IT Security Officer
Our client, one of Asia‑Pacific’s leading organizations is looking for:
Responsibilities
- Conduct security reviews, system hardening checks and conducting risk assessment based on deviations to hardening requirements (e.g. CIS Benchmarks)
- Create hardening baselines using available benchmarks (e.g. CIS Benchmarks or those provided by the manufacturer).
- Review and maintain Standard Operation Procedures (SOPs), plan and schedule annual reviews of security hardening documents, perform compliance reviews, and ensure remediation of findings.
- Monitor phishing alerts and communicate with staff regarding malicious emails, support audit activities, vulnerability scans, and penetration tests.
- Perform malware scans on endpoints with anti‑virus alerts following SOP.
- Work with cloud security engineers and System Managers to follow up on findings identified in CSPM and in‑house CSPM tool (Cloudscape). Perform routine review of CSPM findings, monitor suppression expiry, and follow up with system Officers‑in‑Charge and infrastructure teams to rectify actions in a timely manner.
- Maintain a tracking system to monitor the status of remediation efforts, document whether recommended actions have been completed, are in progress, or require escalation, ensuring accountability and timely resolution of security issues.
- Assess whether security recommendations are required or false alarms using the provided GenAI tool.
- Provide vulnerability monitoring and recommend and implement mitigation actions to system Officers‑in‑Charge and infrastructure teams.
- Provide security advice or proposals on security measures for new projects and functionalities and monitor governance compliance tools, such as Cloudscape.
- Prioritise rectification of alerts based on risk assessments (e.g. Cloudscape).
- Manage and update governance compliance tools with relevant information to suppress affected findings when approval is sought.
- Respond to auditors’ RFI on security monitoring.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field
- Recognised security certifications such as CISSP, CISM, CRISC, or CISA.
- Proven experience of at least 4 years in Cloud cybersecurity is required, including security assessment, vulnerability management within cloud and on‑prem environments, particularly GCC.
- Familiarity with security platforms such as Azure Log Analytics, AWS CloudWatch, AWS Security Hub CSPM, and Microsoft Defender for Cloud is preferred.
- Strong analytical and problem‑solving skills are necessary to resolve security related issues, along with excellent communication skills in both spoken and written English to effectively collaborate with team members, system Officers‑in‑Charge, infrastructure teams, and external vendors.
Interested applicants can also email CV at jagveer@nsearchglobal.com (for faster processing, please state the exact job / position title applied “IT Security Officer”).
Only shortlisted candidates will be notified.
EA License Number: 10C3636
EA Personnel Name: Jagveer Singh Arora
EA Personnel Registration Number: R22109615