Search by job, company or skills

Cyber Security Specialist

4-6 Years
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

Job Summary

The Cybersecurity Specialist is the hands-on focal point for cybersecurity operations, information security assurance, incident response, audit and certification management, and customer security assurance. Reporting to the Head of IT, the role coordinates Group-wide internal, external, ISO, regulatory and customer audits and certifications, including readiness, evidence, findings and remediation.

The role partners with Sales, Technology, Legal and business teams on customer security assessments, tenders and due diligence, ensuring accurate and approved responses. Responsibilities also include security control testing, risk assessment, incident response, policy management and continuous improvement. The role combines technical cybersecurity expertise, audit discipline and commercial judgement.

Key Responsibilities

Security Operations and Monitoring

· Review and improve security monitoring across identity, endpoint, email, cloud, network, applications and critical third parties, tune use cases and escalation paths.

· Coordinate XDR/MDR and vendor alert triage, validate severity and evidence, manage escalations and ensure false positives/negatives inform tuning.

· Track threat intelligence and indicators relevant to the group, convert them into practical detections, blocks, checks or communications.

· Maintain security operational dashboards and daily/weekly oversight of material alerts, incidents, coverage gaps and overdue actions.

Vulnerability, Configuration and Identity Risk

· Coordinate asset-based vulnerability scanning, triage, risk-based remediation targets, exception documentation and validation of closure.

· Review security configuration and exposure for endpoints, identity, email, cloud, networks, applications and digital solutions against approved baselines.

· Support least privilege, MFA, privileged-access controls, joiner/mover/leaver processes, service-account governance and periodic access reviews to all systems.

· Partner with technology owners to prioritise and verify remediation, escalate overdue or repeatedly deferred critical risk.

Incident Response and Digital Forensics Coordination

· Maintain and activate incident-response policy, severity model, contact tree, playbooks, evidence procedures and communications/escalation requirements.

· Act as security incident coordinator or technical lead as directed, maintaining timeline, hypotheses, actions, evidence, containment options and stakeholder updates.

· Coordinate containment, eradication, recovery and validation with IT owners and qualified third parties while preserving evidence and chain of custody.

· Lead post-incident review, lessons learned and corrective-action tracking, support legal, privacy, insurer, regulator or law-enforcement engagement when authorised.

· Maintain and manage BCP procedures and communications/escalation requirements.

Enterprise Audit, ISO and Certification Management

· Own and centrally coordinate the group-wide audit and certification programme across functions, legal entities, sites, systems and key third parties, covering internal, external, customer, regulatory, supplier, ISO and cybersecurity audits.

· Maintain the master audit and certification calendar, scope register, obligations register, responsible-owner matrix, readiness status, evidence plan, renewal dates, budget inputs and escalation milestones.

· Lead the end-to-end lifecycle for applicable ISO management-system and cybersecurity certifications, including scoping, gap assessment, implementation planning, internal audit, management review, certification, surveillance, recertification and approved scope expansion.

· Maintain the management-system and assurance artefacts required by applicable standards, including policies, objectives, risk assessments, control library, Statement of Applicability where required, document register, records, metrics and management-review inputs.

· Plan and perform, or coordinate qualified parties to perform, readiness reviews, internal audits, control testing and evidence sampling using a risk-based and documented approach.

· Act as the primary liaison for certification bodies, external auditors, regulators, customers and other assessors, coordinate scope, agendas, interviews, site activities, evidence requests, responses and factual clarification.

· Maintain a controlled, access-managed audit evidence repository with clear ownership, version control, retention, traceability and approval before external release.

· Record findings, nonconformities and observations, assign accountable owners and due dates, challenge weak root-cause analysis or corrective actions, verify effectiveness before closure, and escalate overdue or repeatedly deferred items to the Head of IT and relevant executives.

· Report audit readiness, certification health, open findings, ageing, recurring themes, residual risk and resource needs to leadership. Preserve audit integrity, avoid self-certification and ensure residual risk is accepted only by an authorised risk owner.

Sales, Bids and Customer Assurance

· Act as the audit, ISO and cybersecurity assurance partner to Sales, Account Management and Bid/Tender teams from opportunity qualification through tender, contracting, onboarding and renewal.

