Vulnerability & Risk Engineer — Hybrid Cloud Security

NTT Ltd.

Singapore

Hybrid

SGD 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NTT DATA is seeking an IT Security Officer to support client information security across on-premises and AWS environments. You will drive vulnerability management, maintain the Risk Register, and coordinate risk acceptance and remediation with stakeholders.

This role also oversees security operations, analyzes CVSS scores, and communicates risk to leadership. A 3–5+ year track record in security operations and relevant certifications are expected; hybrid working and a 1-year fixed-term contract

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent work experience)
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization
  • Experience developing and managing Risk Registers and Risk Acceptance documentation
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally
  • Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar
  • Experience with GRC tools (e.g., ServiceNow GRC, Archer)
  • Familiarity with frameworks such as NIST 800-53, NIST CSF, or ISO 27001
  • Experience working in a hybrid on-prem/cloud environment supporting external customers

Responsibilities

  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
  • Follow up with SMEs on outstanding vulnerability findings to ensure timely remediation or documented exceptions
  • Track remediation status and escape overdue items per defined SLAs
  • Own and maintain the organization’s Risk Register, ensuring it reflects current risk data
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
  • Coordinate with stakeholders to review, negotiate, and obtain formal approval on risk acceptances
  • Periodically review accepted risks for continued validity and reassessment
  • Monitor security signature updates across the environment
  • Review vendor security bulletins and vulnerability notifications for applicability
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
  • Perform impact analysis on identified vulnerabilities using CVSS scores
  • Contextualize CVSS base scores against asset criticality and controls
  • Provide risk-based recommendations to stakeholders for remediation prioritization
  • Prepare periodic status reports/dashboards on vulnerability management and risk status
  • Communicate effectively with SMEs, business stakeholders, and management across levels

Skills

Vulnerability management
Security operations
Risk management
CVSS scoring
Stakeholder management
Threat analysis

Education

Bachelor’s degree in Information Security, Computer Science, or related field
Security certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty

Tools

Tenable/Nessus
Qualys
Rapid7
AWS Security Services
ServiceNow GRC
Archer

Job description

NTT DATA is seeking an IT Security Officer to support client information security across on-premises and AWS environments. You will drive vulnerability management, maintain the Risk Register, and coordinate risk acceptance and remediation with stakeholders.

This role also oversees security operations, analyzes CVSS scores, and communicates risk to leadership. A 3–5+ year track record in security operations and relevant certifications are expected; hybrid working and a 1-year fixed-term contract

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Risk & Security Engineer (Hybrid)
Vulnerability Risk & Security Engineer (Hybrid)

NTT Ltd Group Services United Kingdom Limited • Singapore

Hybrid
SGD 90,000 - 130,000
Security Operations & Risk Lead — Hybrid AWS/on‑Prem
Security Operations & Risk Lead — Hybrid AWS/on‑Prem

NTT America, Inc. • Singapore

Remote
SGD 90,000 - 150,000
Security Risk & Vulnerability Engineer - Hybrid
Security Risk & Vulnerability Engineer - Hybrid

NTT Limited • Singapore

Hybrid
SGD 120,000 - 180,000
IT Security Officer - Vulnerability & Risk Management
IT Security Officer - Vulnerability & Risk Management

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
Vulnerability & Risk Security Lead - Hybrid Cloud
Vulnerability & Risk Security Lead - Hybrid Cloud

SAGL CONSULTING PTE. LTD. • Singapore

Hybrid
SGD 70,000 - 110,000
Vulnerability & Risk Lead - Cloud & On-Prem Security
Vulnerability & Risk Lead - Cloud & On-Prem Security

Jobline Resources Pte Ltd • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer – Vulnerability & Risk Management
IT Security Officer – Vulnerability & Risk Management

SAGL Consulting • Singapore

Hybrid
SGD 80,000 - 140,000
IT Security Officer
IT Security Officer

NTT America, Inc. • Singapore

Remote
SGD 90,000 - 150,000
Security Managed Services Engineer (L3)
Security Managed Services Engineer (L3)

NTT Limited • Singapore

Hybrid
SGD 120,000 - 180,000
Vulnerability & Risk Security Engineer
Vulnerability & Risk Security Engineer

Recruit Express Pte Ltd • Singapore

On-site
SGD 110,000 - 170,000