Specialist (Cybersecurity)

NTUC First Campus

Singapore

On-site

SGD 90,000 - 130,000

Full time

5 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NTUC First Campus is seeking an experienced cybersecurity professional in Singapore to lead risk assessments, manage cybersecurity controls, and coordinate remediation with cross-functional teams. The role involves vulnerability management, threat research, and ensuring compliance with ISO 27001, NIST, and OWASP standards.

You will collaborate with Infrastructure, End User Support, and external vendors to implement security controls, conduct regular security testing, and train staff on phishing

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity or related field.
  • CISSP, CISM, or CISA preferred.
  • Minimum 3 years in cybersecurity governance, risk or compliance.

Responsibilities

  • Perform security risk assessments and advise on risk treatment plans.
  • Maintain cybersecurity risk registers and track remediation actions.
  • Review security testing reports and coordinate remediation with application teams.
  • Conduct vulnerability scans, pen tests, and risk assessments across hardware, software, and cloud.
  • Research emerging threats and update defensive protocols.
  • Collaborate with Infrastructure and End User Support to address risks in infrastructure and endpoints.
  • Guide third-party risk management and vendor due-diligence processes.
  • Design and lead employee training on phishing and social engineering risks.
  • Lead security policy development and system hardening standards.
  • Administer cybersecurity operations and monitor alerts from Managed Services.
  • Support internal and external audits (ISO 27001, NIST, OWASP).
  • Investigate security incidents and coordinate containment and remediation.

Skills

Communication skills
Analytical thinking
Problem-solving
Driven and quick learner

