Cybersecurity Specialist

LANDI INTERNATIONAL (SINGAPORE) PTE. LTD.

Singapore

On-site

SGD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

LANDI INTERNATIONAL (SINGAPORE) PTE. LTD. is seeking a Cybersecurity Specialist to lead group-wide audits, manage ISO and cybersecurity certifications, and coordinate incident response.

The role collaborates with Sales, Delivery teams and external auditors to ensure evidence, scope and remediation meet business and regulatory requirements. The ideal candidate has hands-on security operations experience, and a strong understanding of ISO frameworks, governance and risk management within

Qualifications

  • Diploma or degree in Cybersecurity, IT, CS or related field.
  • At least 4 years hands-on experience in security operations, incident response, governance or risk.
  • Experience coordinating multi-site regional teams and vendors.

Responsibilities

  • Oversee security operations and monitoring across multiple domains.
  • Coordinate vulnerability management, remediation and evidence collection.
  • Lead incident response, digital forensics coordination and post-incident reviews.

Skills

Cybersecurity
Incident Response
Audits & Certifications
Threat Detection
Cloud Security
SIEM/XDR

Education

Bachelor’s or Diploma in Cybersecurity/IT/CS

Tools

SIEM/XDR
Threat Intelligence
Cloud Security Tools

Job description

Job Summary

The Cybersecurity Specialist is the hands-on group focal point for cybersecurity operations, enterprise audit and certification management, information-security assurance, incident response and customer assurance. Reporting to the Head of IT, the role works across all group functions, legal entities and sites, and with Sales, technology teams, business leaders, auditors, certification bodies, customers and vendors.

The role is the central owner and coordinator of the group-wide audit and certification programme. It leads the full lifecycle for internal, external, customer, regulatory, supplier, ISO and cybersecurity audits and certifications, including annual planning, scope definition, readiness assessment, evidence coordination, audit execution, finding management, corrective actions, surveillance and recertification. Functional and control owners remain responsible for operating their controls, providing evidence and implementing remediation.

The role works closely with Sales, Account Management and Bid/Tender teams to interpret customer ISO and cybersecurity requirements, support tenders and due diligence, prepare accurate and approved responses, and participate in customer assurance discussions. It enables commercial progress without making unsupported claims, disclosing restricted evidence or accepting commitments without the required business, legal and technical approvals.

The role combines practical cybersecurity expertise, audit discipline and commercial judgement. Lead audits, test controls, coordinate remediation, manage incidents and translate certification requirements into clear actions for management, customers and delivery teams.

