Security Analyst

RAPSYS TECHNOLOGIES PTE. LTD.

Singapore

On-site

SGD 70,000 - 110,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RAPSYS TECHNOLOGIES PTE. LTD. in Singapore seeks a Security Analyst to own end-to-end vulnerability management across the organization. You will triage findings, classify risk, and drive remediation with engineering and DevOps teams.

This role requires 2+ years in information security, hands-on scanning with Tenable/Qualys/Rapid7, and strong communication with technical and business stakeholders. You will produce dashboards, support audits, and advance threat intelligence efforts.

Qualifications

  • 2+ years of information security or vulnerability management experience.
  • Hands-on experience with vulnerability scanning platforms (Tenable, Qualys, Rapid7, Wiz).
  • Solid understanding of CVSS scoring and risk-based prioritization.
  • Experience communicating findings to technical teams and business stakeholders.
  • Familiarity with NIST CSF, ISO 27001, SOC 2.
  • Familiarity with GovTech IM8 policies and risk-based assessment methodology.
  • Strong organizational skills to manage multiple workstreams and deadlines.

Responsibilities

  • Own end-to-end vulnerability management lifecycle from intake to closure.
  • Classify vulnerabilities by severity and business impact using CVSS/EPSS.
  • Plan and manage quarterly vulnerability assessments.
  • Manage yearly penetration testing: scoping, vendor coordination, remediation tracking.
  • Track remediation across teams and ensure documentation and sign-off.
  • Coordinate with engineering/DevOps/infrastructure for timely resolutions.
  • Maintain risk acceptance records with approvals.
  • Track remediation SLAs and escalate overdue/high-risk items.
  • Produce status reports and dashboards for stakeholders.
  • Aggregate data from multiple scanners into unified risk view.
  • Develop metrics and KPIs for leadership visibility.
  • Present findings and recommendations in reports and briefings.
  • Act as liaison between security and remediation owners.
  • Continuously improve vulnerability management workflows and tooling.
  • Support audit/compliance with evidence of tracking and risk treatment.
  • Contribute to threat intelligence and stay current on CVEs.

Skills

Vulnerability management
Security incident remediation
Risk-based prioritization
Stakeholder communication
Governance & compliance
Threat & risk reporting

Tools

Tenable
Qualys
Rapid7
Wiz
Jira
ServiceNow

Job description

Key Responsibilities
  • Own and manage the end-to-end Vulnerability Management process, including intake, triage, and lifecycle tracking of security findings across the organization's systems and assets.
  • Classify vulnerabilities by severity, exploitability, and business impact using frameworks such as CVSS, EPSS, and internal risk criteria.
  • Plan, coordinate, and manage Quarterly Vulnerability Assessments — scoping targets, engaging scanning tools, reviewing outputs, and driving findings through to resolution.
  • Manage the Yearly Penetration Testing cycle, including scoping, vendor coordination, findings review, and tracking remediation commitments through to closure.
  • Track key remediation implementations end-to-end, maintaining visibility from initial detection through to verified closure — for example, overseeing the transition of WAF rules from detection mode to prevention mode, ensuring each step is documented, tested, and signed off.
  • Coordinate with remediation teams (engineering, DevOps, infrastructure) to ensure timely resolution of findings, providing clear context and prioritization guidance.
  • Maintain and update risk acceptance records, ensuring appropriate approvals are obtained, documented, and reviewed on schedule.
  • Track and report on remediation SLAs, escalating overdue or high-risk items to the appropriate stakeholders.
  • Produce regular status reports and dashboards that communicate the project's overall security posture to technical and non-technical audiences.
  • Aggregate vulnerability data from multiple scanning tools and sources into a coherent, unified view of security risk.
  • Develop and maintain metrics and KPIs that enable leadership visibility into ongoing security exposure and program effectiveness.
  • Present findings, trends, and recommendations in written reports, executive briefings, and team meetings.
  • Act as a liaison between the security team and remediation owners, facilitating communication and removing blockers to resolution.
  • Continuously improve vulnerability management workflows, tooling, and documentation.
  • Support audit and compliance activities by providing evidence of vulnerability tracking and risk treatment processes.
  • Contribute to threat intelligence efforts and stay current on emerging CVEs and attack trends relevant to the organization.
Qualifications Required
  • 2+ years of experience in an information security, vulnerability management, or related role.
  • Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7, Wiz, or similar).
  • Solid understanding of CVSS scoring, vulnerability classification, and risk-based prioritization.
  • Experience communicating security findings and risk to both technical teams and business stakeholders.
  • Familiarity with common compliance and risk frameworks (e.g., NIST CSF, ISO 27001, SOC 2).
  • Familiarity with GovTech's IM8 (Instruction Manual 8) policies and its associated risk-based assessment methodology, including the application of controls, classification of government ICT systems, and conducting or supporting IM8-aligned security reviews.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines simultaneously.
Preferred
  • Relevant certifications such as CompTIA Security+, CEH, GWAPT, or equivalent.
  • Experience with ticketing and workflow tools (e.g., Jira, ServiceNow) for tracking remediation.
  • Scripting or automation skills (Python, Bash) to support data aggregation and reporting workflows.
  • Background in cloud security environments (AWS, Azure, GCP).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Rapsys Technologies Pte Ltd. • Singapore

On-site
SGD 60,000 - 100,000
Security Analyst
Security Analyst

Tap Growth ai • Singapore

On-site
SGD 60,000 - 90,000
Security Analyst
Security Analyst

RAPSYS TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 70,000 - 90,000
Senior Vulnerability Management Analyst
Senior Vulnerability Management Analyst

Income Insurance Limited • Singapore

On-site
SGD 120,000 - 180,000
Security Managed Services Associate Manager
Security Managed Services Associate Manager

Accenture • Singapore

On-site
SGD 90,000 - 130,000
Vulnerability Operations Engineer
Vulnerability Operations Engineer

Ensign InfoSecurity • Singapore

On-site
SGD 90,000 - 130,000
System Engineer
System Engineer

SEDHA CONSULTING PTE. LTD. • Singapore

On-site
SGD 80,000 - 110,000
Information Security
Information Security

Helius Technologies Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Security Managed Services Lead (VAPT)
Security Managed Services Lead (VAPT)

Accenture Southeast Asia • Singapore

On-site
SGD 140,000 - 180,000
IT Security Engineer
IT Security Engineer

KRISE MANNPOWER PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000