Security Analyst
About this job
Key Responsibilities
Vulnerability Management
• Own and manage the end-to-end Vulnerability Management process, including intake, triage, and lifecycle tracking of security findings across the organization's systems and assets.
• Classify vulnerabilities by severity, exploitability, and business impact using frameworks such as CVSS, EPSS, and internal risk criteria.
• Plan, coordinate, and manage Quarterly Vulnerability Assessments — scoping targets, engaging scanning tools, reviewing outputs, and driving findings through to resolution.
• Manage the Yearly Penetration Testing cycle, including scoping, vendor coordination, findings review, and tracking remediation commitments through to closure.
• Track key remediation implementations end-to-end, maintaining visibility from initial detection through to verified closure — for example, overseeing the transition of WAF rules from detection mode to prevention mode, ensuring each step is documented, tested, and signed off.
• Coordinate with remediation teams (engineering, DevOps, infrastructure) to ensure timely resolution of findings, providing clear context and prioritization guidance.
• Maintain and update risk acceptance records, ensuring appropriate approvals are obtained, documented, and reviewed on schedule.
• Track and report on remediation SLAs, escalating overdue or high-risk items to the appropriate stakeholders.
• Produce regular status reports and dashboards that communicate the project's overall security posture to technical and non-technical audiences.
Security Visibility & Reporting
• Aggregate vulnerability data from multiple scanning tools and sources into a coherent, unified view of security risk.
• Develop and maintain metrics and KPIs that enable leadership visibility into ongoing security exposure and program effectiveness.
• Present findings, trends, and recommendations in written reports, executive briefings, and team meetings.
Collaboration & Process Improvement
• Act as a liaison between the security team and remediation owners, facilitating communication and removing blockers to resolution.
• Continuously improve vulnerability management workflows, tooling, and documentation.
• Support audit and compliance activities by providing evidence of vulnerability tracking and risk treatment processes.
• Contribute to threat intelligence efforts and stay current on emerging CVEs and attack trends relevant to the organization.
Qualifications Required
• 2+ years of experience in an information security, vulnerability management, or related role.
• Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7, Wiz, or similar).
• Solid understanding of CVSS scoring, vulnerability classification, and risk-based prioritization.
• Experience communicating security findings and risk to both technical teams and business stakeholders.
• Familiarity with common compliance and risk frameworks (e.g., NIST CSF, ISO 27001, SOC 2).
• Familiarity with GovTech's IM8 (Instruction Manual 8) policies and its associated risk-based assessment methodology, including the application of controls, classification of government ICT systems, and conducting or supporting IM8-aligned security reviews.
• Strong organizational skills with the ability to manage multiple workstreams and deadlines simultaneously.
Preferred
• Relevant certifications such as CompTIA Security+, CEH, GWAPT, or equivalent.
• Experience with ticketing and workflow tools (e.g., Jira, ServiceNow) for tracking remediation.
• Scripting or automation skills (Python, Bash) to support data aggregation and reporting workflows.
• Background in cloud security environments (AWS, Azure, GCP).
Market insight
19% above medianExplore related jobs
Similar jobs
See all similar jobsSecurity Analyst
Intern, Admin & Research Support — Part-Time or Full-Time
Admin & Operations Intern (Marketing / Online Work Support)
Creative Design Enginneer
Football Coaching Internship (Trial Development Program-no experience needed)
Human Resource Executive
Frequently asked questions
What salary can I expect?
The employer lists 6 000 – 8 500 $ for this role at OPENSOURCE TECHNOLOGIES PTE. LTD. in Singapore. For comparison, the local market median is about 6 085 $ based on 26 065 similar offers.
How do I apply for this job?
Open the original source page and contact the employer there. Finder never charges job seekers.
Are these jobs up to date?
Yes. Finder regularly refreshes vacancies from public sources and removes closed offers.
Where can I see employment type and work format?
Key conditions are shown above the description. You can also open related listings for OPENSOURCE TECHNOLOGIES PTE. LTD. and Singapore.



