- 30 RAFFLES PLACE Central Region (Singapore) Singapore

Working Location
Job Description
Responsibilities
We are seeking an experienced IT Security Consultant to strengthen our security operations, vendor governance, and risk management frameworks. In this role, you will oversee third-party security deliverables, direct vulnerability assessments and testing cycles, and provide expert technical guidance to ensure enterprise systems remain resilient against evolving cyber threats.
Key Responsibilities
Vendor & Testing Management: Oversee security vendors and ensure high-quality technical deliverables. Manage periodic penetration testing and vulnerability scanning schedules.
Remediation & Risk Assessment: Evaluate security findings, assess proposed mitigation plans for technical adequacy, and drive timely remediation across systems.
Governance & Advisory: Review and refine security policies, standards, and operational guidelines. Provide internal cybersecurity consultancy across technical projects.
Incident Response & Operations: Monitor and respond to security alerts and advisories. Handle security incidents, conduct root-cause analysis, and drive resolution.
Training & Awareness: Develop and conduct organization-wide security awareness sessions and issue regular threat advisories.
Qualifications & Skill Requirements
Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
Experience: 4 to 7 years of hands-on experience in cybersecurity operations, security analysis, or an equivalent consultant role.
Mandatory Certifications: Must hold an active CISSP and/or CISM.
Technical Skills:
Deep understanding of network protocols, OS administration (Windows/Linux), and major cloud architectures (AWS, Azure, or GCP).
Hands-on proficiency with SIEM platforms, vulnerability scanners, and penetration testing tools.
Experience using scripting languages (e.g., Python, PowerShell) for task automation.
Solid understanding of OWASP Top 10 vulnerabilities, web application security, and incident response frameworks.
Frameworks & Standards: Practical familiarity with established frameworks like NIST and ISO 27001.
Soft Skills: Excellent problem-solving capabilities, strong attention to detail, and the ability to articulate complex technical risks to non-technical stakeholders.
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.