IT Security Engineer/Officer

Recruit Express Pte Ltd

Singapore

On-site

SGD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Recruit Express Pte Ltd seeks a security professional to lead vulnerability management across on-prem and AWS environments, generate reports, coordinate with SMEs, and ensure timely remediation or documented exceptions.

You will own the risk register, oversee security operations, review vendor advisories, and provide risk-based recommendations to leadership. Strong CVSS expertise and stakeholder communication are essential.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field.
  • 3-5+ years of IT security operations, vulnerability management, or risk management.
  • Hands-on with vulnerability scanning tools (Tenable/Nessus, Qualys, Rapid7).
  • Working knowledge of AWS security services and shared responsibility model.
  • Solid understanding of CVSS scoring methodology and risk prioritization.
  • Experience developing and managing Risk Registers and Risk Acceptance documentation.
  • Excellent stakeholder management and communication skills, with cross-functional collaboration.

Responsibilities

  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services.
  • Generate, review, and distribute vulnerability reports to technical teams and leadership.
  • Follow up with SMEs on outstanding findings to ensure timely remediation or documented exceptions.
  • Track remediation status and escape overdue items per SLAs.
  • Own and maintain the organization's Risk Register with current risk data.
  • Draft Risk Acceptance forms for risks requiring non-immediate remediation.
  • Coordinate with stakeholders to review and obtain formal approval on risk acceptances.
  • Monitor that security signatures updates are applied consistently across the environment.
  • Review vendor security bulletins to determine applicability to the customer environment.
  • Provide risk-based recommendations to stakeholders to support remediation prioritization.
  • Prepare periodic status reports/dashboards on vulnerability management and risk acceptances.

Skills

Vulnerability management
IT security operations
Risk management
Cloud security AWS
CVSS scoring
Stakeholder communication

Education

Bachelor's degree in Information Security, Computer Science, or related field

Tools

Tenable/Nessus
Qualys
Rapid7
AWS Security Services

Job description

Vulnerability Management
  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and escape overdue items per defined SLAs
Risk Register & Risk Acceptance
  • Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment
Security Operations Oversight
  • Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
  • Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
Impact& Risk Analysis
  • Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores
  • Contextualize CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritization
  • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions
Reporting& Communication
  • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
  • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding
Required Qualifications
  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)
  • 3-5+ years of experience in IT security operations, vulnerability management, or risk management
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally
Preferred Qualifications
  • Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar
  • Experience with GRC tools (e.g., ServiceNow GRC, Archer)
  • Familiarity with frameworks such as NIST 800-53, NIST CSF, or ISO 27001
  • Experience working in a hybrid on-prem/cloud environment supporting external customers
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Officer (Vulnerability & Risk Management)
IT Security Officer (Vulnerability & Risk Management)

infinite Computer Solution • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer - Vulnerability & Risk Management
IT Security Officer - Vulnerability & Risk Management

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
IT Security Officer (Vulnerability & Risk Management) (Ref 26589)
IT Security Officer (Vulnerability & Risk Management) (Ref 26589)

Jobline Resources Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer – Vulnerability & Risk Management
IT Security Officer – Vulnerability & Risk Management

SAGL Consulting • Singapore

Hybrid
SGD 80,000 - 140,000
IT Security Officer
IT Security Officer

PCCW SOLUTIONS INSYS PTE. LTD. • Singapore

On-site
SGD 100,000 - 150,000
IT Security Officer (ITSO)
IT Security Officer (ITSO)

SEDHA CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Consultant, IT Security (ITSO) - #1679
Consultant, IT Security (ITSO) - #1679

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 70,000 - 110,000
IT Security Officer
IT Security Officer

User Experience Researchers Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

Manpower Staffing Services (Singapore) Pte Ltd • Singapore

On-site
SGD 90,000 - 120,000
Senior Information Technology Security Officer
Senior Information Technology Security Officer

Total eBiz Solutions • Singapore

On-site
SGD 90,000 - 150,000