Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
NTT Singapore Pte. Ltd. is seeking a cybersecurity professional to support its Security Exposure and Third-Party Cyber Assurance initiatives.
The role focuses on hands-on operations across SEM and TPCA, monitoring attack surfaces for the organization and its portfolio. You will validate risks, drive remediation, and ensure continual improvement of security posture. The ideal candidate has 3–5 years of practical experience, strong scripting ability, and familiarity with cloud exposures and vendor
Possess a degree in Computer Science/Information Technology or related field.
3 to 5 years of hands-on experiencein cybersecurity operations, attack surface/exposure management, third-partycyber risk assessment, or data lake platforms.
Strong practical experience inrunning third-party/vendor security assessments and questionnaires (VDD/ODD,SIG) and control frameworks (NIST, ISO 27001, CIS Controls).
Hands-on experience with ASM/EASM,cyber exposure, or digital risk/dark-web monitoring platforms, and Cyber ThreatIntelligence (CTI).
Advanced scripting knowledge (e.g.Python, PowerShell, or Bash) to automate tasks and build reporting dashboardson data lake platforms.
Solid understanding of TCP/IP, DNS,HTTP/S, common cloud exposures (AWS, Azure, GCP), and how third-/fourth-partyrisk propagates.
Strong analytical, documentation,and communication skills, with discretion to handle sensitive findings.
Good communication skill, with the ability to document processes clearly and liaise with technical and business stakeholders.
The successful candidate is expected to support CSAD's new Security Exposure and Third-Party Cyber Assurance Centre of Excellence during its build phase.
The role provides the hands‑on technical and operational backbone across two tracks - Security ExposureManagement (SEM), an outside‑in, continuous view of the organization and its portfolio companies' internet‑facing attack surface, and Third-Party Cyber Assurance (TPCA), end‑to‑end due diligence and continuous assurance across third parties and the supply chain.
Responsible to operate the always‑on monitoring platforms, run third‑party assurance, validate clear‑and‑present-danger threats, and drive remediation – narrowing the window between exposure and exploitation across organization, its portfolio companies, and third parties.