The Information Technology Security Officer(ITSO) is responsible for supporting the organization's cybersecuritygovernance, risk management, incident response, and security operationsactivities. The role ensures that IT systems, applications, and infrastructureare protected in accordance with organizational security policies, regulatoryrequirements, and industry best practices.
Key Responsibilities
Security Governance & Compliance
Develop, maintain, and review information security policies, standards, procedures, and implementation roadmaps.
Support the establishment and continuous improvement of cybersecurity governance frameworks and security management practices.
Conduct security risk assessments and recommend mitigation measures to address identified risks.
Ensure compliance with applicable cybersecurity policies, standards, and regulatory requirements.
Monitor security controls and provide recommendations to enhance the organization's security posture.
Security Operations & IncidentManagement
Support the monitoring, detection, investigation, and response of cybersecurity incidents.
Coordinate with internal stakeholders and external service providers to manage and resolve security incidents.
Participate in cybersecurity exercises, simulations, and readiness assessments.
Investigate security events and perform root cause analysis to identify corrective and preventive actions.
Review security alerts, reports, and audit findings, ensuring timely follow-up and remediation.
Threat & Vulnerability Management
Monitor emerging cyber threats, vulnerabilities, and security trends.
Assess the impact of identified threats on the organization's environment and recommend mitigation strategies.
Support vulnerability management activities, including assessment, tracking, and remediation verification.
Evaluate security technologies and solutions to improve operational effectiveness and risk management.
Security Monitoring & AssetManagement
Ensure security monitoring coverage across relevant infrastructure components, systems, and applications.
Maintain visibility of assets under security monitoring and support onboarding of new assets into security platforms.
Review security dashboards and reports, providing regular updates to stakeholders on risks and remediation status.
Support continuous improvement of security monitoring and incident detection capabilities.
Stakeholder Engagement
Engage business, project, and technical teams on cybersecurity requirements and security best practices.
Conduct regular security reviews and recommend improvements to strengthen security controls.
Coordinate with external vendors, service providers, regulatory bodies, and industry partners on cybersecurity-related matters.
Provide cybersecurity advice and guidance to project teams during solution design and implementation.
Additional Duties
Support cybersecurity initiatives, audits, assessments, and special projects as assigned.
Contribute to the development of security awareness and cybersecurity improvement programs.
Perform other cybersecurity-related duties as required.
Qualifications & Experience
Education
Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related discipline.
Experience
Minimum 7-10 years of experience in cybersecurity, information security, or IT infrastructure security roles.
Experience in security governance, risk management, security operations, or incident response.
Familiarity with enterprise security technologies and cybersecurity frameworks.
Experience working with cross-functional teams and external service providers.
Technical Knowledge
Understanding of cybersecurity principles, frameworks, standards, and best practices.
Knowledge of:
Security Operations (SOC)
Incident Response
Vulnerability Management
Risk Assessment
Security Monitoring Tools
Endpoint, Network, and Infrastructure Security
Identity and Access Management (IAM)
Cloud Security concepts
Familiarity with security investigations and digital forensic processes is advantageous.
Skills & Competencies
Strong analytical, problem-solving, and critical-thinking skills.
Good written, presentation, and communication skills.
Ability to engage stakeholders at different levels of the organization.
Strong organizational and documentation skills.
Ability to work independently and collaboratively in a team environment.
Preferred Certifications
Applicants possessing one or more of thefollowing certifications will have an advantage:
Certified Information Systems Security Professional (CISSP)
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Back End Developer Full-Time Jobs in Singapore.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Singapore, connecting you to thousands of jobs fast!
Find the best jobs in Singapore, apply in 1 click and get a job today!