Cyber Security Specialist

LANDI Global

Singapore

On-site

SGD 90,000 - 130,000

Full time

Just now
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

LANDI Global is seeking a Cybersecurity Specialist to lead hands-on operations, incident response, and assurance activities across the group. You will coordinate audits, readiness, evidence collection and remediation, while partnering with Sales, Legal and business teams on customer security assessments and due diligence.

The role requires strong technical cybersecurity expertise combined with audit discipline and commercial judgement, and reports to the Head of IT.

Qualifications

  • Diploma or degree in Cybersecurity, IT, CS or related discipline.
  • At least 4 years of hands-on experience across security operations, incident response, vulnerability management, governance/risk/compliance or security engineering.

Responsibilities

  • Lead security operations, incident response, audit readiness and certification management.
  • Coordinate audits and certifications (internal, external, ISO, regulatory, customer).
  • Collaborate with Sales, Legal and business units on security assessments and due diligence.
  • Maintain incident response policy, playbooks, evidence handling and communications.
  • Manage governance, risk, compliance activities and continuous improvement.

Skills

Security operations
Incident response
Vulnerability management
Audit & compliance
ISMS/ISO 27001
Stakeholder communication

Education

Diploma or degree in Cybersecurity, IT, CS or related

Tools

SIEM/XDR
Vulnerability scanners
Cloud security

Job description

The Cybersecurity Specialist is the hands‑on focal point for cybersecurity operations, information security assurance, incident response, audit and certification management, and customer security assurance. Reporting to the Head of IT, the role coordinates Group‑wide internal, external, ISO, regulatory and customer audits and certifications, including readiness, evidence, findings and remediation.

The role partners with Sales, Technology, Legal and business teams on customer security assessments, tenders and due diligence, ensuring accurate and approved responses. Responsibilities also include security control testing, risk assessment, incident response, policy management and continuous improvement. The role combines technical cybersecurity expertise, audit discipline and commercial judgement.

