Search by job, company or skills

5-7 Years
SGD 7,500 - 8,500 per month
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

IT Security Officer (ITSO)

In this role, you will help ensure that vulnerabilities and exposures across our environment are identified, validated, and remediated in a timely manner, responsible for IM8 cybersecurity policy development work. You will work closely with system owners and report findings, helping to keep our risk posture visible and well-managed.

Job Scope

  • Attack Surface Monitoring, Vulnerability Scanning, and Triage
  • Monitor and triage findings surfaced by our Attack Surface Management (ASM) and Vulnerability Management tools
  • Assess each finding for validity, severity, and exploitability before escalating or acting on it
  • Distinguish genuine exposures from false positives and contextualise findings against our asset inventory
  • Prioritise remediation efforts based on risk
  • Remediation Workflow Management
  • Work with system owners to follow up on outstanding findings
  • Track remediation progress and ensure findings are resolved in a timely manner
  • Manage exceptions and risk acceptance where remediation is not immediately feasible
  • Communicate clearly with non-technical stakeholders, translating technical findings into actionable guidance
  • Reporting & Insights
  • Consolidate vulnerability data and remediation metrics for reporting
  • Identify trends and surface systemic issues across the organisation's attack surface and internal asset landscape
  • Provide recommendations to improve our overall exposure management programme
  • Process Improvement
  • Contribute to the refinement of ASM and vulnerability management processes, tooling configurations, and escalation playbooks over time
  • Support the development and maintenance of vulnerability management policies, standards, and procedures in alignment with industry best practices

Prerequisites

  • Bachelor's Degree in Computer Science/Information Security or equivalent
  • Professional certifications, including GWEB, OSCP, CRISC, CISA or other relevant certifications will be preferred
  • Familiar with IM8 Cybersecurity policies will be preferred
  • Preferably 5 years of experience in a relevant cybersecurity function, such as vulnerability management, attack surface management, security operations, or IT risk
  • Strong understanding of cybersecurity concepts, particularly around vulnerability management, patch management, common vulnerability scoring frameworks (eg CVSS), and external-facing attack surface risks
  • Familiarity with ASM or vulnerability management tools (such as Tenable, Qualys, Censys, or similar)
  • Proficiency in programming languages such as Python will be advantageous
  • Strong analytical and judgement skills, with the ability to think critically and make sound recommendations
  • Good communication and interpersonal skills, with the ability to multitask, prioritise, and translate technical findings
  • Meticulous, with a high degree of integrity, initiative, and energy

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 151483427

Similar Jobs

Singapore

Skills:

CortexCloudformationTerraformSiemSplunkPAMWafNessusDamEDRAVTenable

Singapore

Skills:

Vulnerability ManagementIncident ResponseIdentity and Access Management IAMRisk AssessmentSecurity Monitoring ToolsSecurity Operations SOCCloud Security conceptsEndpoint Network and Infrastructure Security

Orchard Road, Singapore

Skills:

Vulnerability ManagementIncident ResponseSecurity ControlsIamrisk managementSecurity Operationscompliance with cybersecurity policiessecurity governancecybersecurity policiesSecurity Monitoringcybersecurity frameworkscloud security conceptssecurity risk assessments

Singapore

Skills:

Vulnerability ManagementCloud SecurityInfrastructure SecurityIncident ResponseIdentity and Access Management IAMRisk AssessmentSecurity Monitoring ToolsSecurity Operations SOC

Singapore

Skills:

Patch ManagementVulnerability ManagementQualysPythonAttack Surface ManagementCensysTenableCybersecurity concepts