Point your AI agent at freehire and let it find you a job.

Get the CLI →

JOBLINE RESOURCES PTE. LTD.

New

IT Security Officer (Vulnerability & Risk Management) (Ref 26589)

Posted 3 views
Discussion

Responsibilities

Vulnerability Management

• Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)

• Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership

• Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions

• Track remediation status and escalate overdue items per defined SLAs

Risk Register & Risk Acceptance

• Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data

• Draft Risk Acceptance forms for identified risks that cannot be immediately remediated

• Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances

• Periodically review accepted risks for continued validity and reassessment

Security Operations Oversight

• Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment

• Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment

• Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems

Impact & Risk Analysis

• Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores

• Contextualise CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritisation

• Provide risk-based recommendations to stakeholders to support remediation prioritization decisions

Reporting & Communication

• Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review

• Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding

Requirements

• Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)

• 3–5+ years of experience in IT security operations, vulnerability management, or risk management

• Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)

• Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)

• Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)

• Strong understanding of CVSS scoring methodology and practical risk-based prioritization

• Experience developing and managing Risk Registers and Risk Acceptance documentation

• Excellent stakeholder management and communication skills, with ability to work cross-functionally



Licence no: 12C6060

Skills

Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available