About the Role
Our client is a public-sector organisation in Singapore responsible for overseeing critical infrastructure and built-environment systems, where cybersecurity resilience is a strategic priority. They are seeking an experienced
IT Security Consultant
to strengthen their security operations and governance function. In this role, you will serve as a key advisor and operator — managing vendors, overseeing testing cycles, and ensuring that enterprise systems remain robust against evolving cyber threats. This is an excellent opportunity for a seasoned cybersecurity professional to make a meaningful impact within a mission-driven organisation at the intersection of technology and public safety.
Key Responsibilities
- Lead the management of cybersecurity vendors, overseeing deliverables, performance, and service quality
- Drive periodic security testing cycles, including vulnerability assessments and penetration testing coordination
- Assess the adequacy and effectiveness of mitigation and remediation measures across systems and applications
- Review and enhance security policies, standards, procedures, and guidelines to align with industry best practices
- Provide expert cybersecurity consultancy to internal stakeholders, translating technical findings into actionable recommendations for non-technical audiences
- Monitor and respond to security alerts and advisories, and manage end-to-end incident handling processes
- Conduct security awareness training programmes and disseminate timely security advisories across the organisation
- Own the review of security reports, identifying trends and recommending improvements to the overall security posture
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, with at least 4 years of hands‑on experience in a cybersecurity analyst or equivalent role
- Holding a valid CISSP and/or CISM certification is required; additional certifications such as GCIH, OSCP, CEH, ECSA, CompTIA CySA+, CompTIA Security+, or SSCP (are a bonus)
- Strong working knowledge of network protocols, operating systems (Windows and Linux), andcloud securityconcepts across platforms such as AWS, Azure, or GCP
- Proficiency with security tooling including vulnerability scanners, penetration testing tools, andSIEM platforms; experience with scripting (e.g. Python, PowerShell) for security automation (is a bonus)
- Familiarity with cybersecurity frameworks and standards such as NIST and ISO 27001, and a solid understanding of OWASP Top 10 vulnerabilities and incident management practices
- Prior experience in software development or security operations (is a bonus)