Intern - Information Security (Spring 2027, Jan to Jun)

SGX·Singapore·Generalist Tech Internships / Programmes / Graduate Schemes

SGX is hiring a Intern - Information Security (Spring 2027, Jan to Jun) in Singapore. Posted 2026-09-25; applications close 2026-11-24 (in 59 days).

Role details

Job Summary

We are Asia’s leading and trusted securities and derivatives market infrastructure, operating equity, fixed income, currency, and commodity markets to the highest regulatory standards. We also operate a multi-asset sustainability platform, SGX FIRST (Future in Reshaping Sustainability Together).

We are committed to facilitating economic growth in a sustainable manner, leveraging our roles as a key ecosystem player, business, regulator, and listed company. With climate action as a key priority, we aim to be a leading sustainable and transition financing and trading hub, offering trusted, quality, end-to-end products and solutions.

As Asia’s most international, multi-asset exchange, we provide listing, trading, clearing, settlement, depository, and data services. About 40% of listed companies and over 80% of listed bonds originate outside of Singapore. In foreign exchange, we are Asia's leading marketplace and most comprehensive service provider for global FX over-the-counter and futures participants.

Headquartered in AAA-rated Singapore, we are globally recognized for our risk management and clearing capabilities.

Be a part of this fast-paced world where your contributions count. SGX offers you the unique experience of gaining insights into the Exchange business and the finance value chain. You will be immersed in respective specialist functions—at SGX, we believe that our interns are involved in real-time work from Day 1.

Note: Leave of Absence (LOA) may be required to take on the internship.

Job Responsibilities

Brief Overview:

The Information Security Team encompasses key functions covering Governance & Risk, Design & Engineering, Defense & Response, and Security Operations. The team strengthens the cyber resiliency of SGX services to serve its customers and internet users.

Learning Objectives:

Shortlisted interns would participate and contribute to Information Security projects, daily operations, and the development and enhancement of existing processes/procedures, along with the implementation and governance of these controls. The intern will learn about security practices and implementations driven by industry best practice, regulatory, and business requirements, focusing on specific areas in Defence & Response, Design & Engineering, and Security Operations. Key learning areas include:

  • Security Architecture of the Enterprise.
  • Security Operations for the tools deployed within the SGX environment.
  • Determining how security intelligence is used within an organization.
  • Understanding how threat vulnerabilities change the approach to vulnerability management.
  • Identifying how process automation can be leveraged for manual tasks.

Job Description Details

Data Loss Prevention (DLP)

  • Assist in configuring and refining Microsoft Purview DLP policies and sensitivity labels across Microsoft 365 workloads.
  • Support the development and testing of advanced classifiers, including Exact Data Match (EDM), Document Fingerprinting, and Trainable Classifiers.
  • Monitor DLP policy alerts, investigate incidents, and document findings for review by the DLP Champion network.
  • Contribute to the DLP Champions programme by preparing communications, training materials, and awareness content.
  • Analyze policy effectiveness and produce periodic reporting on data protection posture.
  • Research emerging DLP capabilities and recommend improvements aligned with SGX's data governance framework.

Identity & Access Management (IAM)

  • Support day-to-day access provisioning and de-provisioning workflows in line with least-privilege principles.
  • Assist with periodic user access reviews and recertification campaigns across enterprise systems.
  • Help maintain IAM runbooks, role matrices, and access control documentation.
  • Contribute to the review and enforcement of Privileged Access Management (PAM) controls.
  • Liaise with application owners and HR to ensure joiner-mover-leaver processes are correctly executed.
  • Support audit and compliance activities related to access governance (e.g., MAS TRM, ISO 27001).

Security Design & Engineering

  • Support the design, development, and enhancement of security engineering solutions across enterprise platforms and services.
  • Assist in building scripts, utilities, and proof-of-concept solutions using structured programming languages such as Python, Java, C#, JavaScript, or similar technologies.
  • Apply Artificial Intelligence and automation concepts to explore opportunities for improving security processes, analysis, detection, and operational efficiency.
  • Work with security architects and engineers to document security design patterns, technical standards, and implementation guidelines.
  • Develop a strong understanding of foundational cybersecurity concepts, including secure design, threat modeling, vulnerability management, identity security, data protection, and defense-in-depth principles.
  • Participate in technical research on emerging security technologies, AI-enabled security capabilities, and secure software engineering practices.
  • Support cloud security-related engineering activities where applicable, including understanding cloud infrastructure, cloud-native security controls, and security considerations across major cloud platforms.
  • Contribute to documentation, testing, and validation of security controls to ensure solutions are aligned with regulatory expectations, enterprise standards, and industry best practices.

Threat & Vulnerability Management (TVM)

  • Support the team in vulnerability tracking, remediation coordination, and security reporting activities.
  • Develop and enhance automation solutions to streamline data collection, analysis, and management reporting processes.
  • Coordinate penetration testing activities conducted by independent security assessors and facilitate discussion for remediation.
  • Collaborate with Technology teams to gather, validate, and consolidate data for reporting.
  • Explore and evaluate AI-assisted approaches to improve operational efficiency, reporting accuracy, and response time to emerging cybersecurity threats.
  • Contribute to continuous improvement initiatives within cybersecurity operations and technology risk management.

Job Requirements & Skills

Knowledge and Skill Requirements

  • Good communication and stakeholder management skills.
  • Good command of English.
  • Basic knowledge of networking, operating systems, cloud technologies, or cybersecurity concepts.
  • Strong interest in Cybersecurity, Technology Risk Management, Automation, Data Analytics, or Artificial Intelligence.
  • Proactive, self-motivated, and willing to learn in a fast-paced environment.
  • Experience in PowerShell, Python, Tableau, PowerBI, and any other tools related to data analytics.
  • Good understanding of concepts around Identity and Access Management and Data Loss Prevention.
  • Detail oriented.

More open roles at SGX

Other open Generalist Tech Internships / Programmes / Graduate Schemes roles

Applying to this role

This Intern - Information Security (Spring 2027, Jan to Jun) role at SGX runs through the firm's own careers portal and expects a CV and cover letter written specifically for the posting, not a portable submission carried across firms. Jorb AI's application agent tailors a CV and cover letter from your background to this posting and tracks the role alongside the rest of your applications.

Jorb AI tracks details for Intern - Information Security (Spring 2027, Jan to Jun) at SGX. Postings refresh hourly from primary careers pages. Job details mirror the firm's posting; the apply link goes directly to the source. Last refreshed 2026-09-26.

SGX careers

Save this role and tailor your cover letter with Jorb AI.