Key Responsibilities
Security Operations and Monitoring
  • Review and improve security monitoring across identity, endpoint, email, cloud, network, applications and critical third parties, tune use cases and escalation paths.
  • Coordinate XDR/MDR and vendor alert triage, validate severity and evidence, manage escalations and ensure false positives/negatives inform tuning.
  • Track threat intelligence and indicators relevant to the group, convert them into practical detections, blocks, checks or communications.
  • Maintain security operational dashboards and daily/weekly oversight of material alerts, incidents, coverage gaps and overdue actions.
Vulnerability, Configuration and Identity Risk
  • Coordinate asset-based vulnerability scanning, triage, risk-based remediation targets, exception documentation and validation of closure.
  • Review security configuration and exposure for endpoints, identity, email, cloud, networks, applications and digital solutions against approved baselines.
  • Support least privilege, MFA, privileged-access controls, joiner/mover/leaver processes, service-account governance and periodic access reviews to all systems.
  • Partner with technology owners to prioritise and verify remediation, prioritise overdue or repeatedly deferred critical risk.
Incident Response and Digital Forensics Coordination
  • Maintain and activate incident-response policy, severity model, contact tree, playbooks, evidence procedures and communications/escalation requirements.
  • Act as security incident coordinator or technical lead as directed, maintaining timeline, hypotheses, actions, evidence, containment options and stakeholder updates.
  • Coordinate containment, eradication, recovery and validation with IT owners and qualified third parties while preserving evidence and chain of custody.
  • Lead post‑incident review, lessons learned and corrective‑action tracking, support legal, privacy, insurer, regulator or law‑enforcement engagement when authorised.
  • Maintain and manage BCP procedures and communications/escalation requirements.
Enterprise Audit, ISO and Certification Management
  • Own and centrally coordinate the group‑wide audit and certification programme across functions, legal entities, sites, systems and key third parties, covering internal, external, customer, regulatory, supplier, ISO and cybersecurity audits.
  • Maintain the master audit and certification calendar, scope register, obligations register, responsible‑owner matrix, readiness status, evidence plan, renewal dates, budget inputs and escalation milestones.
  • Lead the end‑to‑end lifecycle for applicable ISO management‑system and cybersecurity certifications, including scoping, gap assessment, implementation planning, internal audit, management review, certification, surveillance, recertification and approved scope expansion.
  • Maintain the management‑system and assurance artefacts required by applicable standards, including policies, objectives, risk assessments, control library, Statement of Applicability where required, document register, records, metrics and management‑review inputs.
  • Plan and perform, or coordinate qualified parties to perform, readiness reviews, internal audits, control testing and evidence sampling using a risk‑based and documented approach.
  • Act as the primary liaison for certification bodies, external auditors, regulators, customers and other assessors, coordinate scope, agendas, interviews, site activities, evidence requests, responses and factual clarification.
  • Maintain a controlled, access‑managed audit evidence repository with clear ownership, version control, retention, traceability and approval before external release.
  • Record findings, nonconformities and observations, assign accountable owners and due dates, challenge weak root‑cause analysis or corrective actions, verify effectiveness before closure, and challenge weak root‑cause analysis or corrective actions, verify effectiveness before closure, and ???
  • Report audit readiness, certification health, open findings, ageing, recurring themes, residual risk and resource needs to leadership. Preserve audit integrity, avoid self‑certification and ensure residual risk is accepted only by an authorised risk owner.
Sales, Bids and Customer Assurance
  • Act as the audit, ISO and cybersecurity assurance partner to Sales, Account Management and Bid/Tender teams from opportunity qualification through tender, contracting, onboarding and renewal.
  • Coordinate and quality‑review responses to RFPs, RFIs, due‑diligence questionnaires, security schedules, control matrices and customer audit requests with Legal, Privacy, Quality, Product, Operations and technology owners.
  • Maintain an approved, version‑controlled assurance pack and response library covering certifications, scope statements, policies, control summaries, test reports and other evidence, release information only at the appropriate classification and approval level.
  • Record all material assurance commitments, exceptions and promised remediation in an accountable register, obtain required approvals and hand them over to delivery or control owners so no sales commitment is lost after contract signature.
Third‑Party, Project and Secure‑by‑Design Assurance
  • Perform risk‑based security review of vendors, contracts, architectures, integrations, data flows and production changes before commitment or release.
  • Define security requirements and acceptance criteria, review control evidence such as certifications, penetration tests, incident terms and subprocess or information.
  • Track material third‑party findings and changes in risk and coordinate exit/continuity considerations for critical suppliers.
  • Embed security gates and practical patterns into infrastructure, application, digital and AI delivery lifecycles.
  • Perform other related duties and special projects as assigned by management to support operational needs.
Awareness, Exercises and Continuous Improvement
  • Deliver role‑appropriate awareness/training and phishing/social‑engineering activities in coordination with HR and business leaders.
  • Plan and facilitate cyber tabletop exercises covering executive, technical and business response, including ransomware, data breach, business email compromise and key vendor outage scenarios.
  • Coordinate technical validation such as recovery tests, attack simulations or penetration tests based on risk and approved scope.
  • Measure control effectiveness, maturity and incident readiness, maintain a prioritised improvement roadmap and communicate progress to leadership.
  • Maintain and manage IT policies, SOP, guides and other IT related documents.
Qualifications
Education and Professional Background
  • Diploma or degree in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline, or equivalent relevant experience.
  • At least 4 years of hands‑on experience across security operations, incident response, vulnerability management, governance/risk/compliance or security engineering.
  • Experience supporting a multi‑site or regional environment and coordinating internal teams plus managed security/technology vendors.
Technical and Assurance Capability
  • Working knowledge of identity/MFA/PAM, endpoint and email security, SIEM/XDR, vulnerability scanning, cloud/network security, logging and incident evidence.
  • Ability to investigate alerts using timelines, logs, endpoint/identity/network context and disciplined hypotheses, and to communicate uncertainty accurately.
  • Practical understanding of ISO/IEC 27001, NIST CSF, CIS Controls or equivalent frameworks, risk assessment, audit evidence and remediation verification.
  • Understanding of privacy, breach notification, records/evidence, third‑party risk and secure‑by‑design requirements across multiple jurisdictions, able to engage Legal/Privacy rather than provide unauthorized legal conclusions.
  • Relevant certifications such as Security+, SSCP, GCIH, CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or cloud security certifications are advantageous.
Communication and Judgement
  • Fluent in written and spoken English and Chinese, with the ability to brief executives, guide technical responders and influence non‑technical stakeholders across Chinese‑speaking markets.
  • Calm prioritization and evidence preservation during high‑pressure incidents, including willingness to escalat incomplete or uncomfortable facts.
  • Balanced, risk‑based judgement that enables business outcomes while protecting mandatory controls and regulatory obligations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Compliance Manager
IT Compliance Manager

Bank Of China Limited • Singapore

On-site
SGD 120,000 - 180,000
Cyber Defense Lead
Cyber Defense Lead

Univers Invest • Singapore

On-site
SGD 200,000 - 300,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cybersecurity Associate Consultant (Cyber Audit)
Cybersecurity Associate Consultant (Cyber Audit)

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 55,000 - 85,000
Cybersecurity Engineer, Security Programmes (Contract)
Cybersecurity Engineer, Security Programmes (Contract)

Monetary Authority of Singapore • Singapore

On-site
SGD 70,000 - 100,000
Cybersecurity Auditor
Cybersecurity Auditor

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Associate Director - Cyber Security
Associate Director - Cyber Security

BGC GROUP PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Head of Cybersecurity / Security Engineering Manager
Head of Cybersecurity / Security Engineering Manager

Charterhouse Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
Senior Executive, IT Security Operations
Senior Executive, IT Security Operations

auto & general (sea) services pte. limited • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Analyst
Cyber Security Analyst

Peoplebank Singapore Pte Ltd • Singapore

On-site
SGD 70,000 - 110,000