IT Security Officer -
jobster private ltd.- Posted 3 hours ago
- Be among the first 10 applicants
Job Description
Job Description
The IT Security Officer will be responsible for supporting the organisation's information security posture, ensuring that IT systems, applications and data are protected against security threats and comply with applicable government security policies, standards and regulatory requirements.
The successful candidate will work closely with internal IT teams, application owners, infrastructure teams, vendors and business stakeholders to identify security risks, implement appropriate controls, monitor security compliance and respond to security incidents.
Key Responsibilities
Support the day-to-day management and monitoring of information security controls across IT systems, applications and infrastructure.
Identify, assess and manage cybersecurity risks, vulnerabilities and security exposures.
Conduct regular security assessments and vulnerability reviews and coordinate remediation activities with relevant IT teams and vendors.
Monitor security incidents, investigate alerts and coordinate incident response and remediation activities.
Perform security incident analysis, root cause analysis and follow-up actions to prevent recurrence.
Support security monitoring activities and review system, application and security logs where required.
Ensure timely application of security patches, updates and remediation measures to reduce security vulnerabilities.
Perform periodic review of user access, privileged accounts and system permissions to ensure appropriate access control.
Support identity and access management activities, including access reviews, account provisioning/deprovisioning and privileged-access controls.
Ensure IT systems comply with applicable government cybersecurity policies, security standards and internal controls.
Support security audits, risk assessments and compliance reviews, including tracking and remediation of audit findings.
Work with system owners, infrastructure teams, application teams and vendors to implement security controls and address identified risks.
Review security requirements for system enhancements, new applications, integrations and technology implementations.
Participate in security assessments during system development, testing, implementation and deployment.
Support security requirements analysis and provide security input for IT projects and system changes.
Maintain security documentation, policies, procedures, risk registers, assessment reports and security records.
Assist in the development and maintenance of security policies, SOPs and security guidelines.
Support business continuity, disaster recovery and high-availability exercises from an information-security perspective.
Conduct security awareness activities and advise users and IT teams on security best practices.
Keep abreast of emerging cybersecurity threats, vulnerabilities and relevant security standards.
Recommend continuous improvements to strengthen the organisation's cybersecurity posture.
Required Skills & Experience
Diploma or Degree in Information Technology, Computer Science, Cybersecurity, Information Security or a related discipline.
Relevant experience in IT security, cybersecurity, infrastructure security, application security or IT risk and compliance.
Good understanding of information security principles, security controls and risk management.
Experience in vulnerability assessment and remediation.
Experience in security incident management and troubleshooting.
Experience in access control and privileged-account management.
Experience working with IT infrastructure, applications, networks or cloud environments.
Experience coordinating security remediation activities with internal IT teams and external vendors.
Strong analytical and problem-solving skills.
Good stakeholder management and communication skills.
Ability to work independently as well as collaboratively with cross-functional teams.
Good documentation and reporting skills.
Preferred Skills
Experience supporting Singapore government or public-sector IT environments.
Knowledge of Singapore government cybersecurity policies, standards and controls.
Experience with Government Instruction Manuals / government security policies and standards.
Knowledge of Personal Data Protection Act (PDPA) requirements and data protection principles.
Experience with security audits, compliance assessments and risk registers.
Experience with security operations, SIEM, endpoint security, vulnerability-management or security-monitoring tools.
Experience with cloud security, particularly AWS or Microsoft Azure.
Knowledge of network security, application security, identity and access management and database security.
Experience with penetration testing or security assessment activities.
Relevant cybersecurity certifications such as CISSP, CISM, CEH, CompTIA Security+ or GIAC.
More Info
Key Skills
Security Incident Management
Privileged-Account Management
Security-Monitoring Tools
IT Risk and Compliance
Vulnerability-Management