· Coordinate and quality-review responses to RFPs, RFIs, due-diligence questionnaires, security schedules, control matrices and customer audit requests with Legal, Privacy, Quality, Product, Operations and technology owners.

· Maintain an approved, version-controlled assurance pack and response library covering certifications, scope statements, policies, control summaries, test reports and other evidence, release information only at the appropriate classification and approval level.

· Record all material assurance commitments, exceptions and promised remediation in an accountable register, obtain required approvals and hand them over to delivery or control owners so no sales commitment is lost after contract signature.

Third-Party, Project and Secure-by-Design Assurance

· Perform risk-based security review of vendors, contracts, architectures, integrations, data flows and production changes before commitment or release.

· Define security requirements and acceptance criteria, review control evidence such as certifications, penetration tests, incident terms and subprocess or information.

· Track material third-party findings and changes in risk and coordinate exit/continuity considerations for critical suppliers.

· Embed security gates and practical patterns into infrastructure, application, digital and AI delivery lifecycles.

· Perform other related duties and special projects as assigned by management to support operational needs.

Awareness, Exercises and Continuous Improvement

· Deliver role-appropriate awareness/training and phishing/social-engineering activities in coordination with HR and business leaders.

· Plan and facilitate cyber tabletop exercises covering executive, technical and business response, including ransomware, data breach, business email compromise and key vendor outage scenarios.

· Coordinate technical validation such as recovery tests, attack simulations or penetration tests based on risk and approved scope.

· Measure control effectiveness, maturity and incident readiness, maintain a prioritised improvement roadmap and communicate progress to leadership.

· Maintain and manage IT policies, SOP, guides and other IT related documents.

Qualifications

Education and Professional Background

· Diploma or degree in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline, or equivalent relevant experience.

· At least 4 years of hands-on experience across security operations, incident response, vulnerability management, governance/risk/compliance or security engineering.

· Experience supporting a multi-site or regional environment and coordinating internal teams plus managed security/technology vendors.

Technical and Assurance Capability

· Working knowledge of identity/MFA/PAM, endpoint and email security, SIEM/XDR, vulnerability scanning, cloud/network security, logging and incident evidence.

· Ability to investigate alerts using timelines, logs, endpoint/identity/network context and disciplined hypotheses, and to communicate uncertainty accurately.

· Practical understanding of ISO/IEC 27001, NIST CSF, CIS Controls or equivalent frameworks, risk assessment, audit evidence and remediation verification.

· Understanding of privacy, breach notification, records/evidence, third-party risk and secure-by-design requirements across multiple jurisdictions, able to engage Legal/Privacy rather than provide unauthorized legal conclusions.

· Relevant certifications such as Security+, SSCP, GCIH, CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or cloud security certifications are advantageous.

Communication and Judgement

· Fluent in written and spoken English and Chinese, with the ability to brief executives, guide technical responders and influence non-technical stakeholders across Chinese-speaking markets.

· Calm prioritization and evidence preservation during high-pressure incidents, including willingness to escalate incomplete or uncomfortable facts.

· Balanced, risk-based judgement that enables business outcomes while protecting mandatory controls and regulatory obligations.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 152547701

Similar Jobs

Singapore

Skills:

Cloud SecurityCIS NIST security benchmarkIM8 requirementsCyberSecurity Risk AssessmentVAPT Vulnerability AssessmentVAPT managementCyberSecurity certifications

Singapore

Skills:

logrhythm CyberarkPkiIpsHsmPAMWindows ServerTlsSiemIdsKubernetesRhelIamPalo AltoFirewallsVulnerability ScanningBeyondTrustNessusCheck Point

Singapore

Skills:

Azure Log AnalyticsAWS Security HubCloud SecurityCSPMAWS CloudWatchSecurity alerts Incident handlingMicrosoft Defender for CloudSecurity Audit HandlingSecurity Vulnerabilities management mitigations

Singapore

Skills:

IEC-62443 fundamentals certificationconsultancy business salesMaritime AutonomyOT cyber securityRemote Operations CentresAI developmentsCISSP certification

Singapore

Skills:

cloud securityIpsvulnerability assessmentSiemIdsDlpIncident ResponseISO IEC 27001risk managementendpoint protection

Beware of Scammers

We don’t charge money for job offers