IT Security Officer (Central / 5 days / Standby required)
About this job
Key Responsibilities
1.Vulnerability Management
- Coordinate vulnerability management activities across on-premises infrastructure, servers, endpoints, applications, and Azure cloud environments.
- Utilize security tools such as Vulnerability Management Systems (VMS), TenableOne, Cloudscape, and related platforms to identify, assess, and monitor security vulnerabilities.
- Conduct regular reviews of vulnerability assessment results and patch compliance reports to identify remediation priorities.
- Coordinate periodic status updates and remediation tracking exercises with infrastructure, application, and support teams.
- Monitor patching progress and ensure vulnerabilities are remediated within defined timelines and compliance requirements.
- Track and manage outstanding vulnerabilities, risk acceptance requests, and remediation exceptions.
- Analyse vulnerability data to identify trends, recurring issues, and areas requiring additional attention.
- Escalate overdue or high-risk vulnerabilities to relevant stakeholders and management.
- Support security audits, compliance assessments, and reporting activities by providing required vulnerability management evidence and documentation.
- Ensure remediation activities comply with IM8 requirements, internal policies, and cybersecurity standards.
2.Security Incident Response Support
- Support cybersecurity incident response activities in collaboration with the CISO, Infrastructure Team, and security service providers.
- Coordinate incident investigations and facilitate communications among relevant technical and business stakeholders.
- Assist in the identification, escalation, containment, recovery, and closure of cybersecurity incidents.
- Maintain accurate incident records, logs, and supporting documentation.
- Follow up on remediation activities arising from security incidents and ensure completion within agreed timelines.
- Participate in incident review sessions and support the implementation of lessons learned and process improvements.
- Monitor incident trends and recommend operational improvements to enhance security effectiveness.
- Ensure incident management processes are executed in accordance with established security procedures and governance requirements.
3.DDoS and Web Application Firewall (WAF) Operations
- Support the operation and administration of DDoS mitigation and Web Application Firewall (WAF) services protecting NParks' Internet-facing applications.
- Coordinate with service providers and internal stakeholders to ensure the effectiveness of deployed security controls.
- Review security alerts, attack reports, and service performance metrics to identify potential risks and improvement opportunities.
- Facilitate WAF policy reviews, rule updates, and change requests in accordance with operational requirements.
- Support investigations involving web application attacks, suspicious traffic, and DDoS-related events.
- Track service issues and follow up with vendors to ensure timely resolution.
- Assist in service reviews and operational assessments of DDoS and WAF solutions.
4.Security and Infra Operations Coordination
- Coordinate cybersecurity and infra operational activities across application teams, infrastructure teams, Onsite FM teams, GCC FM teams, and external security vendors.
- Maintain security risk, remediation, and compliance tracking registers.
- Follow up on action items arising from vulnerability assessments, incidents, audits, and service reviews.
- Support security governance activities through effective communication and collaboration with stakeholders.
- Escalate operational issues, delays, and security risks where required.
- Ensure cybersecurity and infra operational processes are executed consistently and effectively.
5.Reporting and Compliance Monitoring
- Collect, consolidate, and analyse vulnerability, incident, compliance, and operational security data.
- Prepare regular operational reports, dashboards, and management updates on cybersecurity posture and remediation progress.
- Monitor compliance against prescribed security requirements, policies, and standards.
- Produce metrics and reports on vulnerability remediation, incident management, patch compliance, and security service performance.
- Support management review meetings by providing timely and accurate cybersecurity status updates.
- Assist in audit preparation activities and coordinate the collection of supporting evidence and documentation.
Requirements
Qualifications
- Diploma or Degree in Information Technology, Cybersecurity, Computer Science, Information Systems, or a related field.
Experience
- Minimum 2–5 years of experience in IT security operations, cybersecurity operations, vulnerability management, or related IT security functions.
- Experience working with vulnerability management tools such as Tenable, or equivalent solutions.
- Exposure to Microsoft Azure security and cloud environments is advantageous.
- Experience coordinating cybersecurity incidents and remediation activities.
- Familiarity with DDoS protection and WAF technologies is preferred.
- Experience supporting compliance and governance requirements within enterprise or public-sector environments is advantageous.
Market insight
25% above medianExplore related jobs
Similar jobs
Desktop Support (Shift / Full Time / Woodlands / Healthcare)
System Engineer (L2 Support / Virtualization / Security)
Technical Project Manager / Javascript / In-House
Technical Project Manager - In-house / Front-End
Junior Service Engineer - Hands-on/ Training Provided/ Manufacturing
Service Technician / Sembawang / No Experience Welcome
Frequently asked questions
What salary can I expect?
The employer lists 5 000 – 7 000 $ for this role at ALPSOFT TECHNOLOGIES PTE. LTD. in Singapore. For comparison, the local market median is about 4 800 $ based on 75 102 similar offers.
How do I apply for this job?
Open the original source page and contact the employer there. Finder never charges job seekers.
Are these jobs up to date?
Yes. Finder regularly refreshes vacancies from public sources and removes closed offers.
Where can I see employment type and work format?
Key conditions are shown above the description. You can also open related listings for ALPSOFT TECHNOLOGIES PTE. LTD. and Singapore.