Security Risk & Vulnerability Engineer - Hybrid

NTT Limited

Singapore

Hybrid

SGD 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NTT DATA in Singapore is hiring an IT Security Officer to support the customer’s information security program across on‑premises systems and AWS cloud services. You will drive vulnerability management, maintain the risk register, and coordinate risk acceptance with stakeholders.

Oversee security operations, review vendor bulletins, perform CVSS‑based risk analysis, and prepare leadership dashboards. The role requires 3–5+ years in IT security, strong stakeholder management, and experience with

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally

Responsibilities

  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with SMEs on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and escalation overdue items per defined SLAs
  • Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment
  • Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
  • Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
  • Perform impact analysis on identified vulnerabilities using CVSS scores
  • Contextualize CVSS base scores against the actual environment to determine real-world risk and prioritization
  • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions
  • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
  • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding

Skills

Vulnerability management
Stakeholder management
Analytical thinking
Documentation
Communication
Adaptability

Education

Bachelor's degree in Information Security, Computer Science, or related field

Tools

Tenable/Nessus
Qualys
Rapid7
AWS Security Services
ServiceNow GRC
Archer

Job description

NTT DATA in Singapore is hiring an IT Security Officer to support the customer’s information security program across on‑premises systems and AWS cloud services. You will drive vulnerability management, maintain the risk register, and coordinate risk acceptance with stakeholders.

Oversee security operations, review vendor bulletins, perform CVSS‑based risk analysis, and prepare leadership dashboards. The role requires 3–5+ years in IT security, strong stakeholder management, and experience with

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Risk & Security Engineer (Hybrid)
Vulnerability Risk & Security Engineer (Hybrid)

NTT Ltd Group Services United Kingdom Limited • Singapore

Hybrid
SGD 90,000 - 130,000
Vulnerability & Risk Engineer — Hybrid Cloud Security
Vulnerability & Risk Engineer — Hybrid Cloud Security

NTT Ltd. • Singapore

Hybrid
SGD 90,000 - 130,000
Security Operations & Risk Lead — Hybrid AWS/on‑Prem
Security Operations & Risk Lead — Hybrid AWS/on‑Prem

NTT America, Inc. • Singapore

Remote
SGD 90,000 - 150,000
Vulnerability & Risk Management Lead - IT Security
Vulnerability & Risk Management Lead - IT Security

SAGL Consulting • Singapore

Hybrid
SGD 80,000 - 140,000
Vulnerability & Risk Security Lead - Hybrid Cloud
Vulnerability & Risk Security Lead - Hybrid Cloud

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
IT Security Officer - Vulnerability & Risk Management
IT Security Officer - Vulnerability & Risk Management

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
Vulnerability & Risk Lead - Cloud & On-Prem Security
Vulnerability & Risk Lead - Cloud & On-Prem Security

Jobline Resources Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer – Vulnerability & Risk Management
IT Security Officer – Vulnerability & Risk Management

SAGL Consulting • Singapore

Hybrid
SGD 80,000 - 140,000
Vulnerability & Risk Security Engineer
Vulnerability & Risk Security Engineer

Recruit Express Pte Ltd • Singapore

On-site
SGD 110,000 - 170,000
Vulnerability & Risk Management Lead
Vulnerability & Risk Management Lead

infinite Computer Solution • Singapore

On-site
SGD 90,000 - 130,000