Search by job, company or skills

7-10 Years
SGD 8,500 - 10,000 per month
Early Applicant
  • Posted 3 days ago
  • Be among the first 10 applicants

Job Description

The Information Technology Security Officer(ITSO) is responsible for supporting the organization's cybersecuritygovernance, risk management, incident response, and security operationsactivities. The role ensures that IT systems, applications, and infrastructureare protected in accordance with organizational security policies, regulatoryrequirements, and industry best practices.

Key Responsibilities

Security Governance & Compliance

  • Develop, maintain, and review information security policies, standards, procedures, and implementation roadmaps.
  • Support the establishment and continuous improvement of cybersecurity governance frameworks and security management practices.
  • Conduct security risk assessments and recommend mitigation measures to address identified risks.
  • Ensure compliance with applicable cybersecurity policies, standards, and regulatory requirements.
  • Monitor security controls and provide recommendations to enhance the organization's security posture.

Security Operations & IncidentManagement

  • Support the monitoring, detection, investigation, and response of cybersecurity incidents.
  • Coordinate with internal stakeholders and external service providers to manage and resolve security incidents.
  • Participate in cybersecurity exercises, simulations, and readiness assessments.
  • Investigate security events and perform root cause analysis to identify corrective and preventive actions.
  • Review security alerts, reports, and audit findings, ensuring timely follow-up and remediation.

Threat & Vulnerability Management

  • Monitor emerging cyber threats, vulnerabilities, and security trends.
  • Assess the impact of identified threats on the organization's environment and recommend mitigation strategies.
  • Support vulnerability management activities, including assessment, tracking, and remediation verification.
  • Evaluate security technologies and solutions to improve operational effectiveness and risk management.

Security Monitoring & AssetManagement

  • Ensure security monitoring coverage across relevant infrastructure components, systems, and applications.
  • Maintain visibility of assets under security monitoring and support onboarding of new assets into security platforms.
  • Review security dashboards and reports, providing regular updates to stakeholders on risks and remediation status.
  • Support continuous improvement of security monitoring and incident detection capabilities.

Stakeholder Engagement

  • Engage business, project, and technical teams on cybersecurity requirements and security best practices.
  • Conduct regular security reviews and recommend improvements to strengthen security controls.
  • Coordinate with external vendors, service providers, regulatory bodies, and industry partners on cybersecurity-related matters.
  • Provide cybersecurity advice and guidance to project teams during solution design and implementation.

Additional Duties

  • Support cybersecurity initiatives, audits, assessments, and special projects as assigned.
  • Contribute to the development of security awareness and cybersecurity improvement programs.
  • Perform other cybersecurity-related duties as required.

Qualifications & Experience

Education

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related discipline.

Experience

  • Minimum 7-10 years of experience in cybersecurity, information security, or IT infrastructure security roles.
  • Experience in security governance, risk management, security operations, or incident response.
  • Familiarity with enterprise security technologies and cybersecurity frameworks.
  • Experience working with cross-functional teams and external service providers.

Technical Knowledge

  • Understanding of cybersecurity principles, frameworks, standards, and best practices.
  • Knowledge of:
  • Security Operations (SOC)
  • Incident Response
  • Vulnerability Management
  • Risk Assessment
  • Security Monitoring Tools
  • Endpoint, Network, and Infrastructure Security
  • Identity and Access Management (IAM)
  • Cloud Security concepts
  • Familiarity with security investigations and digital forensic processes is advantageous.

Skills & Competencies

  • Strong analytical, problem-solving, and critical-thinking skills.
  • Good written, presentation, and communication skills.
  • Ability to engage stakeholders at different levels of the organization.
  • Strong organizational and documentation skills.
  • Ability to work independently and collaboratively in a team environment.

Preferred Certifications

Applicants possessing one or more of thefollowing certifications will have an advantage:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • GIAC Certified Incident Handler (GCIH)
  • Certified Ethical Hacker (CEH)
  • CompTIA Security+
  • Certified Information Systems Auditor (CISA)
  • GIAC Security Essentials (GSEC)

More Info

Job Type:
Industry:
Employment Type:

Job ID: 151421747

Similar Jobs

Singapore

Skills:

Vulnerability ManagementIncident ResponseIdentity and Access Management IAMRisk AssessmentSecurity Monitoring ToolsSecurity Operations SOCCloud Security conceptsEndpoint Network and Infrastructure Security

Orchard Road, Singapore

Skills:

Vulnerability ManagementIncident ResponseSecurity ControlsIamrisk managementSecurity Operationscompliance with cybersecurity policiessecurity governancecybersecurity policiesSecurity Monitoringcybersecurity frameworkscloud security conceptssecurity risk assessments

Singapore

Skills:

Vulnerability ManagementVulnerability ScanningQualysPythonAttack Surface ManagementCensysCybersecurity Policy DevelopmentTenable

Singapore, Kallang

Skills:

netcdf cloud securityCehAzureCismAWSrisk assessmentsGRIBcybersecurity measuresendpoint detection toolsGeoJSONIWXXMSIEM platformsGICSPvulnerability analysesCisspfismanisticsIEC 62443SCADAOT systemsBUFR

Eunos, Singapore

Skills:

SIEM platformsNIST FISMACybersecurity awareness trainingEndpoint detection toolsVulnerability scansSecurity AuditsEnvironmental monitoring technologiesIEC 62443Penetration tests