IT Security Officer (Vulnerability & Risk Management)

INFINITE COMPUTER SOLUTIONS PTE LTD

Singapore

On-site

SGD 90,000 - 140,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

INFINITE COMPUTER SOLUTIONS PTE LTD in Singapore is seeking a Security Operations professional to lead vulnerability management and risk governance across on-prem and cloud environments.

The role focuses on executing scans, generating reports, maintaining risk registers, and coordinating risk acceptances with stakeholders. You will monitor security controls, review vendor advisories, and deliver risk-based recommendations to leadership.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field
  • 3–5+ years of experience in IT security operations, vulnerability management, or risk management
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally

Responsibilities

  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with SMEs on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and elevate overdue items per defined SLAs
  • Own and maintain the organization's Risk Register, ensuring it reflects current risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with business and technical stakeholders to review and obtain formal approval on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment
  • Monitor and verify that security signature updates across the environment are applied consistently
  • Review vendor security bulletins and vulnerability notifications to determine applicability
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
  • Perform impact analysis on identified vulnerabilities using CVSS scores
  • Contextualize CVSS base scores against the actual environment to determine real-world risk
  • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions
  • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
  • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding

Skills

Vulnerability management
Stakeholder management
Communication skills
Risk assessment
Analytical thinking

Education

Bachelor's degree in Information Security/CS

Tools

Tenable Nessus
Qualys
Rapid7

Job description

Key Responsibilities

Vulnerability Management

  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2,S3, RDS, and other relevant services)
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and elevate overdue items per defined SLAs

Risk Register & Risk Acceptance

  • Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment

Security Operations Oversight

  • Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
  • Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems

Impact& Risk Analysis

  • Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System)scores
  • Contextualize CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritization
  • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions

Reporting& Communication

  • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
  • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding
Required Qualifications
  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)
  • 3–5+ years of experience in IT security operations, vulnerability management, or risk management
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally
Preferred Qualifications
  • Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar
  • Experience with GRC tools(e.g., ServiceNow GRC, Archer)
  • Familiarity with frameworks such as NIST 800-53, NIST CSF, or ISO 27001
  • Experience working in a hybrid on-prem/cloud environment supporting external customers
Soft Skills
  • Strong analytical and problem-solving skills
  • Detail-oriented with strong documentation habits
  • Ability to influence and drive accountability without direct authority
  • Comfortable working with ambiguity and competing priorities
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Engineer/Officer
IT Security Engineer/Officer

Recruit Express Pte Ltd • Singapore

On-site
SGD 110,000 - 170,000
IT Security Officer (Vulnerability & Risk Management) (Ref 26589)
IT Security Officer (Vulnerability & Risk Management) (Ref 26589)

Jobline Resources Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer – Vulnerability & Risk Management
IT Security Officer – Vulnerability & Risk Management

SAGL Consulting • Singapore

Hybrid
SGD 80,000 - 140,000
IT Security Officer - Vulnerability & Risk Management
IT Security Officer - Vulnerability & Risk Management

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
IT Security Officer
IT Security Officer

PCCW SOLUTIONS INSYS PTE. LTD. • Singapore

On-site
SGD 100,000 - 150,000
IT Security Officer (ITSO)
IT Security Officer (ITSO)

SEDHA CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
IT Security Officer
IT Security Officer

K2 PARTNERING SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 180,000
IT Security Officer
IT Security Officer

DBiz.ai • Singapore

On-site
SGD 90,000 - 120,000
IT Security Officer (Application Security & Cloud Computing)
IT Security Officer (Application Security & Cloud Computing)

CMC-APAC PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 180,000
Consultant, IT Security (ITSO) - #1679
Consultant, IT Security (ITSO) - #1679

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 70,000 - 110,000