S
IT Security Officer Vulnerability & Risk Management
S
IT Security Officer Vulnerability & Risk Management
sagl consulting pte. ltd.- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Role Overview
We are looking for an IT Security Officer specializing in Vulnerability Management and IT Risk Management to support a hybrid on-premises and AWS environment.
The role will own the vulnerability management lifecycle, maintain the IT Risk Register, drive remediation and risk acceptance activities, and provide risk-based recommendations to technical and business stakeholders.
Key Responsibilities
- Manage the end-to-end vulnerability management lifecycle across on-premises and AWS environments.
- Run and manage vulnerability scans using tools such as Tenable/Nessus, Qualys or Rapid7.
- Review vulnerability findings, assess their impact and prioritize remediation based on CVSS and business/technical context.
- Track remediation activities with infrastructure and application SMEs and escalate overdue vulnerabilities.
- Maintain the IT Risk Register and ensure risks, owners, treatment plans and status are current.
- Prepare and coordinate Risk Acceptance for vulnerabilities or risks that cannot be remediated within the required timeframe.
- Work with technical and business stakeholders to obtain risk acceptance approvals and periodically review accepted risks.
- Review vendor security advisories and determine their applicability and potential impact to the environment.
- Monitor security-update compliance for AV/EDR, IDS/IPS and similar security controls.
- Prepare vulnerability and risk management dashboards/status reports for management.
- Work across Security, Infrastructure, Cloud and Application teams to drive remediation and risk reduction.
Required Skills
- 3-5+ years of experience in Vulnerability Management, IT Security or Risk Management.
- Hands-on experience with Tenable/Nessus, Qualys, Rapid7 or equivalent vulnerability scanning tools.
- Strong understanding of CVSS and risk-based vulnerability prioritization.
- Practical experience managing Risk Registers and Risk Acceptance processes.
- Strong experience in vulnerability remediation tracking and coordination with technical SMEs.
- Good understanding of on-premises infrastructure security covering servers, network devices and endpoints.
- Working knowledge of AWS security and the shared responsibility model, particularly EC2, S3, RDS, IAM and services such as Security Hub, GuardDuty and Inspector.
- Strong stakeholder management and communication skills.
Preferred
- Experience with GRC tools such as ServiceNow GRC or RSA Archer.
- Knowledge of NIST CSF, NIST 800-53 or ISO 27001.
- Relevant certifications such as Security+, CySA+, CISSP, CRISC or AWS Security Specialty.
- Experience supporting security/risk management in a hybrid cloud environment or managed-services/customer environment.
