Support penetration testing and specialist assessments.
Requirements
- 2 to 3 years of experience in IT operations, infrastructure support, systems administration or a related technical role. Strong graduates with relevant internship experience will be considered.
- Working knowledge of Linux and networking fundamentals.
- Familiarity with identity and access management concepts, including account provisioning, permissions and access reviews.
- Some scripting ability in Python, bash or a similar language, or clear evidence of aptitude for it.
- Careful, methodical working habits. This role involves controlled procedures that must be followed exactly as written.
- Clear written documentation and accurate record keeping.
- Willingness to learn cryptographic key management, cloud security and regulatory technology requirements on the job.
- Strong written and verbal English.
- Based in Singapore, and able to attend on-site infrastructure activities as required.
Good to Have
- Exposure to cloud infrastructure, preferably AWS.
- Exposure to CI/CD pipelines, infrastructure as code or configuration management tools.
- Experience working in an environment subject to external audit or regulatory inspection.
- Background in financial services, capital markets or digital asset infrastructure.
- Familiarity with key management or hardware security modules in any capacity.
- Relevant certifications such as CompTIA Security+, AWS Cloud Practitioner or Solutions Architect Associate, or equivalent.