Key Responsibilities
Security Operations and Monitoring
  • Review and improve security monitoring across identity, endpoint, email, cloud, network, applications and critical third parties, tune use cases and escalation paths.
  • Coordinate XDR/MDR and vendor alert triage, validate severity and evidence, manage escalations and ensure false positives/negatives inform tuning.
  • Track threat intelligence and indicators relevant to the group, convert them into practical detections, blocks, checks or communications.
  • Maintain security operational dashboards and daily/weekly oversight of material alerts, incidents, coverage gaps and overdue actions.
Vulnerability, Configuration and Identity Risk
  • Coordinate asset-based vulnerability scanning, triage, risk-based remediation targets, exception documentation and validation of closure.
  • Review security configuration and exposure for endpoints, identity, email, cloud, networks, applications and digital solutions against approved baselines.
  • Support least privilege, MFA, privileged-access controls, joiner/mover/leaver processes, service-account governance and periodic access reviews to all systems.
  • Partner with technology owners to prioritise and verify remediation, elevate overdue or repeatedly deferred critical risk.
Incident Response and Digital Forensics Coordination
  • Maintain and activate incident-response policy, severity model, contact tree, playbooks, evidence procedures and communications/escalation requirements.
  • Act as security incident coordinator or technical lead as directed, maintaining timeline, hypotheses, actions, evidence, containment options and stakeholder updates.
  • Coordinate containment, eradication, recovery and validation with IT owners and qualified third parties while preserving evidence and chain of custody.
  • Lead post-incident review, lessons learned and corrective-action tracking, support legal, privacy, insurer, regulator or law-enforcement engagement when authorised.
  • Maintain and manage BCP procedures and communications/escalation requirements.
Enterprise Audit, ISO and Certification Management
  • Own and centrally coordinate the group-wide audit and certification programme across functions, legal entities, sites, systems and key third parties, covering internal, external, customer, regulatory, supplier, ISO and cybersecurity audits.
  • Maintain the master audit and certification calendar, scope register, obligations register, responsible-owner matrix, readiness status, evidence plan, renewal dates, budget inputs and escalation milestones.
  • Lead the end-to-end lifecycle for applicable ISO management-system and cybersecurity certifications, including scoping, gap assessment, implementation planning, internal audit, management review, certification, surveillance, recertification and approved scope expansion.
  • Maintain the management-system and assurance artefacts required by applicable standards, including policies, objectives, risk assessments, control library, Statement of Applicability where required, document register, records, metrics and management-review inputs.
  • Plan and perform, or coordinate qualified parties to perform, readiness reviews, internal audits, control testing and evidence sampling using a risk-based and documented approach.
  • Act as the primary liaison for certification bodies, external auditors, regulators, customers and other assessors, coordinate scope, agendas, interviews, site activities, evidence requests, responses and factual clarification.
  • Maintain a controlled, access-managed audit evidence repository with clear ownership, version control, retention, traceability and approval before external release.
  • Record findings, nonconformities and observations, assign accountable owners and due dates, challenge weak root-cause analysis or corrective actions, verify effectiveness before closure, and elevate overdue or repeatedly deferred items to the Head of IT and relevant executives.
  • Report audit readiness, certification health, open findings, ageing, recurring themes, residual risk and resource needs to leadership. Preserve audit integrity, avoid self-certification and ensure residual risk is accepted only by an authorised risk owner.
Sales, Bids and Customer Assurance
  • Act as the audit, ISO and cybersecurity assurance partner to Sales, Account Management and Bid/Tender teams from opportunity qualification through tender, contracting, onboarding and renewal.
  • Coordinate and quality-review responses to RFPs, RFIs, due-diligence questionnaires, security schedules, control matrices and customer audit requests with Legal, Privacy, Quality, Product, Operations and technology owners.
  • Maintain an approved, version-controlled assurance pack and response library covering certifications, scope statements, policies, control summaries, test reports and other evidence, release information only at the appropriate classification and approval level.
  • Record all material assurance commitments, exceptions and promised remediation in an accountable register, obtain required approvals and hand them over to delivery or control owners so no sales commitment is lost after contract signature.
Third-Party, Project and Secure-by-Design Assurance
  • Perform risk-based security review of vendors, contracts, architectures, integrations, data flows and production changes before commitment or release.
  • Define security requirements and acceptance criteria, review control evidence such as certifications, penetration tests, incident terms and subprocess or information.
  • Track material third-party findings and changes in risk and coordinate exit/continuity considerations for critical suppliers.
  • Embed security gates and practical patterns into infrastructure, application, digital and AI delivery lifecycles.
  • Perform other related duties and special projects as assigned by management to support operational needs.
Awareness, Exercises and Continuous Improvement
  • Deliver role-appropriate awareness/training and phishing/social-engineering activities in coordination with HR and business leaders.
  • Plan and facilitate cyber tabletop exercises covering executive, technical and business response, including ransomware, data breach, business email compromise and key vendor outage scenarios.
  • Coordinate technical validation such as recovery tests, attack simulations or penetration tests based on risk and approved scope.
  • Measure control effectiveness, maturity and incident readiness, maintain a prioritised improvement roadmap and communicate progress to leadership.
  • Maintain and manage IT policies, SOP, guides and other IT related documents.
Qualifications
Education and Professional Background
  • Diploma or degree in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline, or equivalent relevant experience.
  • At least 4years of hands-on experience across security operations, incident response, vulnerability management, governance/risk/compliance or security engineering.
  • Experience supporting a multi-site or regional environment and coordinating internal teams plus managed security/technology vendors.
Technical and Assurance Capability
  • Working knowledge of identity/MFA/PAM, endpoint and email security, SIEM/XDR, vulnerability scanning, cloud/network security, logging and incident evidence.
  • Ability to investigate alerts using timelines, logs, endpoint/identity/network context and disciplined hypotheses, and to communicate uncertainty accurately.
  • Practical understanding of ISO/IEC 27001, NIST CSF, CIS Controls or equivalent frameworks, risk assessment, audit evidence and remediation verification.
  • Understanding of privacy, breach notification, records/evidence, third-party risk and secure-by-design requirements across multiple jurisdictions, able to engage Legal/Privacy rather than provide unauthorized legal conclusions.
  • Relevant certifications such as Security+, SSCP, GCIH, CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or cloud security certifications are advantageous.
Communication and Judgement
  • FluentinwrittenandspokenEnglishandChinese,withtheabilitytobriefexecutives,guidetechnicalrespondersandinfluencenon-technicalstakeholdersacrossChinese-speakingmarkets.
  • Calm prioritization and evidence preservation during high-pressure incidents, including willingness to elevate incomplete or uncomfortable facts.
  • Balanced, risk-based judgement that enables business outcomes while protecting mandatory controls and regulatory obligations.
Key Competencies
  • Prioritizes by credible threat, exposure, business impact and control effectiveness.
  • Able to create order from uncertainty, preserves evidence, communicates clearly and drives safe containment/recovery.
  • Tests whether controls work in practice and closes findings only with adequate evidence.
  • Secures remediation and behaviour change through clarity, partnership and proportionate recommendations.
  • Handles sensitive information carefully, reports facts accurately and avoids conflicts or unauthorized disclosure.
  • Tracks evolving threats, technology and obligations and translates them into practical improvements.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

LANDI Global • Singapore

On-site
SGD 90,000 - 130,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Security Engineer
Security Engineer

U3 Infotech Pte Ltd • Singapore

On-site
SGD 100,000 - 180,000
Security Manager
Security Manager

ensign infosecurity (cybersecurity) pte. ltd. • Singapore

On-site
SGD 120,000 - 170,000
Cybersecurity Associate Consultant (Cyber Audit)
Cybersecurity Associate Consultant (Cyber Audit)

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 55,000 - 85,000
IT Compliance Manager
IT Compliance Manager

Bank Of China Limited • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Assurance Specialist or Lead
Cybersecurity Assurance Specialist or Lead

Kerry Consulting • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Auditor
Cybersecurity Auditor

BDO ADVISORY PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Technical Project Manager (Cyber Security)
Technical Project Manager (Cyber Security)

d l resources pte ltd • Singapore

On-site
SGD 160,000 - 230,000
Director - Cyber Security Architect
Director - Cyber Security Architect

Selby Jennings • Singapore

On-site
SGD 240,000 - 360,000