IT Security Officer - Vulnerability & Risk Management

SAGL CONSULTING PTE. LTD.

Singapore

Hybrid

SGD 70,000 - 110,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

SAGL CONSULTING PTE. LTD. is seeking an IT Security Officer focused on Vulnerability Management and IT Risk Management to support a hybrid on-premises and AWS environment.

You will own the vulnerability lifecycle, maintain the IT Risk Register, drive remediation and risk acceptance, and provide risk-based recommendations to technical and business stakeholders. Responsibilities include managing scans across on-prem and AWS, prioritizing remediation, coordinating with SMEs, and producing risk

Qualifications

  • 3–5+ years of experience in Vulnerability Management, IT Security or Risk Management.
  • Hands-on experience with Tenable/Nessus, Qualys, Rapid7 or similar scanning tools.
  • Strong understanding of CVSS and risk-based prioritization.
  • Experience managing Risk Registers and Risk Acceptance processes.
  • Proven ability to track remediation with SMEs and coordinate with stakeholders.
  • Good understanding of on-premises security plus AWS security model.

Responsibilities

  • Manage end-to-end vulnerability management lifecycle across on-premises and AWS.
  • Run vulnerability scans using Tenable/Nessus, Qualys or Rapid7.
  • Review findings, assess impact and prioritize remediation based on CVSS and context.
  • Track remediation with infrastructure and application SMEs; escalate overdue items.
  • Maintain IT Risk Register; ensure risks, owners, treatments and status are current.
  • Coordinate Risk Acceptance for unreparable vulnerabilities within timeframes.
  • Work with stakeholders to obtain risk acceptance approvals and reviews.
  • Review vendor security advisories for applicability and impact.
  • Monitor security-update compliance for AV/EDR, IDS/IPS controls.
  • Prepare vulnerability and risk dashboards for management.

Skills

Vulnerability management
IT security
Risk management
Risk-based prioritization
Stakeholder management

Education

Certifications in security (e.g. Security+, CySA+, CISSP, CRISC)

Tools

Tenable/Nessus
Qualys
Rapid7
AWS Security Hub
GuardDuty
Inspector
AWS security services

Job description

Role Overview

We are looking for an IT Security Officer specializing in Vulnerability Management and IT Risk Management to support a hybrid on-premises and AWS environment.The role will own the vulnerability management lifecycle, maintain the IT Risk Register, drive remediation and risk acceptance activities, and provide risk-based recommendations to technical and business stakeholders.

Key Responsibilities
  • Manage the end-to-end vulnerability management lifecycle across on-premises and AWS environments.
  • Run and manage vulnerability scans using tools such as Tenable/Nessus, Qualys or Rapid7 .
  • Review vulnerability findings, assess their impact and prioritize remediation based on CVSS and business/technical context .
  • Track remediation activities with infrastructure and application SMEs and escal overdue vulnerabilities.
  • Maintain the IT Risk Register and ensure risks, owners, treatment plans and status are current.
  • Prepare and coordinate Risk Acceptance for vulnerabilities or risks that cannot be remediated within the required timeframe.
  • Work with technical and business stakeholders to obtain risk acceptance approvals and periodically review accepted risks.
  • Review vendor security advisories and determine their applicability and potential impact to the environment.
  • Monitor security-update compliance for AV/EDR, IDS/IPS and similar security controls .
  • Prepare vulnerability and risk management dashboards/status reports for management.
  • Work across Security, Infrastructure, Cloud and Application teams to drive remediation and risk reduction.
Required Skills
  • 3-5+ years of experience in Vulnerability Management, IT Security or Risk Management.
  • Hands-on experience with Tenable/Nessus, Qualys, Rapid7 or equivalent vulnerability scanning tools .
  • Strong understanding of CVSS and risk-based vulnerability prioritization .
  • Practical experience managing Risk Registers and Risk Acceptance processes .
  • Strong experience in vulnerability remediation tracking and coordination with technical SMEs.
  • Good understanding of on-premises infrastructure security covering servers, network devices and endpoints.
  • Working knowledge of AWS security and the shared responsibility model , particularly EC2, S3, RDS, IAM and services such as Security Hub, GuardDuty and Inspector.
  • Strong stakeholder management and communication skills.
Preferred
  • Experience with GRC tools such as ServiceNow GRC or RSA Archer.
  • Knowledge of NIST CSF, NIST 800-53 or ISO 27001 .
  • Relevant certifications such as Security+, CySA+, CISSP, CRISC or AWS Security Specialty .
  • Experience supporting security/risk management in a hybrid cloud environment or managed-services/customer environment.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability & Risk Security Lead - Hybrid Cloud
Vulnerability & Risk Security Lead - Hybrid Cloud

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
IT Security Officer
IT Security Officer

PCCW SOLUTIONS INSYS PTE. LTD. • Singapore

On-site
SGD 100,000 - 150,000
IT Security Consultant
IT Security Consultant

K2 PARTNERING SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Lead - VM & App Security Engineer
Lead - VM & App Security Engineer

StarHub • Singapore

On-site
SGD 90,000 - 120,000
IT Security Consultant
IT Security Consultant

K2 Partnering Solutions Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer
IT Security Officer

K2 PARTNERING SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 180,000
Cyber and IT Security Advisory, Specialist / Principal Specialist
Cyber and IT Security Advisory, Specialist / Principal Specialist

CIMB Bank Berhad • Singapore

On-site
SGD 180,000 - 250,000
Vulnerability Management Operations Analyst
Vulnerability Management Operations Analyst

U3 INFOTECH PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Information Technology Security Engineer
Information Technology Security Engineer

Newtone consulting • Singapore

On-site
SGD 60,000 - 90,000
Senior Information Technology Security Officer
Senior Information Technology Security Officer

Total eBiz Solutions • Singapore

On-site
SGD 90,000 - 150,000