Job Search and Career Advice Platform

Enable job alerts via email!

IT Security Officer - Contract

NTT SINGAPORE PTE. LTD.

Singapore

On-site

SGD 70,000 - 95,000

Full time

3 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading IT security firm in Singapore is seeking a team of IT Security Officers (ITSOs) to serve as cybersecurity subject matter experts. Responsibilities include conducting security reviews, performing risk assessments, and ensuring compliance with security standards. Candidates must possess a relevant bachelor's degree, hold certifications such as CISSP or CISM, and have at least 2 years of experience in Cloud cybersecurity. Excellent communication skills and strong analytical abilities are essential for effective collaboration.

Qualifications

  • Candidates must have a bachelor's degree in a relevant field.
  • Minimum 2 years of experience in Cloud cybersecurity required.
  • Strong analytical and problem-solving skills are necessary.

Responsibilities

  • Conduct security reviews and system hardening checks.
  • Provide vulnerability monitoring and recommend mitigation actions.
  • Compile monthly reports on task progress and outstanding issues.

Skills

Cloud cybersecurity
Security assessment
Vulnerability management
Strong analytical skills
Excellent communication

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity
CISSP, CISM, CRISC, or CISA certification

Tools

Azure Log Analytics
AWS CloudWatch
AWS Security Hub CSPM
Microsoft Defender for Cloud
Job description
Job Summary

We are seeking a team of IT Security Officers (ITSOs) who will serve as ITsecurity subject matter experts, providing comprehensive support for system managersand the Board's Cybersecurity team. The team will be responsible for ensuring the security of the IT infrastructure, compliance with security policies and standards, and overseeing cyber operations across all hosting environments (On premise, GDC, GCC,GCC+ and etc). The scope of responsibilities will be distributed among the teammembers to ensure comprehensive coverage and effective security operations.

Team Structure and Scope Distribution

The ITSO team will divide responsibilities across key security domains to ensure comprehensive coverage. The team will directly report to Board’s Cybersecurity Team, team members will focus on specialised areas including security monitoring, systemsecurity and compliance activities, and technical support, risk assessments, and governance functions. This distribution ensures specialised expertise whilst maintaining collaborative oversight across all security functions.

Key Responsibilities

System Security and Compliance: The team will conduct security reviews, system hardening checks and conduct risk assessment based on deviations to hardening requirements (e.g. CIS Benchmarks). The team will also create PUB hardening baselines using available benchmarks (e.g. CIS Benchmarks or those provided by the manufacturer). Responsibilities include create, review and maintain Standard Operation Procedures (SOPs), planning and scheduling annual reviews of security hardening documents, performing compliance reviews, and ensuring remediation of findings.

Technical Support and Governance

The role involves providing vulnerability monitoring and recommending and implementing mitigation actions to system Officers-in-Charge and infrastructure teams. The team will also provide security advice or proposals on security measures for new projects and functionalities and monitor governance compliance tools, such as Cloudscape. The team will also provide their risk-based assessments to prioritise rectification of alerts (e.g. Cloudscape). The Team is also expected to manage and update into the governance compliance tools with the relevant information to suppress the affected findings when approval is sought. The team will respond to auditors’ RFI on security monitoring.

Reporting and Training

Monthly reports to summarise the progress of tasks and to flag outstanding non-remediated issues/alerts across the key security domains will be compiled collaboratively by the team and presented to the Board's Cybersecurity team. The team will coordinate monthly IT security awareness training and briefings for users to enhance organisational security posture, with team members contributing their specialised expertise to deliver comprehensive training programmer.

Qualifications

All candidates must possess a bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field along with minimally an internationally recognised security certifications such as CISSP, CISM, CRISC, or CISA. Proven experience of at least 2 years in Cloud cybersecurity is required, including security assessment, vulnerability management within cloud and on prem environments, particularly GCC. Familiarity with security platforms such as Azure Log Analytics, AWS CloudWatch, AWS Security Hub CSPM, and Microsoft Defender for Cloud are preferred. Strong analytical and problem‑solving skills are necessary to resolve security related issues, along with excellent communication skills in both spoken and written English to effectively collaborate with team members, system Officers-in-Charge, infrastructure teams, and external vendors.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.