Job Description
IT Security Officer (Cybersecurity Governance & Assurance)
Experience Required: 5-7 years
About the Role
We are looking for an IT Security Officer to support cybersecurity governance, assurance, and security management across enterprise systems. You will coordinate security reviews and assessments, track remediation actions, maintain security registers and dashboards, and support the upkeep of cybersecurity policies, standards, and documentation. This role is suited for a detail-oriented security professional who is strong in coordination, documentation, and stakeholder management, and who can work across multiple technical and business teams.
Key Responsibilities
- Support security architecture governance by maintaining security architecture artefacts, tracking review requests, documenting decisions, and preparing advisory materials
- Coordinate vulnerability assessment and penetration testing (VAPT) engagements, maintain trackers, follow up on remediation, and manage re-testing and closure
- Facilitate cybersecurity risk assessments, maintain risk registers, track risk treatment actions, and support risk acceptance/exception workflows
- Coordinate system hardening compliance checks, track gaps, maintain checklists/records, and produce periodic compliance updates
- Monitor and triage cloud security posture findings, track misconfigurations, and drive remediation follow-ups with system and cloud owners
- Manage software security clearance requests, track approvals/expiry, and coordinate collection of required technical/security documentation
- Track firewall rule change requests and network security deviations, maintain deviation registers, and coordinate periodic reviews
- Support policy, standards, and governance activities including drafting/updating cybersecurity policies, standards, guidelines, procedures, and maintaining document repositories and review cycles
- Produce security metrics and reporting: consolidate status updates, maintain dashboards (vulnerabilities, risks, deviations, compliance, audit items), and prepare management reports
- Support security compliance and audit readiness, including evidence collection and maintaining accurate security records and documentation
- Handle sensitive information in accordance with organisational security and confidentiality requirements
Screening Requirements / Skills (Must-Have)
- Good understanding of enterprise cybersecurity concepts including vulnerability management, risk assessment, system hardening, firewall controls, cloud security, and security governance
- Experience coordinating security assessments and remediation activities involving multiple stakeholders (system owners, infrastructure teams, vendors)
- Ability to review and interpret VAPT findings, risk assessment outputs, architecture diagrams, firewall rule requests, and compliance reports
- Familiarity with cybersecurity frameworks, policies, standards, and governance processes
- Strong analytical, documentation, coordination, and follow-through skills
- Comfortable producing structured artefacts such as trackers, registers, dashboards, and management updates
Nice-to-Have / Advantage
- Familiarity with CSPM tools and cloud security concepts (AWS/Azure or equivalent)
- Experience interpreting CVE/CVSS and working with vulnerability management/VAPT tools
- Understanding of enterprise network security concepts (security zones, segmentation, firewall rule governance)
- Experience supporting audits, GRC activities, and compliance evidence collection
- Relevant certifications (advantage): Security+ / ISC2 CC, CISSP/CISM, CRISC, ISO 27001, cloud security certifications
More Info
Key Skills
remediation activities
CVSS
CSPM tools
CVE
system hardening
GRC activities
firewall controls


