Search by job, company or skills

Security Analyst

2-4 Years
SGD 6,000 - 8,000 per month
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

Key Responsibilities

Vulnerability Management

. Own and manage the end-to-end Vulnerability Management process, including intake, triage, and lifecycle tracking of security findings across the organization's systems and assets.

. Classify vulnerabilities by severity, exploitability, and business impact using frameworks such as CVSS, EPSS, and internal risk criteria.

. Plan, coordinate, and manage Quarterly Vulnerability Assessments - scoping targets, engaging scanning tools, reviewing outputs, and driving findings through to resolution.

. Manage the Yearly Penetration Testing cycle, including scoping, vendor coordination, findings review, and tracking remediation commitments through to closure.

. Track key remediation implementations end-to-end, maintaining visibility from initial detection through to verified closure - for example, overseeing the transition of WAF rules from detection mode to prevention mode, ensuring each step is documented, tested, and signed off.

. Coordinate with remediation teams (engineering, DevOps, infrastructure) to ensure timely resolution of findings, providing clear context and prioritization guidance.

. Maintain and update risk acceptance records, ensuring appropriate approvals are obtained, documented, and reviewed on schedule.

. Track and report on remediation SLAs, escalating overdue or high-risk items to the appropriate stakeholders.

. Produce regular status reports and dashboards that communicate the project's overall security posture to technical and non-technical audiences.

Security Visibility & Reporting

. Aggregate vulnerability data from multiple scanning tools and sources into a coherent, unified view of security risk.

. Develop and maintain metrics and KPIs that enable leadership visibility into ongoing security exposure and program effectiveness.

. Present findings, trends, and recommendations in written reports, executive briefings, and team meetings.

Collaboration & Process Improvement

. Act as a liaison between the security team and remediation owners, facilitating communication and removing blockers to resolution.

. Continuously improve vulnerability management workflows, tooling, and documentation.

. Support audit and compliance activities by providing evidence of vulnerability tracking and risk treatment processes.

. Contribute to threat intelligence efforts and stay current on emerging CVEs and attack trends relevant to the organization.

Qualifications Required

. 2+ years of experience in an information security, vulnerability management, or related role.

. Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7, Wiz, or similar).

. Solid understanding of CVSS scoring, vulnerability classification, and risk-based prioritization.

. Experience communicating security findings and risk to both technical teams and business stakeholders.

. Familiarity with common compliance and risk frameworks (e.g., NIST CSF, ISO 27001, SOC 2).

. Familiarity with GovTech's IM8 (Instruction Manual 8) policies and its associated risk-based assessment methodology, including the application of controls, classification of government ICT systems, and conducting or supporting IM8-aligned security reviews.

. Strong organizational skills with the ability to manage multiple workstreams and deadlines simultaneously.

Preferred

. Relevant certifications such as CompTIA Security+, CEH, GWAPT, or equivalent.

. Experience with ticketing and workflow tools (e.g., Jira, ServiceNow) for tracking remediation.

. Scripting or automation skills (Python, Bash) to support data aggregation and reporting workflows.

. Background in cloud security environments (AWS, Azure, GCP).

More Info

Job Type:
Industry:
Employment Type:

Job ID: 152185895

Similar Jobs

Singapore

Skills:

Vulnerability ManagementRisk-Based PrioritizationCVSS Scoring

Shenton Way, Singapore

Skills:

KibanaServicenowWindows ServerItil ProcessesVulnerability ManagementTcp IpDnsGrafanaIpsDatadogIncident ResponseDHCPVpnElasticsearchIdsNetwork TroubleshootingPythonLinux AdministrationBash ScriptingPowerShellJiraPkiPalo AltoLog AnalysisPAMMFABasic AWSAzure knowledgeIBM QRadar SIEMFortinet FirewallsPim

Singapore

Skills:

Incident ResponseVulnerability ManagementPowerShellSiemIso27001PythonEDRKQLNIST CSFSOC audits

Singapore

Skills:

Vulnerability ManagementSecurity ComplianceSiemSecurity OperationsOutsourcing GuidelinesIAM toolingRisk Assessmentevidence gatheringMAS Technology Risk Management GuidelinesIT risk governanceCyber Hygiene NoticeAudit Coordinationpolicy documentationremediation trackingvendor due diligence

Singapore

Skills:

Vulnerability ManagementNetwork AdministrationInfrastructure SupportEndpoint SecurityNetwork SecurityCybersecurity OperationsSIEM MonitoringSecurity Monitoring

Beware of Scammers

We don’t charge money for job offers