Intern - Information Security (Spring 2027, Jan to Jun)
Singapore, SG
Job Summary
We are Asia’s leading and trusted securities and derivatives market infrastructure, operating equity, fixed income, currency and commodity markets to the highest regulatory standards. We also operate a multi-asset sustainability platform, SGX FIRST or Future in Reshaping Sustainability Together (sgx.com/first). We are committed to facilitating economic growth in a sustainable manner leveraging our roles as a key player in the ecosystem, a business, regulator and listed company. With climate action as a key priority, we aim to be a leading sustainable and transition financing and trading hub offering trusted, quality, end-to-end products and solutions. As Asia’s most international, multi-asset exchange, we provide listing, trading, clearing, settlement, depository and data services, with about 40% of listed companies and over 80% of listed bonds originating outside of Singapore. We are the world's most liquid international market for the benchmark equity indices of China, India, Japan and ASEAN. In foreign exchange, we are Asia's leading marketplace and most comprehensive service provider for global FX over-the-counter and futures participants. Headquartered in AAA rated Singapore, we are globally recognised for our risk management and clearing capabilities.
Be a part of this fast-paced world where your contributions count. SGX offers you the unique experience of gaining insights into the Exchange business and the finance value chain. You will be immersed in the respective specialist functions – at SGX, we believe that our interns are involved in real-time work from Day 1.
Note: Leave of Absence (LOA) may be required to take on the internship.
Job Responsibilities
Brief Overview:
The Information Security Team encompasses key functions, covering Governance & Risk, Design & Engineering, Defense & Response, and Security Operations. The team strengthens the cyber resiliency of SGX services to service its customers and internet users.
Learning Objectives:
The shortlisted intern would participate and contribute in the Information Security projects, daily operations, development of new and enhancement to existing processes/procedures, the implementation and governance of these set of controls. The intern will learn about security practices and implementation driven by industry best practice, regulatory and business requirements. Specific for areas in Defence & Response, Design & Engineering and Security Operations.
- Security Architecture of the Enterprise.
- Security Operations for the tools deployed within the SGX environment.
- Determine/ identify how security intelligence is used within an organization
- Understand how threat vulnerability changes the way we look at vulnerability management
- Determine/ identify how we can leverage on process automation for manual tasks
Job Description
- Data Loss Prevention (DLP)
-
- Assist in configuring and refining Microsoft Purview DLP policies and sensitivity labels across Microsoft 365 workloads.
- Support the development and testing of advanced classifiers including Exact Data Match (EDM), Document Fingerprinting, and Trainable Classifiers.
- Monitor DLP policy alerts, investigate incidents, and document findings for review by the DLP Champion network.
- Contribute to the DLP Champions programme by preparing communications, training materials, and awareness content.
- Analyse policy effectiveness and produce periodic reporting on data protection posture.
- Research emerging DLP capabilities and recommend improvements aligned to SGX's data governance framework.
- Identity & Access Management (IAM)
-
- Support day-to-day access provisioning and de-provisioning workflows in line with least-privilege principles.
- Assist with periodic user access reviews and recertification campaigns across enterprise systems.
- Help maintain IAM runbooks, role matrices, and access control documentation.
- Contribute to the review and enforcement of Privileged Access Management (PAM) controls.
- Liaise with application owners and HR to ensure joiner-mover-leaver processes are correctly executed.
- Support audit and compliance activities related to access governance (e.g. MAS TRM, ISO 27001).
Job Requirements
- Security Design & Engineering
-
- Support the design, development, and enhancement of security engineering solutions across enterprise platforms and services.
- Assist in building scripts, utilities, and proof-of-concept solutions using structured programming languages such as Python, Java, C#, JavaScript, or similar technologies.
- Apply Artificial Intelligence and automation concepts to explore opportunities for improving security processes, analysis, detection, and operational efficiency.
- Work with security architects and engineers to document security design patterns, technical standards, and implementation guidelines.
- Develop a strong understanding of foundational cybersecurity concepts including secure design, threat modelling, vulnerability management, identity security, data protection, and defense-in-depth principles.
- Participate in technical research on emerging security technologies, AI-enabled security capabilities, and secure software engineering practices.
- Support cloud security-related engineering activities where applicable, including understanding cloud infrastructure, cloud-native security controls, and security considerations across major cloud platforms.
- Contribute to documentation, testing, and validation of security controls to ensure solutions are aligned with regulatory expectations, enterprise standards, and industry best practices.
- Threat & Vulnerability Management (TVM)
-
- Support the team in vulnerability tracking, remediation coordination, and security reporting activities.
- Develop and enhance automation solutions to streamline data collection, analysis, and management reporting processes.
- Coordinate penetration testing activities conducted by independent security assessors and facilitate the discussion for remediation.
- Collaborate with Technology teams to gather, validate, and consolidate data for reporting.
- Explore and evaluate AI-assisted approaches to improve operational efficiency, reporting accuracy, and response time to emerging cybersecurity threats.
- Contribute to continuous improvement initiatives within cybersecurity operations and technology risk management.
Knowledge and Skill Requirements
- Good communication and stakeholder management skill.
- Good command of English
- Basic knowledge of networking, operating systems, cloud technologies, or cybersecurity concepts.
- Strong interest in Cybersecurity, Technology Risk Management, Automation, Data Analytics, or Artificial Intelligence.
- Proactive, self-motivated, and willing to learn in a fast-paced environment.
- Experience in PowerShell, Python, Tableau, PowerBI and any other tools related to data analytics
- Good understanding of concepts around Identity and Access Management and Data Loss Prevention
- Detail oriented
Job Segment:
Information Security, Risk Management, Loss Prevention, Cloud, Compliance, Technology, Finance, Security, Legal