Education

Bachelor's degree in CS/IT/Cybersecurity
CISSP/CISM/CISA preferred

Tools

Firewalls
IDS/IPS
PAM
Vulnerability scanning tools
EDR
WAF

Job description

  • Perform security risk assessments, formulate and advise on a risk treatment plan, assist the business in performing business impact analysis,
  • Maintain cybersecurity risk registers, track remediation actions, and oversee security control testing.
  • Review security testing reports (e.g. vulnerability assessment, penetration testing and secure code review) and work with application teams for remediation.
  • Conduct regular vulnerability scans, penetration testing, and risk assessments to identify flaws across hardware, software, and cloud environments.
  • Research emerging cyber threat vectors, vulnerabilities (CVEs), and attacker methodologies to update defensive protocols proactively.
  • Work closely with Infrastructure and End User Support teams to identify and address any risks and gaps in the infrastructure, endpoints, and application systems
  • Collaborate with third-party vendors and contractors to ensure the security of outsourced systems and services meets the industrial best practice to configure, deploy, and maintain critical security infrastructure, including firewalls, antivirus software, data loss prevention (DLP) tools, and regular vulnerability scans.
  • Support vendor due-diligence process and help to guide overall third-party risk management efforts.
  • Design and lead employee training programs to mitigate human-centric risks like phishing, social engineering, and poor password hygiene (e.g. newsletters, trainings, phishing campaigns)
  • Lead the implementation of security protocols, establish robust system hardening standards across enterprise assets, conduct regular risk assessments on hardening control applied.
  • Policy & Framework Development: Design, update, and maintain enterprise cybersecurity policies, standards, and control frameworks aligned with business goals
  • Support and administer cybersecurity operations using enterprise security solutions (e.g. onboarding of privileged accounts to PAM, implementing WAF for website protection, and reviewing firewall rules, Tenable, Web defacement tools, report phishing tool management, etc.)
  • Support both internal audit and external audits (e.g. ISO 27001, NIST, OWASP)
  • Primary Point of Contact, and First Responder (monitoring and responding to alerts from Managed Services)
  • Perform log analysis, investigate and respond to security incidents, including suspicious activities, phishing attempts, malware infections and data breaches.
  • Collaborate with various teams to investigate, contain and remediate security incidents.
Key Responsibilities
  • Perform security risk assessments, formulate and advise on a risk treatment plan, assist the business in performing business impact analysis,
  • Maintain cybersecurity risk registers, track remediation actions, and oversee security control testing.
  • Review security testing reports (e.g. vulnerability assessment, penetration testing and secure code review) and work with application teams for remediation.
  • Conduct regular vulnerability scans, penetration testing, and risk assessments to identify flaws across hardware, software, and cloud environments.
  • Research emerging cyber threat vectors, vulnerabilities (CVEs), and attacker methodologies to update defensive protocols proactively.
  • Work closely with Infrastructure and End User Support teams to identify and address any risks and gaps in the infrastructure, endpoints, and application systems
  • Collaborate with third-party vendors and contractors to ensure the security of outsourced systems and services meets the industrial best practice to configure, deploy, and maintain critical security infrastructure, including firewalls, antivirus software, data loss prevention (DLP) tools, and regular vulnerability scans.
  • Support vendor due-diligence process and help to guide overall third-party risk management efforts.
  • Design and lead employee training programs to mitigate human-centric risks like phishing, social engineering, and poor password hygiene (e.g. newsletters, trainings, phishing campaigns)
  • Lead the implementation of security protocols, establish robust system hardening standards across enterprise assets, conduct regular risk assessments on hardening control applied.
  • Policy & Framework Development: Design, update, and maintain enterprise cybersecurity policies, standards, and control frameworks aligned with business goals
  • Support and administer cybersecurity operations using enterprise security solutions (e.g. onboarding of privileged accounts to PAM, implementing WAF for website protection, and reviewing firewall rules, Tenable, Web defacement tools, report phishing tool management, etc.)
  • Support both internal audit and external audits (e.g. ISO 27001, NIST, OWASP)
  • Primary Point of Contact, and First Responder (monitoring and responding to alerts from Managed Services)
  • Perform log analysis, investigate and respond to security incidents, including suspicious activities, phishing attempts, malware infections and data breaches.
  • Collaborate with various teams to investigate, contain and remediate security incidents.
Education
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity or a related field
  • Relevant professional certifications such as CISSP, CISM, or CISA are preferred.
Experience
  • Minimum of 3 years of experience in cybersecurity
  • Experience in cybersecurity governance, technology risk, or compliance assurance
  • Experience with security technologies such as firewalls, intrusion detection/prevention systems, and data encryption
  • Has knowledge in security technologies such as Antivirus/Endpoint Detection and Response (EDR), Privilege Access Management (PAM), Vulnerability Scanning tools, Phishing reporting tools, Web Defacement monitoring tools and Web Application Firewall (WAF)
  • Familiarity with security assessment tools and techniques, including vulnerability scanning and penetration testing.
  • Experience in vendor and project management
Skills And Attributes
  • Excellent communication skills and the ability to explain complex technical concepts to non-technical stakeholders.
  • Deep understanding of network infrastructure, TCP/IP protocols, routers, switches, and secure architecture principles.
  • Strong analytical and problem-solving skills
  • Highly driven and willing to learn
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Singapore

On-site
SGD 70,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

Alliance Healthcare Group Limited • Singapore

On-site
SGD 60,000 - 100,000
Security Manager
Security Manager

ensign infosecurity (cybersecurity) pte. ltd. • Singapore

On-site
SGD 120,000 - 170,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
Cybersecurity Engineer * (AMK)
Cybersecurity Engineer * (AMK)

MAESTRO HUMAN RESOURCE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
Senior Security Specialist
Senior Security Specialist

aramco • Singapore

On-site
SGD 120,000 - 190,000
Assoc. Spclst , Cybersecurity Engineering
Assoc. Spclst , Cybersecurity Engineering

MSD INTERNATIONAL GMBH (Singapore Branch) • Singapore

On-site
SGD 70,000 - 90,000
Executive, Network & Security
Executive, Network & Security

Y3 Technologies • Singapore

On-site
SGD 90,000 - 130,000
Security Analyst
Security Analyst

R SYSTEMS CONSULTING SERVICES LIMITED • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Specialist
Cybersecurity Specialist

FLINTEX CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000