IT Security Officer (Vulnerability & Risk Management) (Ref 26589)

Jobline Resources Pte Ltd

Singapore

On-site

SGD 90,000 - 130,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobline Resources Pte Ltd is seeking a dedicated security operations professional to manage vulnerability programs and risk acceptance processes across on‑premises and AWS environments. The role emphasizes CVSS-based prioritization, reporting, and cross‑functional collaboration.

You will maintain risk registers, coordinate with SMEs, and provide leadership with actionable risk-based remediation guidance in a fast-paced setting.

Qualifications

  • 3–5+ years in IT security operations or risk management.
  • Hands-on with vulnerability scanners such as Tenable Nessus, Qualys or Rapid7.
  • Experience with AWS security services and shared responsibility model.
  • Solid understanding of on-prem infrastructure security.
  • Strong CVSS scoring knowledge and risk-based prioritization.
  • Experience developing and managing Risk Registers and Risk Acceptance docs.
  • Excellent stakeholder management and communication skills.

Responsibilities

  • Execute vulnerability scans across on‑premises and AWS; report findings to teams and leadership.
  • Maintain the Risk Register and draft risk acceptance forms as needed.
  • Coordinate remediation with SMEs and track SLA‑driven items.
  • Oversee security operations and verify updates to AV/EDR and IDS/IPS.
  • Provide risk-based recommendations to prioritize remediation efforts.

Skills

Vulnerability Management
Risk Management
Security Operations
Stakeholder Management
CVSS Scoring
Communication Skills

Education

Bachelor's degree in Information Security

Tools

Tenable Nessus
Qualys
Rapid7
AWS Security Services

Job description

Responsibilities
Vulnerability Management
  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and elevate overdue items per defined SLAs
Risk Register & Risk Acceptance
  • Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment
Security Operations Oversight
  • Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
  • Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
Impact & Risk Analysis
  • Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores
  • Contextualise CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritisation
  • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions
Reporting & Communication
  • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
  • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding
Requirements
  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)
  • 3–5+ years of experience in IT security operations, vulnerability management, or risk management
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally

Licence no: 12C6060

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Officer – Vulnerability & Risk Management
IT Security Officer – Vulnerability & Risk Management

SAGL Consulting • Singapore

Hybrid
SGD 80,000 - 140,000
IT Security Officer - Vulnerability & Risk Management
IT Security Officer - Vulnerability & Risk Management

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
Security Officer (IT Infra and Security Operations) (Ref 24964)
Security Officer (IT Infra and Security Operations) (Ref 24964)

Jobline Resources Pte Ltd • Singapore

On-site
SGD 60,000 - 90,000
IT Security Officer (ITSO)
IT Security Officer (ITSO)

SEDHA CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Lead - VM & App Security Engineer
Lead - VM & App Security Engineer

StarHub • Singapore

On-site
SGD 90,000 - 120,000
IT Security Officer
IT Security Officer

K2 PARTNERING SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 90,000 - 180,000
IT Security Officer
IT Security Officer

PCCW SOLUTIONS INSYS PTE. LTD. • Singapore

On-site
SGD 100,000 - 150,000
IT Security Officer (Cybersecurity Engineer) - #1598
IT Security Officer (Cybersecurity Engineer) - #1598

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 90,000 - 120,000
IT Security Officer
IT Security Officer

DBiz.ai • Singapore

On-site
SGD 90,000 - 120,000
IT Security Officer
IT Security Officer

K2 Partnering Solutions Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000