Job Description
The IT SecurityOfficer will beresponsible for supportingthe organisation's informationsecurity posture, ensuringthatIT systems, applicationsand data areprotected against securitythreats and complywith applicable governmentsecurity policies, standardsand regulatory requirements.
The successful candidatewill work closelywithinternal IT teams, application owners, infrastructureteams, vendors andbusiness stakeholders toidentify security risks, implement appropriatecontrols, monitor securitycompliance and respondto securityincidents.
Key Responsibilities
- Support the day-to-day managementand monitoring ofinformation security controlsacross IT systems, applications and infrastructure.
- Identify, assess and manage cybersecurityrisks, vulnerabilitiesand security exposures.
- Conduct regular security assessments and vulnerability reviews and coordinate remediation activities with relevant IT teamsand vendors.
- Monitor security incidents, investigate alerts andcoordinate incident responseand remediation activities.
- Perform security incidentanalysis, root causeanalysis and follow-up actions toprevent recurrence.
- Support security monitoring activities and review system, application and securitylogs where required.
- Ensure timely applicationof security patches, updates and remediationmeasures to reducesecurity vulnerabilities.
- Perform periodicreview of useraccess, privileged accountsand system permissionsto ensure appropriateaccess control.
- Support identity and access management activities,including access reviews, account provisioning/deprovisioningand privileged-accesscontrols.
- Ensure IT systems comply with applicable government cybersecurity policies,security standards andinternal controls.
- Support security audits, risk assessments andcompliance reviews, includingtracking and remediationof audit findings.
- Work with systemowners, infrastructureteams, application teamsand vendors toimplement security controlsand address identifiedrisks.
- Review security requirementsfor system enhancements, new applications, integrationsand technology implementations.
- Participate in securityassessments during systemdevelopment, testing, implementationand deployment.
- Supportsecurity requirements analysisand provide securityinput for ITprojects and systemchanges.
- Maintain security documentation,policies, procedures, riskregisters, assessment reportsand security records.
- Assist in thedevelopment and maintenanceof security policies, SOPs and securityguidelines.
- Support businesscontinuity, disaster recoveryand high-availabilityexercises from aninformation-security perspective.
- Conduct security awareness activities and adviseusers and ITteams on securitybest practices.
- Keep abreast ofemerging cybersecuritythreats, vulnerabilitiesand relevant securitystandards.
- Recommend continuous improvementsto strengthen theorganisation's cybersecurityposture.
Required Skills & Experience
- Diploma or Degreein Information Technology, Computer Science, Cybersecurity, Information Security ora related discipline.
- Relevant experience inIT security, cybersecurity, infrastructure security, application security orIT risk andcompliance.
- Good understanding ofinformation security principles, security controls andrisk management.
- Experience in vulnerabilityassessment and remediation.
- Experience in securityincident management andtroubleshooting.
- Experience in accesscontrol and privileged-account management.
- Experience working withIT infrastructure, applications, networks or cloudenvironments.
- Experience coordinatingsecurity remediation activitieswith internal ITteams and externalvendors.
- Strong analytical andproblem-solving skills.
- Good stakeholder managementand communication skills.
- Ability to workindependently as wellas collaboratively withcross-functional teams.
- Good documentation andreporting skills.
Preferred Skills
- Experience supportingSingapore government orpublic-sector ITenvironments.
- Knowledge of Singaporegovernment cybersecuritypolicies, standards andcontrols.
- Experience withGovernment Instruction Manuals/ government security policiesand standards.
- Knowledge ofPersonal Data ProtectionAct (PDPA)requirements and dataprotection principles.
- Experience with securityaudits, compliance assessmentsand risk registers.
- Experience with securityoperations, SIEM, endpointsecurity, vulnerability-management or security-monitoring tools.
- Experience with cloud security, particularly AWS orMicrosoft Azure.
- Knowledge of networksecurity, application security, identity and accessmanagement and databasesecurity.
- Experience with penetrationtesting or securityassessment activities.
- Relevant cybersecurity certificationssuch asCISSP, CISM, CEH, CompTIA Security+ orGIAC.