Point your AI agent at freehire and let it find you a job.

Get the CLI →

Poh Heng Jewellery (Private) Limited

IT Security and Compliance Specialist (1 year contract)

Posted Updated 1 view
Discussion

Roles and Responsibilities

We are looking for an IT Security and Compliance Specialist to support the organisation’s cybersecurity operations, IT governance, risk management and compliance activities. The role involves monitoring security alerts, coordinating responses to security incidents, supporting vulnerability remediation, maintaining IT security policies and controls, and assisting with cybersecurity audits and certification activities.

The successful candidate will work with the Head of IT, internal stakeholders, external service providers and auditors to identify risks, implement practical controls, maintain audit readiness and support timely remediation.

This role requires relevant technical security knowledge, strong documentation and coordination skills, and the ability to communicate security requirements clearly and practically to both technical and non-technical stakeholders.

In addition, the role requires candidate to be able to commit to operational shift schedules or standby hours (if needed) as required by system incident response protocols to resolve security incidents, critical vulnerabilities, audit activities or project requirements .

Job Description:-

1) Security Monitoring, Incident Response and Operations

  • Monitor and review security alerts from SIEM, EDR, email security, Microsoft 365/cloud security tools and other security platforms; perform initial triage, investigation, escalation and follow-up.

  • Support cybersecurity incident handling including evidence gathering, containment coordination, recovery, root-cause analysisand documentation of lessons learned and preventive actions.

  • Maintain incident and alert records, track recurring trends and provide timely security updates to the Head of IT.

2) IT Security Governance, Policies and Control Operations

  • Maintain and periodically review IT security policies, standards, procedures and supporting records to ensure they remain current and aligned with business and compliance requirements.

  • Execute and coordinate recurring control activities required by IT policies, such as user and privileged-access reviews, security log reviews, patch/compliance checks, backup and restore evidence reviews, security exception tracking and control attestations.

  • Maintain a security compliance calendar, control evidence repository and remediation tracker to ensure recurring obligatations are completed on time

3) Audit, Certification and Compliance

  • Support preparation for Cyber Trust Mark (CTM), ISO, ESG and other applicablecybersecurity, governance or certification audits and assessments.

  • Perform gap assessments, coordinate evidence collection, respond to auditor requests and work with control owners to close identified gaps, observations and non-conformities.

  • Track remediation actions to closure and prepare progress updates, risk summaries and management reporting for the Head of IT.

4) Vulnerability Management and VAPT

  • Coordinate Vulnerability Assessment and Penetration Testing (VAPT), including scoping, vendor coordination, review of findings, risk-based prioritization, remediation tracking and retesting.

  • Monitor vulnerability and patch status across servers, endpoints, applications, network devices and cloud services, and follow up with internal teams and vendors on overdue remediation.

  • Validate closure evidence and maintain an auditable record of vulnerability exceptions, accepted risks and compensating controls where applicable.

5) IT Security Projects and Security Reviews

  • Lead or support IT security projects such as SIEM, EDR, MFA, email security, vulnerability management, privileged access, data protection and security hardening initiatives.

  • Conduct security reviews for new systems, applications, cloud services and material technology changes; identify security requirements and follow up on implementation before go-live where applicable.

  • Coordinate project scope, timelines, vendors, testing, documentation, implementation, handover and postimplementation follow-up.

6) Cyber Risk and Third-Party Security Management

  • Maintain and periodically update the IT/cybersecurity risk register and support risk assessments for systems, projects, vendors and material changes.

  • Support cybersecurity due diligence for relevant third-party vendors and service providers, including security questionnaires, review of security evidence and follow-up on identified risks.

  • Escalate significant residual risks and security exceptions to the Head of IT with practical remediation or compensating control recommendations.

7) Security Awareness and Communications

  • Prepare IT security newsletters, advisories and awareness communications covering current threats, secure practices and internal security requirements.

  • Coordinate cybersecurity awareness activities such as phishing simulations, user briefings and security education for employees, including support for onboarding and periodic refresher activities.

  • Provide clear, practical security guidance to users and stakeholders and promote a security-conscious culture across the organization.

8) Cyber Resilience and Continuous Improvement

  • Support cyber incident response exercises, business continuity/disaster recovery activities and periodic testing of security-related recovery procedures.

  • Keep abreast of emerging cyber threats,vulnerabilities, regulatory developments and security best practices relevant to the organization and recommend proportionate improvements.

  • Maintain cybersecurity documentation, procedures, diagrams, registers and metrics, and identify opportunities to automate or streamline recurring security and compliance activities.

Experience and Qualification

  • A minimum of a diploma or degree, or equivalent professional qualification, in Information Technology, Cybersecurity, Computer Science, Information Systems or a related field.

  • Minimum of 3-5 years' professional experience in IT security, compliance or related security roles.Experience working in an SME or lean IT environment, where the role covers both technical security operations and compliance activities, is highly advantageous.

  • Cybersecurity monitoring and incident response, including alert triage, investigation, escalation and documentation.

  • Hands-on experience with security tools such as SIEM, EDR, email security and Microsoft 365 security tools.

  • Knowledge of vulnerability management, VAPT findings, patch management and risk-based remediation.

  • Ability to maintain IT security policies, procedures, control evidence, risk registers and remediation trackers.

  • Experience supporting IT/security audits, control assessments and remediation coordination.

  • Strong understanding of core security concepts such as IAM, MFA, endpoint security, network security, secure configuration, logging, monitoring, backup/recovery and data protection.

  • Good knowledge of Windows, networking and cloud/SaaS security fundamentals.

  • Strong documentation, reporting, analytical and effective communication and stakeholder management.

  • Ability to translate technical findings and requirements into clear business actions to both technical and non technical stakeholders

  • Strong stakeholder management, project coordination, vendor management, prioritisation and time-management skills for operational alerts, audit activities and project activities concurrently.

Good to have experiences:-

  • Familiarity with Singapore Cyber Trust Mark (CTM), ISO 27001/ISO-related management systems, NIST Cybersecurity Framework, Controls or similar security frameworks.

  • Knowledge of Singapore data protection and cybersecurity requirements relevant to business operations.

  • Relevant certifications such as CompTIA Security+, SSCP, CISA, ISO 27001 Internal/Lead Auditor or equivalent are advantageous

  • Experience with vulnerability scanning platforms, security configuration assessment, phishing simulation or security awareness platforms.

  • Familiarity with project management and ticketing tools such as Microsoft Project, Jira or similar platforms.

  • Familiarity with eCommerce, CRM, ERP, POS, inventory or other retail technology environments is advantageous.

  • Previous experience in the retail industry, especially retail jewellery, is advantageous.


Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available