Search Jobs

Search by job, company or skills

IT Security Officer Vulnerability & Risk Management

IT Security Officer Vulnerability & Risk Management

sagl consulting pte. ltd.
5-8 Years
SGD 8,000 - 10,000 per month
  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

Role Overview

We are looking for an IT Security Officer specializing in Vulnerability Management and IT Risk Management to support a hybrid on-premises and AWS environment.

The role will own the vulnerability management lifecycle, maintain the IT Risk Register, drive remediation and risk acceptance activities, and provide risk-based recommendations to technical and business stakeholders.

Key Responsibilities

  • Manage the end-to-end vulnerability management lifecycle across on-premises and AWS environments.
  • Run and manage vulnerability scans using tools such as Tenable/Nessus, Qualys or Rapid7.
  • Review vulnerability findings, assess their impact and prioritize remediation based on CVSS and business/technical context.
  • Track remediation activities with infrastructure and application SMEs and escalate overdue vulnerabilities.
  • Maintain the IT Risk Register and ensure risks, owners, treatment plans and status are current.
  • Prepare and coordinate Risk Acceptance for vulnerabilities or risks that cannot be remediated within the required timeframe.
  • Work with technical and business stakeholders to obtain risk acceptance approvals and periodically review accepted risks.
  • Review vendor security advisories and determine their applicability and potential impact to the environment.
  • Monitor security-update compliance for AV/EDR, IDS/IPS and similar security controls.
  • Prepare vulnerability and risk management dashboards/status reports for management.
  • Work across Security, Infrastructure, Cloud and Application teams to drive remediation and risk reduction.

Required Skills

  • 3-5+ years of experience in Vulnerability Management, IT Security or Risk Management.
  • Hands-on experience with Tenable/Nessus, Qualys, Rapid7 or equivalent vulnerability scanning tools.
  • Strong understanding of CVSS and risk-based vulnerability prioritization.
  • Practical experience managing Risk Registers and Risk Acceptance processes.
  • Strong experience in vulnerability remediation tracking and coordination with technical SMEs.
  • Good understanding of on-premises infrastructure security covering servers, network devices and endpoints.
  • Working knowledge of AWS security and the shared responsibility model, particularly EC2, S3, RDS, IAM and services such as Security Hub, GuardDuty and Inspector.
  • Strong stakeholder management and communication skills.

Preferred

  • Experience with GRC tools such as ServiceNow GRC or RSA Archer.
  • Knowledge of NIST CSF, NIST 800-53 or ISO 27001.
  • Relevant certifications such as Security+, CySA+, CISSP, CRISC or AWS Security Specialty.
  • Experience supporting security/risk management in a hybrid cloud environment or managed-services/customer environment.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

On-premises infrastructure security

Risk Acceptance processes

NIST CSF

Security Hub

CVSS

Tenable Nessus

NIST 800-53

CySA+

Vulnerability remediation tracking

ServiceNow GRC

Rapid7

AWS security

AWS Security Specialty

GuardDuty

GRC tools