IT Security Officer (1 Oct 2026 - 31 Mar 2027)
Employment Type: 1 Oct 2026 - 31 Mar 2027 (Contract)
Working Days/Hours: Monday to Friday (9am - 6pm)
Location: Botanic Gardens
Eligibility: Singaporean ONLY
Job Summary
Manage cybersecurity vulnerability assessments, incident response, and security operations to protect enterprise IT infrastructure. Collaborate with teams and vendors to ensure compliance and continuous security improvements.
Responsibilities
- Manage vulnerability assessments across servers, endpoints, applications, on-premises and Azure environments using TenableOne, VMS, and Cloudscape tools to identify and prioritize security risks.
- Review vulnerability and patch compliance reports to prioritize risks and track remediation, exceptions, and risk acceptances for effective risk management.
- Follow up with infrastructure and application teams on outstanding vulnerabilities and escalate high-risk or overdue issues to ensure timely resolution.
- Analyze vulnerability trends and prepare detailed reports and evidence for management, audits, and compliance reviews to support informed decision-making.
- Ensure remediation activities comply with IM8 and internal security requirements to maintain organizational security standards.
- Support cybersecurity incident investigations by identifying, escalating, containing, recovering, and closing security incidents to minimize impact.
- Coordinate with the CISO, infrastructure/application teams, business stakeholders, and security vendors to facilitate effective incident response and resolution.
- Maintain incident records, track remediation actions, and support post-incident reviews to improve security processes.
- Support the operation and monitoring of DDoS protection and WAF services for internet-facing applications by reviewing security alerts, attack reports, and service performance.
- Coordinate WAF rule changes and work with vendors and internal teams to investigate security events and resolve service issues promptly.
- Coordinate cybersecurity and infrastructure activities across application, infrastructure, facilities management, and external vendors to ensure cohesive security operations.
- Maintain security risk, remediation, and compliance registers to track and manage security posture.
- Track action items from vulnerabilities, incidents, audits, and service reviews, escalating issues as necessary to ensure accountability.
- Consolidate and analyze security, vulnerability, incident, and compliance data to produce dashboards, management reports, and security metrics covering vulnerability remediation, patch compliance, incidents, and security services.
- Support audits, management reviews, and collection of compliance evidence to uphold regulatory and internal standards.
Required competencies and certifications
- Diploma or Degree in IT, Cybersecurity, Computer Science, Information Systems, or related field.
- 2–5 years of experience in cybersecurity, IT security operations, or vulnerability management.
- Experience with Tenable or similar vulnerability management tools.
Preferred competencies and qualifications
- Exposure to Azure security, incident response, DDoS/WAF, and enterprise security operations.
- Familiarity with IM8, NIST, ISO 27001, and CIS Controls.
- Good knowledge of Excel and PowerPoint for reporting and analysis.
- Strong coordination, communication, and stakeholder management skills.
- Good analytical and problem-solving abilities.
- Organized, detail-oriented, and able to manage multiple priorities.
- Ability to work independently and collaboratively.
- Azure / Microsoft Security Certifications.
- CompTIA Security+.
- CEH.
- ISC2 CC.
- CISSP / CISM.