Security Managed Services Engineer (L3)

NTT Ltd.

Singapore

Hybrid

SGD 90,000 - 130,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NTT DATA is seeking an IT Security Officer to support client information security across on-premises and AWS environments. You will drive vulnerability management, maintain the Risk Register, and coordinate risk acceptance and remediation with stakeholders.

This role also oversees security operations, analyzes CVSS scores, and communicates risk to leadership. A 3–5+ year track record in security operations and relevant certifications are expected; hybrid working and a 1-year fixed-term contract

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent work experience)
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally
  • Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar
  • Experience with GRC tools (e.g., ServiceNow GRC, Archer)
  • Familiarity with frameworks such as NIST 800-53, NIST CSF, or ISO 27001
  • Experience working in a hybrid on-prem/cloud environment supporting external customers

Responsibilities

  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with SMEs on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and escape overdue items per defined SLAs
  • Own and maintain the organization’s Risk Register, ensuring it reflects current risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with stakeholders to review, negotiate, and obtain formal approval on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment
  • Monitor security signature updates across the environment
  • Review vendor security bulletins and vulnerability notifications for applicability
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
  • Perform impact analysis on identified vulnerabilities using CVSS scores
  • Contextualize CVSS base scores against asset criticality and controls
  • Provide risk-based recommendations to stakeholders for remediation prioritization
  • Prepare periodic status reports/dashboards on vulnerability management and risk status
  • Communicate effectively with SMEs, business stakeholders, and management across levels

Skills

Vulnerability management
Security operations
Risk management
CVSS scoring
Stakeholder management
Threat analysis

Education

Bachelor’s degree in Information Security, Computer Science, or related field
Security certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty

Tools

Tenable/Nessus
Qualys
Rapid7
AWS Security Services
ServiceNow GRC
Archer

Job description

Make an impact with NTT DATA

Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Your day at NTT DATA

The IT Security Officer will support the customer’s information security program across a hybrid infrastructure consisting of on-premises systems and AWS cloud services. This role is responsible for driving the vulnerability management lifecycle, maintaining the organizational Risk Register, coordinating risk acceptance and remediation activities with stakeholders, and overseeing day-to-day security operations related to signature updates and vendor vulnerability notifications.

Key Responsibilities:
  • Vulnerability Management
    • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)

    • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership

    • Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions

    • Track remediation status and escape overdue items per defined SLAs

  • Risk Register & Risk Acceptance
    • Own and maintain the organization’s Risk Register, ensuring it reflects current, accurate risk data

    • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated

    • Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances

    • Periodically review accepted risks for continued validity and reassessment

  • Security Operations Oversight
    • Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment

    • Review vendor security bulletins and vulnerability notifications to determine applicability to the customer’s environment

    • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems

  • Impact & Risk Analysis
    • Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores

    • Contextualize CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritization

    • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions

  • Reporting & Communication
    • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review

    • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding

Knowledge and Attributes:
  • Ability to communicate and work across different cultures and social groups
  • Ability to plan activities and projects well in advance and takes into account possible changing circumstances.
  • Ability to maintain a positive outlook at work.
  • Ability to work well in a pressurized environment.
  • Ability to work hard and put in longer hours when it is necessary.
  • Ability to apply active listening techniques such as paraphrasing the message to confirm understanding, probing for further relevant information, and refraining from interrupting.
  • Ability to adapt to changing circumstances.
  • Ability to place clients at the forefront of all interactions, understanding their requirements, and creating a positive client experience throughout the total client journey.
Academic Qualifications and Certifications:
  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent work experience)

  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)

  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)

  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)

  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization

  • Experience developing and managing Risk Registers and Risk Acceptance documentation

  • Excellent stakeholder management and communication skills, with ability to work cross-functionally

  • Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar

  • Experience with GRC tools (e.g., ServiceNow GRC, Archer)

  • Familiarity with frameworks such as NIST 800-53, NIST CSF, or ISO 27001

  • Experience working in a hybrid on-prem/cloud environment supporting external customers

Required experience:
  • 3–5+ years of experience in IT security operations, vulnerability management, or risk management

  • Seasoned Managed Services experience handling complex Security Infrastructure.

  • Seasoned experience required in Engineering function within a medium to large ICT organization.

  • Seasoned working knowledge of ITIL processes.

  • Seasoned experience working with vendors and/or 3rd parties.

  • Strong analytical and problem-solving skills

  • Detail-oriented with strong documentation habits

  • Ability to influence and drive accountability without direct authority

  • Comfortable working with ambiguity and competing priorities

This is a 1-year fixed term contract. You should be willing to work at client site

Workplace type:

Hybrid Working

About NTT DATA

NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune

Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.

Equal Opportunity Employer

NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us.

Third parties fraudulently posing as NTT DATA recruiters

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Managed Services Engineer (L3)
Security Managed Services Engineer (L3)

NTT Ltd Group Services United Kingdom Limited • Singapore

Hybrid
SGD 90,000 - 130,000
Security Managed Services Engineer (L3)
Security Managed Services Engineer (L3)

NTT Limited • Singapore

Hybrid
SGD 120,000 - 180,000
IT Security Officer
IT Security Officer

NTT America, Inc. • Singapore

Remote
SGD 90,000 - 150,000
Cybersecurity Sales Specialist
Cybersecurity Sales Specialist

NTT DATA, Inc. • Singapore

On-site
SGD 90,474 - 116,324
Senior Cybersecurity Architect
Senior Cybersecurity Architect

NTT Limited • Singapore

On-site
SGD 150,000 - 230,000
Cybersecurity Sales Specialist
Cybersecurity Sales Specialist

NTT Limited • Singapore

On-site
SGD 120,000 - 180,000
Associate Customer Experience Technical Services Systems Integration Specialist
Associate Customer Experience Technical Services Systems Integration Specialist

NTT America, Inc. • Singapore

Remote
SGD 42,000 - 56,000
Field Tech Senior Associate
Field Tech Senior Associate

NTTD Ser Singapore Pte.Lt • Singapore

On-site
SGD 33,000 - 61,000
Cybersecurity Architect
Cybersecurity Architect

NTT America, Inc. • Singapore

Remote
SGD 120,000 - 180,000
Director, Cybersecurity Alliances ( Asia Pacific )
Director, Cybersecurity Alliances ( Asia Pacific )

NTT Ltd. • Singapore

On-site
SGD 250,000 - 360,000