Search Jobs

Search by job, company or skills

IT Security Officer (Vulnerability & Risk Management)

IT Security Officer (Vulnerability & Risk Management)

jobline resources pte. ltd.
3-6 Years
SGD 7,000 - 9,000 per month
  • Posted 18 hours ago
  • Be among the first 10 applicants

Job Description

Responsibilities

Vulnerability Management

. Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)

. Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership

. Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions

. Track remediation status and escalate overdue items per defined SLAs

Risk Register & Risk Acceptance

. Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data

. Draft Risk Acceptance forms for identified risks that cannot be immediately remediated

. Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances

. Periodically review accepted risks for continued validity and reassessment

Security Operations Oversight

. Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment

. Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment

. Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems

Impact & Risk Analysis

. Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores

. Contextualise CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritisation

. Provide risk-based recommendations to stakeholders to support remediation prioritization decisions

Reporting & Communication

. Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review

. Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding

Requirements

. Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)

. 3-5+ years of experience in IT security operations, vulnerability management, or risk management

. Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)

. Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)

. Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)

. Strong understanding of CVSS scoring methodology and practical risk-based prioritization

. Experience developing and managing Risk Registers and Risk Acceptance documentation

. Excellent stakeholder management and communication skills, with ability to work cross-functionally



Licence no: 12C6060

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

CVSS scoring methodology

Rapid7

GuardDuty

vulnerability scanning tools

Tenable

Security Hub

AWS security services

Similar Jobs

5-8 yrs
SGD 8,000 - 10,000 per month
Sin Ming, Singapore
Skills:
risk registers , S3, Ec2, Iso 27001, Qualys, Security+, RDS, Rsa Archer, Iam, On-premises infrastructure security, Risk Acceptance processes, NIST CSF, Security Hub, CVSS, Tenable Nessus, Inspector, Cissp, NIST 800-53, CRISC, CySA+, Vulnerability remediation tracking, ServiceNow GRC, Rapid7, AWS security, AWS Security Specialty, GuardDuty, GRC tools